VirtualBox

Ticket #13797: VBoxStartup.log

File VBoxStartup.log, 287.0 KB (added by mnman, 10 years ago)
Line 
11558.1090: Log file opened: 4.3.21r97927 g_hStartupLog=00000000000000c0 g_uNtVerCombined=0x611db110
21558.1090: \SystemRoot\System32\ntdll.dll:
31558.1090: CreationTime: 2013-10-11T00:27:08.898984800Z
41558.1090: LastWriteTime: 2013-08-29T02:16:35.515578900Z
51558.1090: ChangeTime: 2014-12-15T16:32:10.938403200Z
61558.1090: FileAttributes: 0x20
71558.1090: Size: 0x1a6dc0
81558.1090: NT Headers: 0xe0
91558.1090: Timestamp: 0x521eaf24
101558.1090: Machine: 0x8664 - amd64
111558.1090: Timestamp: 0x521eaf24
121558.1090: Image Version: 6.1
131558.1090: SizeOfImage: 0x1a9000 (1740800)
141558.1090: Resource Dir: 0x151000 LB 0x560d8
151558.1090: ProductName: Microsoft® Windows® Operating System
161558.1090: ProductVersion: 6.1.7601.18247
171558.1090: FileVersion: 6.1.7601.18247 (win7sp1_gdr.130828-1532)
181558.1090: FileDescription: NT Layer DLL
191558.1090: \SystemRoot\System32\kernel32.dll:
201558.1090: CreationTime: 2014-04-08T17:52:11.563330500Z
211558.1090: LastWriteTime: 2014-03-04T09:44:00.336000000Z
221558.1090: ChangeTime: 2014-12-15T16:32:06.941796100Z
231558.1090: FileAttributes: 0x20
241558.1090: Size: 0x11c000
251558.1090: NT Headers: 0xe8
261558.1090: Timestamp: 0x5315a059
271558.1090: Machine: 0x8664 - amd64
281558.1090: Timestamp: 0x5315a059
291558.1090: Image Version: 6.1
301558.1090: SizeOfImage: 0x11f000 (1175552)
311558.1090: Resource Dir: 0x116000 LB 0x528
321558.1090: ProductName: Microsoft® Windows® Operating System
331558.1090: ProductVersion: 6.1.7601.18409
341558.1090: FileVersion: 6.1.7601.18409 (win7sp1_gdr.140303-2144)
351558.1090: FileDescription: Windows NT BASE API Client DLL
361558.1090: \SystemRoot\System32\KernelBase.dll:
371558.1090: CreationTime: 2014-05-14T14:19:49.655911900Z
381558.1090: LastWriteTime: 2014-03-04T09:44:00.336000000Z
391558.1090: ChangeTime: 2014-12-15T16:32:06.972996100Z
401558.1090: FileAttributes: 0x20
411558.1090: Size: 0x67c00
421558.1090: NT Headers: 0xe8
431558.1090: Timestamp: 0x5315a05a
441558.1090: Machine: 0x8664 - amd64
451558.1090: Timestamp: 0x5315a05a
461558.1090: Image Version: 6.1
471558.1090: SizeOfImage: 0x6c000 (442368)
481558.1090: Resource Dir: 0x6a000 LB 0x530
491558.1090: ProductName: Microsoft® Windows® Operating System
501558.1090: ProductVersion: 6.1.7601.18409
511558.1090: FileVersion: 6.1.7601.18409 (win7sp1_gdr.140303-2144)
521558.1090: FileDescription: Windows NT BASE API Client DLL
531558.1090: \SystemRoot\System32\apisetschema.dll:
541558.1090: CreationTime: 2013-09-13T00:27:27.125703100Z
551558.1090: LastWriteTime: 2013-08-02T02:12:20.275000000Z
561558.1090: ChangeTime: 2014-12-15T16:32:16.182012500Z
571558.1090: FileAttributes: 0x20
581558.1090: Size: 0x1a00
591558.1090: NT Headers: 0xc0
601558.1090: Timestamp: 0x51fb15ca
611558.1090: Machine: 0x8664 - amd64
621558.1090: Timestamp: 0x51fb15ca
631558.1090: Image Version: 6.1
641558.1090: SizeOfImage: 0x50000 (327680)
651558.1090: Resource Dir: 0x30000 LB 0x3f8
661558.1090: ProductName: Microsoft® Windows® Operating System
671558.1090: ProductVersion: 6.1.7601.18229
681558.1090: FileVersion: 6.1.7601.18229 (win7sp1_gdr.130801-1533)
691558.1090: FileDescription: ApiSet Schema DLL
701558.1090: Found driver NisDrv (0x400)
711558.1090: supR3HardenedWinFindAdversaries: 0x480
721558.1090: \SystemRoot\System32\drivers\MBAMSwissArmy.sys:
731558.1090: CreationTime: 2014-08-29T14:06:38.460628200Z
741558.1090: LastWriteTime: 2015-01-13T22:19:10.600779300Z
751558.1090: ChangeTime: 2015-01-13T22:19:10.600779300Z
761558.1090: FileAttributes: 0x20
771558.1090: Size: 0x1fad8
781558.1090: NT Headers: 0xd8
791558.1090: Timestamp: 0x541caaaf
801558.1090: Machine: 0x8664 - amd64
811558.1090: Timestamp: 0x541caaaf
821558.1090: Image Version: 6.1
831558.1090: SizeOfImage: 0x23000 (143360)
841558.1090: Resource Dir: 0x22000 LB 0x3f0
851558.1090: ProductName: Malwarebytes Anti-Malware
861558.1090: ProductVersion: 0.2.13.0
871558.1090: FileVersion: 0.2.13.0
881558.1090: FileDescription: Malwarebytes Anti-Malware
891558.1090: \SystemRoot\System32\drivers\mwac.sys:
901558.1090: CreationTime: 2014-08-29T14:06:17.837392200Z
911558.1090: LastWriteTime: 2014-11-21T12:14:22.000000000Z
921558.1090: ChangeTime: 2014-12-05T05:38:29.313527300Z
931558.1090: FileAttributes: 0x20
941558.1090: Size: 0xf8d8
951558.1090: NT Headers: 0xf8
961558.1090: Timestamp: 0x53a0f42a
971558.1090: Machine: 0x8664 - amd64
981558.1090: Timestamp: 0x53a0f42a
991558.1090: Image Version: 6.2
1001558.1090: SizeOfImage: 0x12000 (73728)
1011558.1090: Resource Dir: 0x10000 LB 0x3e0
1021558.1090: ProductName: Malwarebytes Web Access Control
1031558.1090: ProductVersion: 1.0.6.0
1041558.1090: FileVersion: 1.0.6.0
1051558.1090: FileDescription: Malwarebytes Web Access Control
1061558.1090: \SystemRoot\System32\drivers\mbamchameleon.sys:
1071558.1090: CreationTime: 2014-08-29T14:06:17.868592300Z
1081558.1090: LastWriteTime: 2014-11-21T12:14:12.000000000Z
1091558.1090: ChangeTime: 2014-12-05T05:38:29.516327600Z
1101558.1090: FileAttributes: 0x20
1111558.1090: Size: 0x16cd8
1121558.1090: NT Headers: 0xe0
1131558.1090: Timestamp: 0x53f2136a
1141558.1090: Machine: 0x8664 - amd64
1151558.1090: Timestamp: 0x53f2136a
1161558.1090: Image Version: 6.1
1171558.1090: SizeOfImage: 0x1a000 (106496)
1181558.1090: Resource Dir: 0x18000 LB 0xbd0
1191558.1090: ProductName: Malwarebytes Chameleon
1201558.1090: ProductVersion: 1.1.4.0
1211558.1090: FileVersion: 1.1.4.0
1221558.1090: FileDescription: Malwarebytes Chameleon Protection Driver
1231558.1090: \SystemRoot\System32\drivers\mbam.sys:
1241558.1090: CreationTime: 2014-08-29T14:06:17.821792200Z
1251558.1090: LastWriteTime: 2014-11-21T12:14:08.000000000Z
1261558.1090: ChangeTime: 2014-12-05T05:38:29.297927200Z
1271558.1090: FileAttributes: 0x20
1281558.1090: Size: 0x64d8
1291558.1090: NT Headers: 0xd8
1301558.1090: Timestamp: 0x540754e1
1311558.1090: Machine: 0x8664 - amd64
1321558.1090: Timestamp: 0x540754e1
1331558.1090: Image Version: 6.1
1341558.1090: SizeOfImage: 0xa000 (40960)
1351558.1090: Resource Dir: 0x8000 LB 0x3d0
1361558.1090: ProductName: Malwarebytes Anti-Malware
1371558.1090: ProductVersion: 0.1.15.0
1381558.1090: FileVersion: 0.1.15.0
1391558.1090: FileDescription: Malwarebytes Anti-Malware
1401558.1090: \SystemRoot\System32\drivers\MpFilter.sys:
1411558.1090: CreationTime: 2014-07-17T23:05:06.000000000Z
1421558.1090: LastWriteTime: 2014-07-17T23:05:06.000000000Z
1431558.1090: ChangeTime: 2014-09-09T23:22:15.541298400Z
1441558.1090: FileAttributes: 0x20
1451558.1090: Size: 0x41ad0
1461558.1090: NT Headers: 0xf0
1471558.1090: Timestamp: 0x53bdfdba
1481558.1090: Machine: 0x8664 - amd64
1491558.1090: Timestamp: 0x53bdfdba
1501558.1090: Image Version: 6.3
1511558.1090: SizeOfImage: 0x42000 (270336)
1521558.1090: Resource Dir: 0x40000 LB 0xd50
1531558.1090: ProductName: Microsoft Malware Protection
1541558.1090: ProductVersion: 4.6.0300.0
1551558.1090: FileVersion: 4.6.0300.0
1561558.1090: FileDescription: Microsoft antimalware file system filter driver
1571558.1090: \SystemRoot\System32\drivers\NisDrvWFP.sys:
1581558.1090: CreationTime: 2014-03-11T14:52:30.000000000Z
1591558.1090: LastWriteTime: 2014-07-17T23:05:06.000000000Z
1601558.1090: ChangeTime: 2014-09-09T23:22:14.801256100Z
1611558.1090: FileAttributes: 0x20
1621558.1090: Size: 0x1ea90
1631558.1090: NT Headers: 0xe0
1641558.1090: Timestamp: 0x53bdfde3
1651558.1090: Machine: 0x8664 - amd64
1661558.1090: Timestamp: 0x53bdfde3
1671558.1090: Image Version: 6.3
1681558.1090: SizeOfImage: 0x1f000 (126976)
1691558.1090: Resource Dir: 0x1c000 LB 0x1b90
1701558.1090: ProductName: Microsoft Malware Protection
1711558.1090: ProductVersion: 4.6.0300.0
1721558.1090: FileVersion: 4.6.0300.0
1731558.1090: FileDescription: Microsoft Network Realtime Inspection Driver
1741558.1090: Calling main()
1751558.1090: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
1761558.1090: SUPR3HardenedMain: Respawn #1
1771558.1090: System32: \Device\HarddiskVolume2\Windows\System32
1781558.1090: WinSxS: \Device\HarddiskVolume2\Windows\winsxs
1791558.1090: KnownDllPath: C:\Windows\system32
1801558.1090: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
1811558.1090: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe)
1821558.1090: supR3HardNtEnableThreadCreation:
1831558.1090: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00000000771bc340 pvNtTerminateThread=00000000771e17e0
1841558.1090: supR3HardenedWinDoReSpawn(1): New child 1d08.99c [kernel32].
1851558.1090: supR3HardNtChildGatherData: PebBaseAddress=000007fffffd5000 cbPeb=0x380
1861558.1090: supR3HardNtPuChFindNtdll: uNtDllParentAddr=0000000077190000 uNtDllChildAddr=0000000077190000
1871558.1090: supR3HardenedWinSetupChildInit: uLdrInitThunk=00000000771bc340
1881558.1090: supR3HardenedWinSetupChildInit: Start child.
1891558.1090: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
1901558.1090: supR3HardNtChildPurify: Startup delay kludge #1/0: 515 ms, 33 sleeps
1911558.1090: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
1921558.1090: *0000000000000000-fffffffffffeffff 0x0001/0x0000 0x0000000
1931558.1090: *0000000000010000-fffffffffffeffff 0x0004/0x0004 0x0020000
1941558.1090: *0000000000030000-000000000002bfff 0x0002/0x0002 0x0040000
1951558.1090: 0000000000034000-0000000000027fff 0x0001/0x0000 0x0000000
1961558.1090: *0000000000040000-000000000003efff 0x0004/0x0004 0x0020000
1971558.1090: 0000000000041000-0000000000031fff 0x0001/0x0000 0x0000000
1981558.1090: *0000000000050000-000000000004efff 0x0004/0x0004 0x0020000
1991558.1090: 0000000000051000-fffffffffffa1fff 0x0001/0x0000 0x0000000
2001558.1090: *0000000000100000-0000000000003fff 0x0000/0x0004 0x0020000
2011558.1090: 00000000001fc000-00000000001f8fff 0x0104/0x0004 0x0020000
2021558.1090: 00000000001ff000-00000000001fdfff 0x0004/0x0004 0x0020000
2031558.1090: 0000000000200000-ffffffff8926ffff 0x0001/0x0000 0x0000000
2041558.1090: *0000000077190000-000000007718efff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
2051558.1090: 0000000077191000-000000007708efff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
2061558.1090: 0000000077293000-0000000077263fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
2071558.1090: 00000000772c2000-00000000772b9fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
2081558.1090: 00000000772ca000-00000000772c8fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
2091558.1090: 00000000772cb000-00000000772c7fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
2101558.1090: 00000000772ce000-0000000077262fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
2111558.1090: 0000000077339000-000000006f691fff 0x0001/0x0000 0x0000000
2121558.1090: *000000007efe0000-000000007dfdffff 0x0000/0x0002 0x0020000
2131558.1090: *000000007ffe0000-000000007ffdefff 0x0002/0x0002 0x0020000
2141558.1090: 000000007ffe1000-000000007ffd1fff 0x0000/0x0002 0x0020000
2151558.1090: 000000007fff0000-ffffffffc09cffff 0x0001/0x0000 0x0000000
2161558.1090: *000000013f610000-000000013f60efff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
2171558.1090: 000000013f611000-000000013f58cfff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
2181558.1090: 000000013f695000-000000013f693fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
2191558.1090: 000000013f696000-000000013f658fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
2201558.1090: 000000013f6d3000-000000013f6d1fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
2211558.1090: 000000013f6d4000-000000013f6d2fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
2221558.1090: 000000013f6d5000-000000013f6d2fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
2231558.1090: 000000013f6d7000-000000013f6d5fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
2241558.1090: 000000013f6d8000-000000013f6d6fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
2251558.1090: 000000013f6d9000-000000013f6d4fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
2261558.1090: 000000013f6dd000-000000013f6a3fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
2271558.1090: 000000013f716000-fffff8037f97bfff 0x0001/0x0000 0x0000000
2281558.1090: *000007feff4b0000-000007feff4aefff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\apisetschema.dll
2291558.1090: 000007feff4b1000-000007fdfe9b1fff 0x0001/0x0000 0x0000000
2301558.1090: *000007fffffb0000-000007fffff8cfff 0x0002/0x0002 0x0040000
2311558.1090: 000007fffffd3000-000007fffffd0fff 0x0001/0x0000 0x0000000
2321558.1090: *000007fffffd5000-000007fffffd3fff 0x0004/0x0004 0x0020000
2331558.1090: 000007fffffd6000-000007fffffcdfff 0x0001/0x0000 0x0000000
2341558.1090: *000007fffffde000-000007fffffdbfff 0x0004/0x0004 0x0020000
2351558.1090: *000007fffffe0000-000007fffffcffff 0x0001/0x0002 0x0020000
2361558.1090: apisetschema.dll: timestamp 0x51fb15ca (rc=VINF_SUCCESS)
2371558.1090: VirtualBox.exe: timestamp 0x54c8fe13 (rc=VINF_SUCCESS)
2381558.1090: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
2391558.1090: '\Device\HarddiskVolume2\Windows\System32\apisetschema.dll' has no imports
2401558.1090: '\Device\HarddiskVolume2\Windows\System32\ntdll.dll' has no imports
2411558.1090: supR3HardNtChildPurify: Done after 546 ms and 0 fixes (loop #0).
2421558.1090: supR3HardNtEnableThreadCreation:
2431d08.99c: Log file opened: 4.3.21r97927 g_hStartupLog=0000000000000004 g_uNtVerCombined=0x611db110
2441d08.99c: supR3HardenedVmProcessInit: uNtDllAddr=0000000077190000
2451d08.99c: ntdll.dll: timestamp 0x521eaf24 (rc=VINF_SUCCESS)
2461d08.99c: New simple heap: #1 0000000000300000 LB 0x400000 (for 1740800 allocation)
2471d08.99c: System32: \Device\HarddiskVolume2\Windows\System32
2481d08.99c: WinSxS: \Device\HarddiskVolume2\Windows\winsxs
2491d08.99c: KnownDllPath: C:\Windows\system32
2501d08.99c: supR3HardenedVmProcessInit: Opening vboxdrv stub...
2511d08.99c: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
2521d08.99c: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
2531d08.99c: Registered Dll notification callback with NTDLL.
2541d08.99c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\kernel32.dll)
2551d08.99c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\kernel32.dll
2561d08.99c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
2571d08.99c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
2581d08.99c: supR3HardenedDllNotificationCallback: load 0000000077070000 LB 0x0011f000 C:\Windows\system32\kernel32.dll [fFlags=0x0]
2591d08.99c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
2601d08.99c: supR3HardenedDllNotificationCallback: load 000007fefd2a0000 LB 0x0006c000 C:\Windows\system32\KERNELBASE.dll [fFlags=0x0]
2611d08.99c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\KernelBase.dll)
2621d08.99c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\KernelBase.dll
2631d08.99c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077070000 'C:\Windows\system32\kernel32.dll'
2641d08.99c: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00000000771bc340 pvNtTerminateThread=00000000771e17e0
2651558.1090: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 16 ms.
2661d08.99c: \SystemRoot\System32\ntdll.dll:
2671d08.99c: CreationTime: 2013-10-11T00:27:08.898984800Z
2681d08.99c: LastWriteTime: 2013-08-29T02:16:35.515578900Z
2691d08.99c: ChangeTime: 2014-12-15T16:32:10.938403200Z
2701d08.99c: FileAttributes: 0x20
2711d08.99c: Size: 0x1a6dc0
2721d08.99c: NT Headers: 0xe0
2731d08.99c: Timestamp: 0x521eaf24
2741d08.99c: Machine: 0x8664 - amd64
2751d08.99c: Timestamp: 0x521eaf24
2761d08.99c: Image Version: 6.1
2771d08.99c: SizeOfImage: 0x1a9000 (1740800)
2781d08.99c: Resource Dir: 0x151000 LB 0x560d8
2791d08.99c: ProductName: Microsoft® Windows® Operating System
2801d08.99c: ProductVersion: 6.1.7601.18247
2811d08.99c: FileVersion: 6.1.7601.18247 (win7sp1_gdr.130828-1532)
2821d08.99c: FileDescription: NT Layer DLL
2831d08.99c: \SystemRoot\System32\kernel32.dll:
2841d08.99c: CreationTime: 2014-04-08T17:52:11.563330500Z
2851d08.99c: LastWriteTime: 2014-03-04T09:44:00.336000000Z
2861d08.99c: ChangeTime: 2014-12-15T16:32:06.941796100Z
2871d08.99c: FileAttributes: 0x20
2881d08.99c: Size: 0x11c000
2891d08.99c: NT Headers: 0xe8
2901d08.99c: Timestamp: 0x5315a059
2911d08.99c: Machine: 0x8664 - amd64
2921d08.99c: Timestamp: 0x5315a059
2931d08.99c: Image Version: 6.1
2941d08.99c: SizeOfImage: 0x11f000 (1175552)
2951d08.99c: Resource Dir: 0x116000 LB 0x528
2961d08.99c: ProductName: Microsoft® Windows® Operating System
2971d08.99c: ProductVersion: 6.1.7601.18409
2981d08.99c: FileVersion: 6.1.7601.18409 (win7sp1_gdr.140303-2144)
2991d08.99c: FileDescription: Windows NT BASE API Client DLL
3001d08.99c: \SystemRoot\System32\KernelBase.dll:
3011d08.99c: CreationTime: 2014-05-14T14:19:49.655911900Z
3021d08.99c: LastWriteTime: 2014-03-04T09:44:00.336000000Z
3031d08.99c: ChangeTime: 2014-12-15T16:32:06.972996100Z
3041d08.99c: FileAttributes: 0x20
3051d08.99c: Size: 0x67c00
3061d08.99c: NT Headers: 0xe8
3071d08.99c: Timestamp: 0x5315a05a
3081d08.99c: Machine: 0x8664 - amd64
3091d08.99c: Timestamp: 0x5315a05a
3101d08.99c: Image Version: 6.1
3111d08.99c: SizeOfImage: 0x6c000 (442368)
3121d08.99c: Resource Dir: 0x6a000 LB 0x530
3131d08.99c: ProductName: Microsoft® Windows® Operating System
3141d08.99c: ProductVersion: 6.1.7601.18409
3151d08.99c: FileVersion: 6.1.7601.18409 (win7sp1_gdr.140303-2144)
3161d08.99c: FileDescription: Windows NT BASE API Client DLL
3171d08.99c: \SystemRoot\System32\apisetschema.dll:
3181d08.99c: CreationTime: 2013-09-13T00:27:27.125703100Z
3191d08.99c: LastWriteTime: 2013-08-02T02:12:20.275000000Z
3201d08.99c: ChangeTime: 2014-12-15T16:32:16.182012500Z
3211d08.99c: FileAttributes: 0x20
3221d08.99c: Size: 0x1a00
3231d08.99c: NT Headers: 0xc0
3241d08.99c: Timestamp: 0x51fb15ca
3251d08.99c: Machine: 0x8664 - amd64
3261d08.99c: Timestamp: 0x51fb15ca
3271d08.99c: Image Version: 6.1
3281d08.99c: SizeOfImage: 0x50000 (327680)
3291d08.99c: Resource Dir: 0x30000 LB 0x3f8
3301d08.99c: ProductName: Microsoft® Windows® Operating System
3311d08.99c: ProductVersion: 6.1.7601.18229
3321d08.99c: FileVersion: 6.1.7601.18229 (win7sp1_gdr.130801-1533)
3331d08.99c: FileDescription: ApiSet Schema DLL
3341d08.99c: Found driver NisDrv (0x400)
3351d08.99c: supR3HardenedWinFindAdversaries: 0x480
3361d08.99c: \SystemRoot\System32\drivers\MBAMSwissArmy.sys:
3371d08.99c: CreationTime: 2014-08-29T14:06:38.460628200Z
3381d08.99c: LastWriteTime: 2015-01-13T22:19:10.600779300Z
3391d08.99c: ChangeTime: 2015-01-13T22:19:10.600779300Z
3401d08.99c: FileAttributes: 0x20
3411d08.99c: Size: 0x1fad8
3421d08.99c: NT Headers: 0xd8
3431d08.99c: Timestamp: 0x541caaaf
3441d08.99c: Machine: 0x8664 - amd64
3451d08.99c: Timestamp: 0x541caaaf
3461d08.99c: Image Version: 6.1
3471d08.99c: SizeOfImage: 0x23000 (143360)
3481d08.99c: Resource Dir: 0x22000 LB 0x3f0
3491d08.99c: ProductName: Malwarebytes Anti-Malware
3501d08.99c: ProductVersion: 0.2.13.0
3511d08.99c: FileVersion: 0.2.13.0
3521d08.99c: FileDescription: Malwarebytes Anti-Malware
3531d08.99c: \SystemRoot\System32\drivers\mwac.sys:
3541d08.99c: CreationTime: 2014-08-29T14:06:17.837392200Z
3551d08.99c: LastWriteTime: 2014-11-21T12:14:22.000000000Z
3561d08.99c: ChangeTime: 2014-12-05T05:38:29.313527300Z
3571d08.99c: FileAttributes: 0x20
3581d08.99c: Size: 0xf8d8
3591d08.99c: NT Headers: 0xf8
3601d08.99c: Timestamp: 0x53a0f42a
3611d08.99c: Machine: 0x8664 - amd64
3621d08.99c: Timestamp: 0x53a0f42a
3631d08.99c: Image Version: 6.2
3641d08.99c: SizeOfImage: 0x12000 (73728)
3651d08.99c: Resource Dir: 0x10000 LB 0x3e0
3661d08.99c: ProductName: Malwarebytes Web Access Control
3671d08.99c: ProductVersion: 1.0.6.0
3681d08.99c: FileVersion: 1.0.6.0
3691d08.99c: FileDescription: Malwarebytes Web Access Control
3701d08.99c: \SystemRoot\System32\drivers\mbamchameleon.sys:
3711d08.99c: CreationTime: 2014-08-29T14:06:17.868592300Z
3721d08.99c: LastWriteTime: 2014-11-21T12:14:12.000000000Z
3731d08.99c: ChangeTime: 2014-12-05T05:38:29.516327600Z
3741d08.99c: FileAttributes: 0x20
3751d08.99c: Size: 0x16cd8
3761d08.99c: NT Headers: 0xe0
3771d08.99c: Timestamp: 0x53f2136a
3781d08.99c: Machine: 0x8664 - amd64
3791d08.99c: Timestamp: 0x53f2136a
3801d08.99c: Image Version: 6.1
3811d08.99c: SizeOfImage: 0x1a000 (106496)
3821d08.99c: Resource Dir: 0x18000 LB 0xbd0
3831d08.99c: ProductName: Malwarebytes Chameleon
3841d08.99c: ProductVersion: 1.1.4.0
3851d08.99c: FileVersion: 1.1.4.0
3861d08.99c: FileDescription: Malwarebytes Chameleon Protection Driver
3871d08.99c: \SystemRoot\System32\drivers\mbam.sys:
3881d08.99c: CreationTime: 2014-08-29T14:06:17.821792200Z
3891d08.99c: LastWriteTime: 2014-11-21T12:14:08.000000000Z
3901d08.99c: ChangeTime: 2014-12-05T05:38:29.297927200Z
3911d08.99c: FileAttributes: 0x20
3921d08.99c: Size: 0x64d8
3931d08.99c: NT Headers: 0xd8
3941d08.99c: Timestamp: 0x540754e1
3951d08.99c: Machine: 0x8664 - amd64
3961d08.99c: Timestamp: 0x540754e1
3971d08.99c: Image Version: 6.1
3981d08.99c: SizeOfImage: 0xa000 (40960)
3991d08.99c: Resource Dir: 0x8000 LB 0x3d0
4001d08.99c: ProductName: Malwarebytes Anti-Malware
4011d08.99c: ProductVersion: 0.1.15.0
4021d08.99c: FileVersion: 0.1.15.0
4031d08.99c: FileDescription: Malwarebytes Anti-Malware
4041d08.99c: \SystemRoot\System32\drivers\MpFilter.sys:
4051d08.99c: CreationTime: 2014-07-17T23:05:06.000000000Z
4061d08.99c: LastWriteTime: 2014-07-17T23:05:06.000000000Z
4071d08.99c: ChangeTime: 2014-09-09T23:22:15.541298400Z
4081d08.99c: FileAttributes: 0x20
4091d08.99c: Size: 0x41ad0
4101d08.99c: NT Headers: 0xf0
4111d08.99c: Timestamp: 0x53bdfdba
4121d08.99c: Machine: 0x8664 - amd64
4131d08.99c: Timestamp: 0x53bdfdba
4141d08.99c: Image Version: 6.3
4151d08.99c: SizeOfImage: 0x42000 (270336)
4161d08.99c: Resource Dir: 0x40000 LB 0xd50
4171d08.99c: ProductName: Microsoft Malware Protection
4181d08.99c: ProductVersion: 4.6.0300.0
4191d08.99c: FileVersion: 4.6.0300.0
4201d08.99c: FileDescription: Microsoft antimalware file system filter driver
4211d08.99c: \SystemRoot\System32\drivers\NisDrvWFP.sys:
4221d08.99c: CreationTime: 2014-03-11T14:52:30.000000000Z
4231d08.99c: LastWriteTime: 2014-07-17T23:05:06.000000000Z
4241d08.99c: ChangeTime: 2014-09-09T23:22:14.801256100Z
4251d08.99c: FileAttributes: 0x20
4261d08.99c: Size: 0x1ea90
4271d08.99c: NT Headers: 0xe0
4281d08.99c: Timestamp: 0x53bdfde3
4291d08.99c: Machine: 0x8664 - amd64
4301d08.99c: Timestamp: 0x53bdfde3
4311d08.99c: Image Version: 6.3
4321d08.99c: SizeOfImage: 0x1f000 (126976)
4331d08.99c: Resource Dir: 0x1c000 LB 0x1b90
4341d08.99c: ProductName: Microsoft Malware Protection
4351d08.99c: ProductVersion: 4.6.0300.0
4361d08.99c: FileVersion: 4.6.0300.0
4371d08.99c: FileDescription: Microsoft Network Realtime Inspection Driver
4381d08.99c: Calling main()
4391d08.99c: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
4401d08.99c: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
4411d08.99c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe)
4421d08.99c: SUPR3HardenedMain: Respawn #2
4431d08.99c: supR3HardNtEnableThreadCreation:
4441d08.99c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\apphelp.dll)
4451d08.99c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\apphelp.dll
4461d08.99c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\apphelp.dll (rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
4471d08.99c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\apphelp.dll [lacks WinVerifyTrust]
4481d08.99c: supR3HardenedDllNotificationCallback: load 000007fefcd50000 LB 0x00057000 C:\Windows\system32\apphelp.dll [fFlags=0x0]
4491d08.99c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\apphelp.dll [lacks WinVerifyTrust]
4501d08.99c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcd50000 'C:\Windows\system32\apphelp.dll'
4511d08.99c: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00000000771bc340 pvNtTerminateThread=00000000771e17e0
4521d08.99c: supR3HardenedWinDoReSpawn(2): New child 28fc.18f8 [kernel32].
4531d08.99c: supR3HardNtChildGatherData: PebBaseAddress=000007fffffd7000 cbPeb=0x380
4541d08.99c: supR3HardNtPuChFindNtdll: uNtDllParentAddr=0000000077190000 uNtDllChildAddr=0000000077190000
4551d08.99c: supR3HardenedWinSetupChildInit: uLdrInitThunk=00000000771bc340
4561d08.99c: supR3HardenedWinSetupChildInit: Start child.
4571d08.99c: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
4581d08.99c: supR3HardNtChildPurify: Startup delay kludge #1/0: 515 ms, 33 sleeps
4591d08.99c: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
4601d08.99c: *0000000000000000-fffffffffffeffff 0x0001/0x0000 0x0000000
4611d08.99c: *0000000000010000-fffffffffffeffff 0x0004/0x0004 0x0020000
4621d08.99c: *0000000000030000-000000000002bfff 0x0002/0x0002 0x0040000
4631d08.99c: 0000000000034000-0000000000027fff 0x0001/0x0000 0x0000000
4641d08.99c: *0000000000040000-000000000003efff 0x0004/0x0004 0x0020000
4651d08.99c: 0000000000041000-0000000000031fff 0x0001/0x0000 0x0000000
4661d08.99c: *0000000000050000-000000000004efff 0x0004/0x0004 0x0020000
4671d08.99c: 0000000000051000-ffffffffffeb1fff 0x0001/0x0000 0x0000000
4681d08.99c: *00000000001f0000-00000000000f3fff 0x0000/0x0004 0x0020000
4691d08.99c: 00000000002ec000-00000000002e8fff 0x0104/0x0004 0x0020000
4701d08.99c: 00000000002ef000-00000000002edfff 0x0004/0x0004 0x0020000
4711d08.99c: 00000000002f0000-ffffffff8944ffff 0x0001/0x0000 0x0000000
4721d08.99c: *0000000077190000-000000007718efff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
4731d08.99c: 0000000077191000-000000007708efff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
4741d08.99c: 0000000077293000-0000000077263fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
4751d08.99c: 00000000772c2000-00000000772b9fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
4761d08.99c: 00000000772ca000-00000000772c8fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
4771d08.99c: 00000000772cb000-00000000772c7fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
4781d08.99c: 00000000772ce000-0000000077262fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
4791d08.99c: 0000000077339000-000000006f691fff 0x0001/0x0000 0x0000000
4801d08.99c: *000000007efe0000-000000007dfdffff 0x0000/0x0002 0x0020000
4811d08.99c: *000000007ffe0000-000000007ffdefff 0x0002/0x0002 0x0020000
4821d08.99c: 000000007ffe1000-000000007ffd1fff 0x0000/0x0002 0x0020000
4831d08.99c: 000000007fff0000-ffffffffc09cffff 0x0001/0x0000 0x0000000
4841d08.99c: *000000013f610000-000000013f60efff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
4851d08.99c: 000000013f611000-000000013f58cfff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
4861d08.99c: 000000013f695000-000000013f693fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
4871d08.99c: 000000013f696000-000000013f658fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
4881d08.99c: 000000013f6d3000-000000013f6d1fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
4891d08.99c: 000000013f6d4000-000000013f6d2fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
4901d08.99c: 000000013f6d5000-000000013f6d2fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
4911d08.99c: 000000013f6d7000-000000013f6d5fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
4921d08.99c: 000000013f6d8000-000000013f6d6fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
4931d08.99c: 000000013f6d9000-000000013f6d4fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
4941d08.99c: 000000013f6dd000-000000013f6a3fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
4951d08.99c: 000000013f716000-fffff8037f97bfff 0x0001/0x0000 0x0000000
4961d08.99c: *000007feff4b0000-000007feff4aefff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\apisetschema.dll
4971d08.99c: 000007feff4b1000-000007fdfe9b1fff 0x0001/0x0000 0x0000000
4981d08.99c: *000007fffffb0000-000007fffff8cfff 0x0002/0x0002 0x0040000
4991d08.99c: 000007fffffd3000-000007fffffcefff 0x0001/0x0000 0x0000000
5001d08.99c: *000007fffffd7000-000007fffffd5fff 0x0004/0x0004 0x0020000
5011d08.99c: 000007fffffd8000-000007fffffd1fff 0x0001/0x0000 0x0000000
5021d08.99c: *000007fffffde000-000007fffffdbfff 0x0004/0x0004 0x0020000
5031d08.99c: *000007fffffe0000-000007fffffcffff 0x0001/0x0002 0x0020000
5041d08.99c: apisetschema.dll: timestamp 0x51fb15ca (rc=VINF_SUCCESS)
5051d08.99c: VirtualBox.exe: timestamp 0x54c8fe13 (rc=VINF_SUCCESS)
5061d08.99c: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
5071d08.99c: '\Device\HarddiskVolume2\Windows\System32\apisetschema.dll' has no imports
5081d08.99c: '\Device\HarddiskVolume2\Windows\System32\ntdll.dll' has no imports
5091d08.99c: supR3HardNtChildPurify: Done after 530 ms and 0 fixes (loop #0).
5101d08.99c: supR3HardenedEarlyCompact: Removed heap 1 (0x00000000300000 LB 0x400000)
5111d08.99c: supR3HardNtEnableThreadCreation:
51228fc.18f8: Log file opened: 4.3.21r97927 g_hStartupLog=0000000000000004 g_uNtVerCombined=0x611db110
51328fc.18f8: supR3HardenedVmProcessInit: uNtDllAddr=0000000077190000
51428fc.18f8: ntdll.dll: timestamp 0x521eaf24 (rc=VINF_SUCCESS)
51528fc.18f8: New simple heap: #1 00000000002f0000 LB 0x400000 (for 1740800 allocation)
51628fc.18f8: System32: \Device\HarddiskVolume2\Windows\System32
51728fc.18f8: WinSxS: \Device\HarddiskVolume2\Windows\winsxs
51828fc.18f8: KnownDllPath: C:\Windows\system32
51928fc.18f8: supR3HardenedVmProcessInit: Opening vboxdrv...
52028fc.18f8: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
52128fc.18f8: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
52228fc.18f8: Registered Dll notification callback with NTDLL.
52328fc.18f8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\kernel32.dll)
52428fc.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\kernel32.dll
52528fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
52628fc.18f8: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
52728fc.18f8: supR3HardenedDllNotificationCallback: load 0000000077070000 LB 0x0011f000 C:\Windows\system32\kernel32.dll [fFlags=0x0]
52828fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
52928fc.18f8: supR3HardenedDllNotificationCallback: load 000007fefd2a0000 LB 0x0006c000 C:\Windows\system32\KERNELBASE.dll [fFlags=0x0]
53028fc.18f8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\KernelBase.dll)
53128fc.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\KernelBase.dll
53228fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077070000 'C:\Windows\system32\kernel32.dll'
53328fc.18f8: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00000000771bc340 pvNtTerminateThread=00000000771e17e0
5341d08.99c: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 31 ms.
53528fc.18f8: \SystemRoot\System32\ntdll.dll:
53628fc.18f8: CreationTime: 2013-10-11T00:27:08.898984800Z
53728fc.18f8: LastWriteTime: 2013-08-29T02:16:35.515578900Z
53828fc.18f8: ChangeTime: 2014-12-15T16:32:10.938403200Z
53928fc.18f8: FileAttributes: 0x20
54028fc.18f8: Size: 0x1a6dc0
54128fc.18f8: NT Headers: 0xe0
54228fc.18f8: Timestamp: 0x521eaf24
54328fc.18f8: Machine: 0x8664 - amd64
54428fc.18f8: Timestamp: 0x521eaf24
54528fc.18f8: Image Version: 6.1
54628fc.18f8: SizeOfImage: 0x1a9000 (1740800)
54728fc.18f8: Resource Dir: 0x151000 LB 0x560d8
54828fc.18f8: ProductName: Microsoft® Windows® Operating System
54928fc.18f8: ProductVersion: 6.1.7601.18247
55028fc.18f8: FileVersion: 6.1.7601.18247 (win7sp1_gdr.130828-1532)
55128fc.18f8: FileDescription: NT Layer DLL
55228fc.18f8: \SystemRoot\System32\kernel32.dll:
55328fc.18f8: CreationTime: 2014-04-08T17:52:11.563330500Z
55428fc.18f8: LastWriteTime: 2014-03-04T09:44:00.336000000Z
55528fc.18f8: ChangeTime: 2014-12-15T16:32:06.941796100Z
55628fc.18f8: FileAttributes: 0x20
55728fc.18f8: Size: 0x11c000
55828fc.18f8: NT Headers: 0xe8
55928fc.18f8: Timestamp: 0x5315a059
56028fc.18f8: Machine: 0x8664 - amd64
56128fc.18f8: Timestamp: 0x5315a059
56228fc.18f8: Image Version: 6.1
56328fc.18f8: SizeOfImage: 0x11f000 (1175552)
56428fc.18f8: Resource Dir: 0x116000 LB 0x528
56528fc.18f8: ProductName: Microsoft® Windows® Operating System
56628fc.18f8: ProductVersion: 6.1.7601.18409
56728fc.18f8: FileVersion: 6.1.7601.18409 (win7sp1_gdr.140303-2144)
56828fc.18f8: FileDescription: Windows NT BASE API Client DLL
56928fc.18f8: \SystemRoot\System32\KernelBase.dll:
57028fc.18f8: CreationTime: 2014-05-14T14:19:49.655911900Z
57128fc.18f8: LastWriteTime: 2014-03-04T09:44:00.336000000Z
57228fc.18f8: ChangeTime: 2014-12-15T16:32:06.972996100Z
57328fc.18f8: FileAttributes: 0x20
57428fc.18f8: Size: 0x67c00
57528fc.18f8: NT Headers: 0xe8
57628fc.18f8: Timestamp: 0x5315a05a
57728fc.18f8: Machine: 0x8664 - amd64
57828fc.18f8: Timestamp: 0x5315a05a
57928fc.18f8: Image Version: 6.1
58028fc.18f8: SizeOfImage: 0x6c000 (442368)
58128fc.18f8: Resource Dir: 0x6a000 LB 0x530
58228fc.18f8: ProductName: Microsoft® Windows® Operating System
58328fc.18f8: ProductVersion: 6.1.7601.18409
58428fc.18f8: FileVersion: 6.1.7601.18409 (win7sp1_gdr.140303-2144)
58528fc.18f8: FileDescription: Windows NT BASE API Client DLL
58628fc.18f8: \SystemRoot\System32\apisetschema.dll:
58728fc.18f8: CreationTime: 2013-09-13T00:27:27.125703100Z
58828fc.18f8: LastWriteTime: 2013-08-02T02:12:20.275000000Z
58928fc.18f8: ChangeTime: 2014-12-15T16:32:16.182012500Z
59028fc.18f8: FileAttributes: 0x20
59128fc.18f8: Size: 0x1a00
59228fc.18f8: NT Headers: 0xc0
59328fc.18f8: Timestamp: 0x51fb15ca
59428fc.18f8: Machine: 0x8664 - amd64
59528fc.18f8: Timestamp: 0x51fb15ca
59628fc.18f8: Image Version: 6.1
59728fc.18f8: SizeOfImage: 0x50000 (327680)
59828fc.18f8: Resource Dir: 0x30000 LB 0x3f8
59928fc.18f8: ProductName: Microsoft® Windows® Operating System
60028fc.18f8: ProductVersion: 6.1.7601.18229
60128fc.18f8: FileVersion: 6.1.7601.18229 (win7sp1_gdr.130801-1533)
60228fc.18f8: FileDescription: ApiSet Schema DLL
60328fc.18f8: Found driver NisDrv (0x400)
60428fc.18f8: supR3HardenedWinFindAdversaries: 0x480
60528fc.18f8: \SystemRoot\System32\drivers\MBAMSwissArmy.sys:
60628fc.18f8: CreationTime: 2014-08-29T14:06:38.460628200Z
60728fc.18f8: LastWriteTime: 2015-01-13T22:19:10.600779300Z
60828fc.18f8: ChangeTime: 2015-01-13T22:19:10.600779300Z
60928fc.18f8: FileAttributes: 0x20
61028fc.18f8: Size: 0x1fad8
61128fc.18f8: NT Headers: 0xd8
61228fc.18f8: Timestamp: 0x541caaaf
61328fc.18f8: Machine: 0x8664 - amd64
61428fc.18f8: Timestamp: 0x541caaaf
61528fc.18f8: Image Version: 6.1
61628fc.18f8: SizeOfImage: 0x23000 (143360)
61728fc.18f8: Resource Dir: 0x22000 LB 0x3f0
61828fc.18f8: ProductName: Malwarebytes Anti-Malware
61928fc.18f8: ProductVersion: 0.2.13.0
62028fc.18f8: FileVersion: 0.2.13.0
62128fc.18f8: FileDescription: Malwarebytes Anti-Malware
62228fc.18f8: \SystemRoot\System32\drivers\mwac.sys:
62328fc.18f8: CreationTime: 2014-08-29T14:06:17.837392200Z
62428fc.18f8: LastWriteTime: 2014-11-21T12:14:22.000000000Z
62528fc.18f8: ChangeTime: 2014-12-05T05:38:29.313527300Z
62628fc.18f8: FileAttributes: 0x20
62728fc.18f8: Size: 0xf8d8
62828fc.18f8: NT Headers: 0xf8
62928fc.18f8: Timestamp: 0x53a0f42a
63028fc.18f8: Machine: 0x8664 - amd64
63128fc.18f8: Timestamp: 0x53a0f42a
63228fc.18f8: Image Version: 6.2
63328fc.18f8: SizeOfImage: 0x12000 (73728)
63428fc.18f8: Resource Dir: 0x10000 LB 0x3e0
63528fc.18f8: ProductName: Malwarebytes Web Access Control
63628fc.18f8: ProductVersion: 1.0.6.0
63728fc.18f8: FileVersion: 1.0.6.0
63828fc.18f8: FileDescription: Malwarebytes Web Access Control
63928fc.18f8: \SystemRoot\System32\drivers\mbamchameleon.sys:
64028fc.18f8: CreationTime: 2014-08-29T14:06:17.868592300Z
64128fc.18f8: LastWriteTime: 2014-11-21T12:14:12.000000000Z
64228fc.18f8: ChangeTime: 2014-12-05T05:38:29.516327600Z
64328fc.18f8: FileAttributes: 0x20
64428fc.18f8: Size: 0x16cd8
64528fc.18f8: NT Headers: 0xe0
64628fc.18f8: Timestamp: 0x53f2136a
64728fc.18f8: Machine: 0x8664 - amd64
64828fc.18f8: Timestamp: 0x53f2136a
64928fc.18f8: Image Version: 6.1
65028fc.18f8: SizeOfImage: 0x1a000 (106496)
65128fc.18f8: Resource Dir: 0x18000 LB 0xbd0
65228fc.18f8: ProductName: Malwarebytes Chameleon
65328fc.18f8: ProductVersion: 1.1.4.0
65428fc.18f8: FileVersion: 1.1.4.0
65528fc.18f8: FileDescription: Malwarebytes Chameleon Protection Driver
65628fc.18f8: \SystemRoot\System32\drivers\mbam.sys:
65728fc.18f8: CreationTime: 2014-08-29T14:06:17.821792200Z
65828fc.18f8: LastWriteTime: 2014-11-21T12:14:08.000000000Z
65928fc.18f8: ChangeTime: 2014-12-05T05:38:29.297927200Z
66028fc.18f8: FileAttributes: 0x20
66128fc.18f8: Size: 0x64d8
66228fc.18f8: NT Headers: 0xd8
66328fc.18f8: Timestamp: 0x540754e1
66428fc.18f8: Machine: 0x8664 - amd64
66528fc.18f8: Timestamp: 0x540754e1
66628fc.18f8: Image Version: 6.1
66728fc.18f8: SizeOfImage: 0xa000 (40960)
66828fc.18f8: Resource Dir: 0x8000 LB 0x3d0
66928fc.18f8: ProductName: Malwarebytes Anti-Malware
67028fc.18f8: ProductVersion: 0.1.15.0
67128fc.18f8: FileVersion: 0.1.15.0
67228fc.18f8: FileDescription: Malwarebytes Anti-Malware
67328fc.18f8: \SystemRoot\System32\drivers\MpFilter.sys:
67428fc.18f8: CreationTime: 2014-07-17T23:05:06.000000000Z
67528fc.18f8: LastWriteTime: 2014-07-17T23:05:06.000000000Z
67628fc.18f8: ChangeTime: 2014-09-09T23:22:15.541298400Z
67728fc.18f8: FileAttributes: 0x20
67828fc.18f8: Size: 0x41ad0
67928fc.18f8: NT Headers: 0xf0
68028fc.18f8: Timestamp: 0x53bdfdba
68128fc.18f8: Machine: 0x8664 - amd64
68228fc.18f8: Timestamp: 0x53bdfdba
68328fc.18f8: Image Version: 6.3
68428fc.18f8: SizeOfImage: 0x42000 (270336)
68528fc.18f8: Resource Dir: 0x40000 LB 0xd50
68628fc.18f8: ProductName: Microsoft Malware Protection
68728fc.18f8: ProductVersion: 4.6.0300.0
68828fc.18f8: FileVersion: 4.6.0300.0
68928fc.18f8: FileDescription: Microsoft antimalware file system filter driver
69028fc.18f8: \SystemRoot\System32\drivers\NisDrvWFP.sys:
69128fc.18f8: CreationTime: 2014-03-11T14:52:30.000000000Z
69228fc.18f8: LastWriteTime: 2014-07-17T23:05:06.000000000Z
69328fc.18f8: ChangeTime: 2014-09-09T23:22:14.801256100Z
69428fc.18f8: FileAttributes: 0x20
69528fc.18f8: Size: 0x1ea90
69628fc.18f8: NT Headers: 0xe0
69728fc.18f8: Timestamp: 0x53bdfde3
69828fc.18f8: Machine: 0x8664 - amd64
69928fc.18f8: Timestamp: 0x53bdfde3
70028fc.18f8: Image Version: 6.3
70128fc.18f8: SizeOfImage: 0x1f000 (126976)
70228fc.18f8: Resource Dir: 0x1c000 LB 0x1b90
70328fc.18f8: ProductName: Microsoft Malware Protection
70428fc.18f8: ProductVersion: 4.6.0300.0
70528fc.18f8: FileVersion: 4.6.0300.0
70628fc.18f8: FileDescription: Microsoft Network Realtime Inspection Driver
70728fc.18f8: Calling main()
70828fc.18f8: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
70928fc.18f8: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
71028fc.18f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe)
71128fc.18f8: SUPR3HardenedMain: Final process, opening VBoxDrv...
71228fc.18f8: supR3HardenedEarlyCompact: Removed heap 1 (0x000000002f0000 LB 0x400000)
71328fc.18f8: supR3HardNtEnableThreadCreation:
71428fc.18f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll)
71528fc.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll
71628fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000008e4fd0:C:\Windows\system32 [calling]
71728fc.18f8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
71828fc.18f8: supR3HardenedDllNotificationCallback: load 000007fef8a40000 LB 0x00005000 C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL [fFlags=0x0]
71928fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
72028fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
72128fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000008e5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files\nodejs\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Users\rjs7\AppData\Roaming\npm [calling]
72228fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef8a40000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
72328fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
72428fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000008e5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files\nodejs\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Users\rjs7\AppData\Roaming\npm [calling]
72528fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef8a40000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
72628fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef8a40000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
72728fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
72828fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'crypt32.dll'.
72928fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msasn1.dll'.
73028fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
73128fc.18f8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\wintrust.dll)
73228fc.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wintrust.dll
73328fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
73428fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
73528fc.18f8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll)
73628fc.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
73728fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
73828fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume2\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
73928fc.18f8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\msasn1.dll)
74028fc.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msasn1.dll
74128fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
74228fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume2\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
74328fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
74428fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msasn1.dll'.
74528fc.18f8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\crypt32.dll)
74628fc.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\crypt32.dll
74728fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
74828fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
74928fc.18f8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\msvcrt.dll)
75028fc.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
75128fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
75228fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume2\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
75328fc.18f8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
75428fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
75528fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
75628fc.18f8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
75728fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000008e4fd0:C:\Windows\system32 [calling]
75828fc.18f8: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
75928fc.18f8: supR3HardenedDllNotificationCallback: load 000007fefcfa0000 LB 0x0003b000 C:\Windows\system32\Wintrust.dll [fFlags=0x0]
76028fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
76128fc.18f8: supR3HardenedDllNotificationCallback: load 000007feff040000 LB 0x0009f000 C:\Windows\system32\msvcrt.dll [fFlags=0x0]
76228fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
76328fc.18f8: supR3HardenedDllNotificationCallback: load 000007fefd100000 LB 0x0016d000 C:\Windows\system32\CRYPT32.dll [fFlags=0x0]
76428fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
76528fc.18f8: supR3HardenedDllNotificationCallback: load 000007fefcf60000 LB 0x0000f000 C:\Windows\system32\MSASN1.dll [fFlags=0x0]
76628fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
76728fc.18f8: supR3HardenedDllNotificationCallback: load 000007fefea20000 LB 0x0012d000 C:\Windows\system32\RPCRT4.dll [fFlags=0x0]
76828fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
76928fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcfa0000 'C:\Windows\system32\Wintrust.dll'
77028fc.18f8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\cryptsp.dll)
77128fc.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cryptsp.dll
77228fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTSP.dll (Input=CRYPTSP.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000008e5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files\nodejs\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Users\rjs7\AppData\Roaming\npm [calling]
77328fc.18f8: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
77428fc.18f8: supR3HardenedDllNotificationCallback: load 000007fefc750000 LB 0x00018000 C:\Windows\system32\CRYPTSP.dll [fFlags=0x0]
77528fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
77628fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc750000 'C:\Windows\system32\CRYPTSP.dll'
77728fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
77828fc.18f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\rsaenh.dll)
77928fc.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\rsaenh.dll
78028fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
78128fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
78228fc.18f8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
78328fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000008e5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files\nodejs\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Users\rjs7\AppData\Roaming\npm [calling]
78428fc.18f8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
78528fc.18f8: supR3HardenedDllNotificationCallback: load 000007fefc450000 LB 0x00047000 C:\Windows\system32\rsaenh.dll [fFlags=0x0]
78628fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
78728fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc450000 'C:\Windows\system32\rsaenh.dll'
78828fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
78928fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'rpcrt4.dll'.
79028fc.18f8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\advapi32.dll)
79128fc.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\advapi32.dll
79228fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
79328fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
79428fc.18f8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
79528fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
79628fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
79728fc.18f8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
79828fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ADVAPI32.dll (Input=ADVAPI32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000008e5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files\nodejs\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Users\rjs7\AppData\Roaming\npm [calling]
79928fc.18f8: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
80028fc.18f8: supR3HardenedDllNotificationCallback: load 000007fefeb50000 LB 0x000db000 C:\Windows\system32\ADVAPI32.dll [fFlags=0x0]
80128fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
80228fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msvcrt.dll'.
80328fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'rpcrt4.dll'.
80428fc.18f8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\sechost.dll)
80528fc.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\sechost.dll
80628fc.18f8: supR3HardenedDllNotificationCallback: load 000007fefd3b0000 LB 0x0001f000 C:\Windows\SYSTEM32\sechost.dll [fFlags=0x0]
80728fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\sechost.dll [lacks WinVerifyTrust]
80828fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefeb50000 'C:\Windows\system32\ADVAPI32.dll'
80928fc.18f8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\cryptbase.dll)
81028fc.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cryptbase.dll
81128fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
81228fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
81328fc.18f8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
81428fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
81528fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
81628fc.18f8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
81728fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTBASE.dll (Input=CRYPTBASE.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000008e5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files\nodejs\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Users\rjs7\AppData\Roaming\npm [calling]
81828fc.18f8: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptbase.dll [lacks WinVerifyTrust]
81928fc.18f8: supR3HardenedDllNotificationCallback: load 000007fefcdb0000 LB 0x0000f000 C:\Windows\system32\CRYPTBASE.dll [fFlags=0x0]
82028fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptbase.dll [lacks WinVerifyTrust]
82128fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcdb0000 'C:\Windows\system32\CRYPTBASE.dll'
82228fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
82328fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000008e5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files\nodejs\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Users\rjs7\AppData\Roaming\npm [calling]
82428fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077070000 'C:\Windows\system32\kernel32.dll'
82528fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
82628fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\WINTRUST.DLL (Input=WINTRUST.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000008e5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files\nodejs\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Users\rjs7\AppData\Roaming\npm [calling]
82728fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcfa0000 'C:\Windows\system32\WINTRUST.DLL'
82828fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
82928fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPT32.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00000000008e5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files\nodejs\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Users\rjs7\AppData\Roaming\npm [calling]
83028fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd100000 'C:\Windows\system32\CRYPT32.dll'
83128fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
83228fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'advapi32.dll'.
83328fc.18f8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\imagehlp.dll)
83428fc.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\imagehlp.dll
83528fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
83628fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
83728fc.18f8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
83828fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
83928fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
84028fc.18f8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
84128fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\imagehlp.dll (Input=imagehlp.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000008e5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files\nodejs\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Users\rjs7\AppData\Roaming\npm [calling]
84228fc.18f8: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\imagehlp.dll [lacks WinVerifyTrust]
84328fc.18f8: supR3HardenedDllNotificationCallback: load 000007fefe8f0000 LB 0x00019000 C:\Windows\system32\imagehlp.dll [fFlags=0x0]
84428fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\imagehlp.dll [lacks WinVerifyTrust]
84528fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe8f0000 'C:\Windows\system32\imagehlp.dll'
84628fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
84728fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTSP.dll (Input=CRYPTSP.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000008e5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files\nodejs\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Users\rjs7\AppData\Roaming\npm [calling]
84828fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc750000 'C:\Windows\system32\CRYPTSP.dll'
84928fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
85028fc.18f8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\user32.dll)
85128fc.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\user32.dll
85228fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
85328fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
85428fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
85528fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'lpk.dll'.
85628fc.18f8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\gdi32.dll)
85728fc.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\gdi32.dll
85828fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'lpk.dll'...
85928fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'lpk.dll' -> '\Device\HarddiskVolume2\Windows\System32\lpk.dll' [rcNtRedir=0xc0150008]
86028fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'gdi32.dll'.
86128fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'user32.dll'.
86228fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'usp10.dll'.
86328fc.18f8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\lpk.dll)
86428fc.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\lpk.dll
86528fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
86628fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
86728fc.18f8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
86828fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'usp10.dll'...
86928fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'usp10.dll' -> '\Device\HarddiskVolume2\Windows\System32\usp10.dll' [rcNtRedir=0xc0150008]
87028fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
87128fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
87228fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'gdi32.dll'.
87328fc.18f8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\usp10.dll)
87428fc.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\usp10.dll
87528fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
87628fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
87728fc.18f8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
87828fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
87928fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
88028fc.18f8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
88128fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
88228fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
88328fc.18f8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
88428fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
88528fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
88628fc.18f8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
88728fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
88828fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
88928fc.18f8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
89028fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\USER32.dll (Input=USER32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000008e5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files\nodejs\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Users\rjs7\AppData\Roaming\npm [calling]
89128fc.18f8: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
89228fc.18f8: supR3HardenedDllNotificationCallback: load 0000000076f70000 LB 0x000fa000 C:\Windows\system32\USER32.dll [fFlags=0x0]
89328fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
89428fc.18f8: supR3HardenedDllNotificationCallback: load 000007feff3b0000 LB 0x00067000 C:\Windows\system32\GDI32.dll [fFlags=0x0]
89528fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
89628fc.18f8: supR3HardenedDllNotificationCallback: load 000007fefec90000 LB 0x0000e000 C:\Windows\system32\LPK.dll [fFlags=0x0]
89728fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\lpk.dll [lacks WinVerifyTrust]
89828fc.18f8: supR3HardenedDllNotificationCallback: load 000007fefe720000 LB 0x000c9000 C:\Windows\system32\USP10.dll [fFlags=0x0]
89928fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\usp10.dll [lacks WinVerifyTrust]
90028fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
90128fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\gdi32.dll (Input=gdi32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000008e5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files\nodejs\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Users\rjs7\AppData\Roaming\npm [calling]
90228fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff3b0000 'C:\Windows\system32\gdi32.dll'
90328fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'user32.dll'.
90428fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
90528fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msctf.dll'.
90628fc.18f8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\imm32.dll)
90728fc.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\imm32.dll
90828fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msctf.dll'...
90928fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msctf.dll' -> '\Device\HarddiskVolume2\Windows\System32\msctf.dll' [rcNtRedir=0xc0150008]
91028fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
91128fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
91228fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'gdi32.dll'.
91328fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'imm32.dll'.
91428fc.18f8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\msctf.dll)
91528fc.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msctf.dll
91628fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
91728fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
91828fc.18f8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
91928fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
92028fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
92128fc.18f8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
92228fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
92328fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume2\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
92428fc.18f8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\imm32.dll [lacks WinVerifyTrust]
92528fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
92628fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
92728fc.18f8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
92828fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
92928fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
93028fc.18f8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
93128fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
93228fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
93328fc.18f8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
93428fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\IMM32.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000008e5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files\nodejs\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Users\rjs7\AppData\Roaming\npm [calling]
93528fc.18f8: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\imm32.dll [lacks WinVerifyTrust]
93628fc.18f8: supR3HardenedDllNotificationCallback: load 000007fefe840000 LB 0x0002e000 C:\Windows\system32\IMM32.DLL [fFlags=0x0]
93728fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\imm32.dll [lacks WinVerifyTrust]
93828fc.18f8: supR3HardenedDllNotificationCallback: load 000007fefe910000 LB 0x00109000 C:\Windows\system32\MSCTF.dll [fFlags=0x0]
93928fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msctf.dll [lacks WinVerifyTrust]
94028fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe840000 'C:\Windows\system32\IMM32.DLL'
94128fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000076f70000 'C:\Windows\system32\USER32.dll'
94228fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'bcrypt.dll'.
94328fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
94428fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msasn1.dll'.
94528fc.18f8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\ncrypt.dll)
94628fc.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ncrypt.dll
94728fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
94828fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume2\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
94928fc.18f8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
95028fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
95128fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
95228fc.18f8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
95328fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
95428fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume2\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
95528fc.18f8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\bcrypt.dll)
95628fc.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\bcrypt.dll
95728fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ncrypt.dll (Input=ncrypt.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000008e5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files\nodejs\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Users\rjs7\AppData\Roaming\npm [calling]
95828fc.18f8: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\ncrypt.dll [lacks WinVerifyTrust]
95928fc.18f8: supR3HardenedDllNotificationCallback: load 000007fefc8d0000 LB 0x00050000 C:\Windows\system32\ncrypt.dll [fFlags=0x0]
96028fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\ncrypt.dll [lacks WinVerifyTrust]
96128fc.18f8: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
96228fc.18f8: supR3HardenedDllNotificationCallback: load 000007fefc8a0000 LB 0x00022000 C:\Windows\system32\bcrypt.dll [fFlags=0x0]
96328fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
96428fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc8d0000 'C:\Windows\system32\ncrypt.dll'
96528fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
96628fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'bcrypt.dll'.
96728fc.18f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll)
96828fc.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll
96928fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
97028fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume2\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
97128fc.18f8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
97228fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
97328fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
97428fc.18f8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
97528fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcryptprimitives.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000008e5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files\nodejs\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Users\rjs7\AppData\Roaming\npm [calling]
97628fc.18f8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
97728fc.18f8: supR3HardenedDllNotificationCallback: load 000007fefc390000 LB 0x0004c000 C:\Windows\system32\bcryptprimitives.dll [fFlags=0x0]
97828fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
97928fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc390000 'C:\Windows\system32\bcryptprimitives.dll'
98028fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
98128fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcrypt.dll (Input=bcrypt.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000008e5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files\nodejs\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Users\rjs7\AppData\Roaming\npm [calling]
98228fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc8a0000 'C:\Windows\system32\bcrypt.dll'
98328fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
98428fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'rpcrt4.dll'.
98528fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'profapi.dll'.
98628fc.18f8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\userenv.dll)
98728fc.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\userenv.dll
98828fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'profapi.dll'...
98928fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'profapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\profapi.dll' [rcNtRedir=0xc0150008]
99028fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
99128fc.18f8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\profapi.dll)
99228fc.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\profapi.dll
99328fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
99428fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
99528fc.18f8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
99628fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
99728fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
99828fc.18f8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
99928fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
100028fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
100128fc.18f8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
100228fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\USERENV.dll (Input=USERENV.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000008e5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files\nodejs\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Users\rjs7\AppData\Roaming\npm [calling]
100328fc.18f8: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\userenv.dll [lacks WinVerifyTrust]
100428fc.18f8: supR3HardenedDllNotificationCallback: load 000007fefcff0000 LB 0x0001e000 C:\Windows\system32\USERENV.dll [fFlags=0x0]
100528fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\userenv.dll [lacks WinVerifyTrust]
100628fc.18f8: supR3HardenedDllNotificationCallback: load 000007fefcf50000 LB 0x0000f000 C:\Windows\system32\profapi.dll [fFlags=0x0]
100728fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\profapi.dll [lacks WinVerifyTrust]
100828fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcff0000 'C:\Windows\system32\USERENV.dll'
100928fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000008e5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files\nodejs\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Users\rjs7\AppData\Roaming\npm [calling]
101028fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd3b0000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
101128fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000008e5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files\nodejs\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Users\rjs7\AppData\Roaming\npm [calling]
101228fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd3b0000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
101328fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
101428fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'rpcrt4.dll'.
101528fc.18f8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\gpapi.dll)
101628fc.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\gpapi.dll
101728fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
101828fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
101928fc.18f8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
102028fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
102128fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
102228fc.18f8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
102328fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\GPAPI.dll (Input=GPAPI.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000008e5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files\nodejs\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Users\rjs7\AppData\Roaming\npm [calling]
102428fc.18f8: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gpapi.dll [lacks WinVerifyTrust]
102528fc.18f8: supR3HardenedDllNotificationCallback: load 000007fefc200000 LB 0x0001b000 C:\Windows\system32\GPAPI.dll [fFlags=0x0]
102628fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gpapi.dll [lacks WinVerifyTrust]
102728fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc200000 'C:\Windows\system32\GPAPI.dll'
102828fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-Management-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000008e5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files\nodejs\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Users\rjs7\AppData\Roaming\npm [calling]
102928fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd3b0000 'API-MS-WIN-Service-Management-L1-1-0.dll'
103028fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
103128fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rpcrt4.dll (Input=rpcrt4.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000008e5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files\nodejs\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Users\rjs7\AppData\Roaming\npm [calling]
103228fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefea20000 'C:\Windows\system32\rpcrt4.dll'
103328fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-Management-L2-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000008e5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files\nodejs\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Users\rjs7\AppData\Roaming\npm [calling]
103428fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd3b0000 'API-MS-WIN-Service-Management-L2-1-0.dll'
103528fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000008e5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files\nodejs\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Users\rjs7\AppData\Roaming\npm [calling]
103628fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd3b0000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
103728fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
103828fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'advapi32.dll'.
103928fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'crypt32.dll'.
104028fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'wldap32.dll'.
104128fc.18f8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\cryptnet.dll)
104228fc.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cryptnet.dll
104328fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wldap32.dll'...
104428fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'wldap32.dll' -> '\Device\HarddiskVolume2\Windows\System32\wldap32.dll' [rcNtRedir=0xc0150008]
104528fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
104628fc.18f8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\Wldap32.dll)
104728fc.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\Wldap32.dll
104828fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
104928fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume2\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
105028fc.18f8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
105128fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
105228fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
105328fc.18f8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
105428fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
105528fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
105628fc.18f8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
105728fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
105828fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
105928fc.18f8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
106028fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (Input=cryptnet.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000008e5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files\nodejs\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Users\rjs7\AppData\Roaming\npm [calling]
106128fc.18f8: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
106228fc.18f8: supR3HardenedDllNotificationCallback: load 000007fef94a0000 LB 0x00027000 C:\Windows\system32\cryptnet.dll [fFlags=0x0]
106328fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
106428fc.18f8: supR3HardenedDllNotificationCallback: load 000007fefec30000 LB 0x00052000 C:\Windows\system32\WLDAP32.dll [fFlags=0x0]
106528fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\Wldap32.dll [lacks WinVerifyTrust]
106628fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
106728fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00000000008e5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files\nodejs\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Users\rjs7\AppData\Roaming\npm [calling]
106828fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef94a0000 'C:\Windows\system32\cryptnet.dll'
106928fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
107028fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00000000008e5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files\nodejs\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Users\rjs7\AppData\Roaming\npm [calling]
107128fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef94a0000 'C:\Windows\system32\cryptnet.dll'
107228fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
107328fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00000000008e5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files\nodejs\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Users\rjs7\AppData\Roaming\npm [calling]
107428fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef94a0000 'C:\Windows\system32\cryptnet.dll'
107528fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
107628fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00000000008e5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files\nodejs\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Users\rjs7\AppData\Roaming\npm [calling]
107728fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef94a0000 'C:\Windows\system32\cryptnet.dll'
107828fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
107928fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00000000008e5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files\nodejs\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Users\rjs7\AppData\Roaming\npm [calling]
108028fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef94a0000 'C:\Windows\system32\cryptnet.dll'
108128fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
108228fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00000000008e5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files\nodejs\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Users\rjs7\AppData\Roaming\npm [calling]
108328fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef94a0000 'C:\Windows\system32\cryptnet.dll'
108428fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
108528fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef94a0000 'C:\Windows\system32\cryptnet.dll'
108628fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
108728fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef94a0000 'C:\Windows\system32\cryptnet.dll'
108828fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
108928fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef94a0000 'C:\Windows\system32\cryptnet.dll'
109028fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
109128fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef94a0000 'C:\Windows\system32\cryptnet.dll'
109228fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
109328fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef94a0000 'C:\Windows\system32\cryptnet.dll'
109428fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef94a0000 'C:\Windows\system32\cryptnet.dll'
109528fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
109628fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef94a0000 'C:\Windows\system32\cryptnet.dll'
109728fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000008e5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files\nodejs\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Users\rjs7\AppData\Roaming\npm [calling]
109828fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd3b0000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
109928fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\profapi.dll [lacks WinVerifyTrust]
110028fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\profapi.dll (Input=profapi.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000008e5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files\nodejs\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Users\rjs7\AppData\Roaming\npm [calling]
110128fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcf50000 'C:\Windows\system32\profapi.dll'
110228fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
110328fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
110428fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msvcrt.dll'.
110528fc.18f8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\shlwapi.dll)
110628fc.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\shlwapi.dll
110728fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
110828fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
110928fc.18f8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
111028fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
111128fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
111228fc.18f8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
111328fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
111428fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
111528fc.18f8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
111628fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\SHLWAPI.dll (Input=SHLWAPI.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000008e5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files\nodejs\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Users\rjs7\AppData\Roaming\npm [calling]
111728fc.18f8: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll [lacks WinVerifyTrust]
111828fc.18f8: supR3HardenedDllNotificationCallback: load 000007fefe870000 LB 0x00071000 C:\Windows\system32\SHLWAPI.dll [fFlags=0x0]
111928fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll [lacks WinVerifyTrust]
112028fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe870000 'C:\Windows\system32\SHLWAPI.dll'
112128fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000000 pwszName=\SystemRoot\System32\ntdll.dll
112228fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: New context 00000000005fb770
112328fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000005fb770
112428fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=771D512B7B1C39F0393BD4EF9FC62F442783FB35
112528fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000008e5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files\nodejs\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Users\rjs7\AppData\Roaming\npm [calling]
112628fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd3b0000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
112728fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-Management-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000008e5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files\nodejs\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Users\rjs7\AppData\Roaming\npm [calling]
112828fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd3b0000 'API-MS-WIN-Service-Management-L1-1-0.dll'
112928fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-winsvc-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000008e5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files\nodejs\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Users\rjs7\AppData\Roaming\npm [calling]
113028fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd3b0000 'API-MS-WIN-Service-winsvc-L1-1-0.dll'
113128fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
113228fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ADVAPI32.dll (Input=ADVAPI32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000008e5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files\nodejs\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Users\rjs7\AppData\Roaming\npm [calling]
113328fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefeb50000 'C:\Windows\system32\ADVAPI32.dll'
113428fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-LSALookup-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000008e5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files\nodejs\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Users\rjs7\AppData\Roaming\npm [calling]
113528fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd3b0000 'API-MS-Win-Security-LSALookup-L1-1-0.dll'
113628fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-LSALookup-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000008e5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files\nodejs\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Users\rjs7\AppData\Roaming\npm [calling]
113728fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd3b0000 'API-MS-Win-Security-LSALookup-L1-1-0.dll'
113828fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_5_for_KB2882822~31bf3856ad364e35~amd64~~6.1.1.2.cat'; file='\SystemRoot\System32\ntdll.dll'
113928fc.18f8: g_pfnWinVerifyTrust=000007fefcfa1010
114028fc.18f8: supR3HardenedScreenImage/preload: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [redoing WinVerifyTrust]
114128fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000e0 pwszName=\Device\HarddiskVolume2\Windows\System32\crypt32.dll
114228fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000005fb770
114328fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000005fb770
114428fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=E4581771CBFFF32DF331EF17B5C5FD7E1F614302
114528fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_136_for_KB2949927~31bf3856ad364e35~amd64~~6.1.1.5.cat'; file='\Device\HarddiskVolume2\Windows\System32\crypt32.dll'
114628fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
114728fc.18f8: supR3HardenedScreenImage/preload: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\crypt32.dll'
114828fc.18f8: supR3HardenedScreenImage/preload: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [redoing WinVerifyTrust]
114928fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000d4 pwszName=\Device\HarddiskVolume2\Windows\System32\wintrust.dll
115028fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000005fb770
115128fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000005fb770
115228fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=108407301192217C74BC9FE609CA642A66DBE98B
115328fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_91_for_KB2949927~31bf3856ad364e35~amd64~~6.1.1.5.cat'; file='\Device\HarddiskVolume2\Windows\System32\wintrust.dll'
115428fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
115528fc.18f8: supR3HardenedScreenImage/preload: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\wintrust.dll'
115628fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000003a4 pwszName=\Device\HarddiskVolume2\Windows\System32\shlwapi.dll
115728fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000005fb770
115828fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000005fb770
115928fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=0AB8D9C9D3E1FC95D01F9A984B16ED031BB40CD8
116028fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\shlwapi.dll'
116128fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
116228fc.18f8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll'
116328fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000398 pwszName=\Device\HarddiskVolume2\Windows\System32\Wldap32.dll
116428fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000005fb770
116528fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000005fb770
116628fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=87E73086F2528CF31D3AD5F0D71E04F8B942D5D8
116728fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\Wldap32.dll'
116828fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
116928fc.18f8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\Wldap32.dll'
117028fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000394 pwszName=\Device\HarddiskVolume2\Windows\System32\cryptnet.dll
117128fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000005fb770
117228fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000005fb770
117328fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=C1C670A9871F2BD448B2F0FA6127AC7A486B8D8F
117428fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_91_for_KB2949927~31bf3856ad364e35~amd64~~6.1.1.5.cat'; file='\Device\HarddiskVolume2\Windows\System32\cryptnet.dll'
117528fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
117628fc.18f8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\cryptnet.dll'
117728fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000260 pwszName=\Device\HarddiskVolume2\Windows\System32\gpapi.dll
117828fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000005fb770
117928fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000005fb770
118028fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=470795C189226F7BDB8E50F42104CC34488B9340
118128fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\gpapi.dll'
118228fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
118328fc.18f8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\gpapi.dll'
118428fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000001cc pwszName=\Device\HarddiskVolume2\Windows\System32\profapi.dll
118528fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000005fb770
118628fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000005fb770
118728fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2449672745D9BA339420451D13FA0380AA768231
118828fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\profapi.dll'
118928fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
119028fc.18f8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\profapi.dll'
119128fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000001c8 pwszName=\Device\HarddiskVolume2\Windows\System32\userenv.dll
119228fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000005fb770
119328fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000005fb770
119428fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=D3E1A2CC7367F751C19EBF4E6EDF5E9A10E47313
119528fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\userenv.dll'
119628fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
119728fc.18f8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\userenv.dll'
119828fc.18f8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll'
119928fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000001a0 pwszName=\Device\HarddiskVolume2\Windows\System32\bcrypt.dll
120028fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000005fb770
120128fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000005fb770
120228fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=62E377A1F0AD0C2EDC0A73CB3EFF841FF18D00D2
120328fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\bcrypt.dll'
120428fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
120528fc.18f8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\bcrypt.dll'
120628fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000019c pwszName=\Device\HarddiskVolume2\Windows\System32\ncrypt.dll
120728fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000005fb770
120828fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000005fb770
120928fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=D68DA0EBD4E0AA6C401CF7C54CEA904099DD3933
121028fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_52_for_KB2992611~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\Windows\System32\ncrypt.dll'
121128fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
121228fc.18f8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\ncrypt.dll'
121328fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000184 pwszName=\Device\HarddiskVolume2\Windows\System32\msctf.dll
121428fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000005fb770
121528fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000005fb770
121628fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=803AF52F95A9EFDFDA06C595023831EE36ACD3A8
121728fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\msctf.dll'
121828fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
121928fc.18f8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\msctf.dll'
122028fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000180 pwszName=\Device\HarddiskVolume2\Windows\System32\imm32.dll
122128fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000005fb770
122228fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000005fb770
122328fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=6EEE1AB3B6D79AFF857940FF5F51ED27698153EC
122428fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\imm32.dll'
122528fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
122628fc.18f8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\imm32.dll'
122728fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000017c pwszName=\Device\HarddiskVolume2\Windows\System32\usp10.dll
122828fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000005fb770
122928fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000005fb770
123028fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=1F1AA8340DE02FC1B6341EE2706E55D56EDF63B8
123128fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB2957509~31bf3856ad364e35~amd64~~6.1.1.2.cat'; file='\Device\HarddiskVolume2\Windows\System32\usp10.dll'
123228fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
123328fc.18f8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\usp10.dll'
123428fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000178 pwszName=\Device\HarddiskVolume2\Windows\System32\lpk.dll
123528fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000005fb770
123628fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000005fb770
123728fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=6FCA4D678614C8615E6E5C082BF3A4562FCF14EB
123828fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB2847311~31bf3856ad364e35~amd64~~6.1.1.2.cat'; file='\Device\HarddiskVolume2\Windows\System32\lpk.dll'
123928fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
124028fc.18f8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\lpk.dll'
124128fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000174 pwszName=\Device\HarddiskVolume2\Windows\System32\gdi32.dll
124228fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000005fb770
124328fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000005fb770
124428fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=7AEB59C2353484ADF282BEA358113ABD82C223B9
124528fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB2993651~31bf3856ad364e35~amd64~~6.1.1.3.cat'; file='\Device\HarddiskVolume2\Windows\System32\gdi32.dll'
124628fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
124728fc.18f8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\gdi32.dll'
124828fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000170 pwszName=\Device\HarddiskVolume2\Windows\System32\user32.dll
124928fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000005fb770
125028fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000005fb770
125128fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B723D1B8AD72750B0CF5F6BEC66171B1254ED879
125228fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\user32.dll'
125328fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
125428fc.18f8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\user32.dll'
125528fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000016c pwszName=\Device\HarddiskVolume2\Windows\System32\imagehlp.dll
125628fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000005fb770
125728fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000005fb770
125828fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2702EE05F1B717B0F2CE0FBE32784A47B8419DCA
125928fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_2_for_KB2893294~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\imagehlp.dll'
126028fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
126128fc.18f8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\imagehlp.dll'
126228fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000120 pwszName=\Device\HarddiskVolume2\Windows\System32\cryptbase.dll
126328fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000005fb770
126428fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000005fb770
126528fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=A965CC5DB13A5FB23BBB1B6B5FA6D400DC49462F
126628fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\cryptbase.dll'
126728fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
126828fc.18f8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\cryptbase.dll'
126928fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000114 pwszName=\Device\HarddiskVolume2\Windows\System32\sechost.dll
127028fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000005fb770
127128fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000005fb770
127228fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=3FA2A014BF360CDC0E203A174FFC9DC5343C5323
127328fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\sechost.dll'
127428fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
127528fc.18f8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\sechost.dll'
127628fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000108 pwszName=\Device\HarddiskVolume2\Windows\System32\advapi32.dll
127728fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000005fb770
127828fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000005fb770
127928fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=7C0A1C638CE7C1160F49C473EC1420BD3AB693C4
128028fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_5_for_KB2882822~31bf3856ad364e35~amd64~~6.1.1.2.cat'; file='\Device\HarddiskVolume2\Windows\System32\advapi32.dll'
128128fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
128228fc.18f8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\advapi32.dll'
128328fc.18f8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\rsaenh.dll'
128428fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000104 pwszName=\Device\HarddiskVolume2\Windows\System32\cryptsp.dll
128528fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000005fb770
128628fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000005fb770
128728fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=FE601E1BC89E11CA16D1CA31315BC348EFAF0C74
128828fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_91_for_KB2949927~31bf3856ad364e35~amd64~~6.1.1.5.cat'; file='\Device\HarddiskVolume2\Windows\System32\cryptsp.dll'
128928fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
129028fc.18f8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\cryptsp.dll'
129128fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000e4 pwszName=\Device\HarddiskVolume2\Windows\System32\msvcrt.dll
129228fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000005fb770
129328fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000005fb770
129428fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2CA2FD632B264C063162F71474266E3615B6420C
129528fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB2654428~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\Windows\System32\msvcrt.dll'
129628fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
129728fc.18f8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll'
129828fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000dc pwszName=\Device\HarddiskVolume2\Windows\System32\msasn1.dll
129928fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000005fb770
130028fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000005fb770
130128fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F2FF57DC30D774F93061607060DAA0DD15E39CCE
130228fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\msasn1.dll'
130328fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
130428fc.18f8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\msasn1.dll'
130528fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000d8 pwszName=\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
130628fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000005fb770
130728fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000005fb770
130828fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=03E871CFC4A3E7194619AFC99CEEA1EC75982D12
130928fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB2978668~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll'
131028fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
131128fc.18f8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll'
131228fc.18f8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll'
131328fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000028 pwszName=\Device\HarddiskVolume2\Windows\System32\KernelBase.dll
131428fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000005fb770
131528fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000005fb770
131628fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=57EB6F834C5A5D9585A660D91756134028A3B089
131728fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_54_for_KB2871997~31bf3856ad364e35~amd64~~6.1.2.5.cat'; file='\Device\HarddiskVolume2\Windows\System32\KernelBase.dll'
131828fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
131928fc.18f8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\KernelBase.dll'
132028fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000020 pwszName=\Device\HarddiskVolume2\Windows\System32\kernel32.dll
132128fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000005fb770
132228fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000005fb770
132328fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=5349346AE66DA4E3A7206628F484AC3B3AA43776
132428fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_54_for_KB2871997~31bf3856ad364e35~amd64~~6.1.2.5.cat'; file='\Device\HarddiskVolume2\Windows\System32\kernel32.dll'
132528fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
132628fc.18f8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\kernel32.dll'
132728fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll
132828fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\crypt32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000690010:C:\Windows\system32 [calling]
132928fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd100000 'C:\Windows\system32\crypt32.dll'
133028fc.18f8: supR3HardenedWinIsDesiredRootCA: Adding 0xc0f405ab4fb0ba00 CN=localhost, O=Skype Click to Call, OU=Skype Click to Call
133128fc.18f8: supR3HardenedWinIsDesiredRootCA: Adding 0x5ad46780fa5df300 DC=com, DC=microsoft, CN=Microsoft Root Certificate Authority
133228fc.18f8: supR3HardenedWinIsDesiredRootCA: Adding 0xea5386456178582b C=ZA, ST=Western Cape, L=Durbanville, O=Thawte, OU=Thawte Certification, CN=Thawte Timestamping CA
133328fc.18f8: supR3HardenedWinIsDesiredRootCA: Adding 0x3be670c1bd02a900 OU=Copyright (c) 1997 Microsoft Corp., OU=Microsoft Corporation, CN=Microsoft Root Authority
133428fc.18f8: supR3HardenedWinIsDesiredRootCA: Adding 0x4d3835aa4180b200 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2011
133528fc.18f8: supR3HardenedWinIsDesiredRootCA: Adding 0x646e3fe3ba08df00 C=US, O=MSFT, CN=Microsoft Authenticode(tm) Root Authority
133628fc.18f8: supR3HardenedWinIsDesiredRootCA: Adding 0xbf1f81e5a97406aa CN=USB\VID_0781&PID_5150 (libwdi autogenerated)
133728fc.18f8: supR3HardenedWinIsDesiredRootCA: Adding 0xece4e4289e08b900 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010
133828fc.18f8: supR3HardenedWinIsDesiredRootCA: Adding 0x5675ad49101bb3f2 CN=USB\VID_0764&PID_0501 (libwdi autogenerated)
133928fc.18f8: supR3HardenedWinIsDesiredRootCA: Adding 0x43a9cc371ff5385a O=Microsoft Trust Network, OU=Microsoft Corporation, OU=Microsoft Time Stamping Service Root, OU=Copyright (c) 1997 Microsoft Corp.
134028fc.18f8: supR3HardenedWinIsDesiredRootCA: Adding 0x2e2d2c7c68f0202e O=VeriSign Trust Network, OU=VeriSign, Inc., OU=VeriSign Time Stamping Service Root, OU=NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.
134128fc.18f8: supR3HardenedWinIsDesiredRootCA: Adding 0x91e3728b8b40d000 C=GB, ST=Greater Manchester, L=Salford, O=COMODO CA Limited, CN=COMODO Certification Authority
134228fc.18f8: supR3HardenedWinIsDesiredRootCA: Adding 0x61a3a33f81aace00 C=US, ST=UT, L=Salt Lake City, O=The USERTRUST Network, OU=http://www.usertrust.com, CN=UTN-USERFirst-Object
134328fc.18f8: supR3HardenedWinIsDesiredRootCA: Adding 0x9e5bc2d78b6a3636 C=ZA, ST=Western Cape, L=Cape Town, O=Thawte Consulting cc, OU=Certification Services Division, CN=Thawte Premium Server CA, [email protected]
134428fc.18f8: supR3HardenedWinIsDesiredRootCA: Adding 0xf4fd306318ccda00 C=US, O=GeoTrust Inc., CN=GeoTrust Global CA
134528fc.18f8: supR3HardenedWinIsDesiredRootCA: Adding 0x83085097e9afdf00 O=Digital Signature Trust Co., CN=DST Root CA X3
134628fc.18f8: supR3HardenedWinIsDesiredRootCA: Adding 0xe248b7eeee4af00 C=CH, O=SwissSign AG, CN=SwissSign Gold CA - G2
134728fc.18f8: supR3HardenedWinIsDesiredRootCA: Adding 0x780679907625cc00 OU=GlobalSign Root CA - R3, O=GlobalSign, CN=GlobalSign
134828fc.18f8: supR3HardenedWinIsDesiredRootCA: Adding 0x3d98ab22bb04a300 C=IE, O=Baltimore, OU=CyberTrust, CN=Baltimore CyberTrust Root
134928fc.18f8: supR3HardenedWinIsDesiredRootCA: Adding 0xa0ee62086758b15d C=US, O=Equifax, OU=Equifax Secure Certificate Authority
135028fc.18f8: supR3HardenedWinIsDesiredRootCA: Adding 0x8ff6fc03c1edbd00 C=US, ST=Arizona, L=Scottsdale, O=Starfield Technologies, Inc., CN=Starfield Root Certificate Authority - G2
135128fc.18f8: supR3HardenedWinIsDesiredRootCA: Adding 0xc6fa4243b695b600 C=US, O=Entrust, Inc., OU=www.entrust.net/CPS is incorporated by reference, OU=(c) 2006 Entrust, Inc., CN=Entrust Root Certification Authority
135228fc.18f8: supR3HardenedWinIsDesiredRootCA: Adding 0xa3ce8d99e60eda00 C=BE, O=GlobalSign nv-sa, OU=Root CA, CN=GlobalSign Root CA
135328fc.18f8: supR3HardenedWinIsDesiredRootCA: Adding 0xa671e9fec832b700 C=US, O=Starfield Technologies, Inc., OU=Starfield Class 2 Certification Authority
135428fc.18f8: supR3HardenedWinIsDesiredRootCA: Adding 0xa8de7211e13be200 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root CA
135528fc.18f8: supR3HardenedWinIsDesiredRootCA: Adding 0x14018a1bf29e595c C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority
135628fc.18f8: supR3HardenedWinIsDesiredRootCA: Adding 0xff3891b54348328 C=US, O=Entrust.net, OU=www.entrust.net/CPS incorp. by ref. (limits liab.), OU=(c) 1999 Entrust.net Limited, CN=Entrust.net Secure Server Certification Authority
135728fc.18f8: supR3HardenedWinIsDesiredRootCA: Adding 0xabd0695c5d11d15e C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority - G2, OU=(c) 1998 VeriSign, Inc. - For authorized use only, OU=VeriSign Trust Network
135828fc.18f8: supR3HardenedWinIsDesiredRootCA: Adding 0x7ae89c50f0b6a00f C=US, O=GTE Corporation, OU=GTE CyberTrust Solutions, Inc., CN=GTE CyberTrust Global Root
135928fc.18f8: supR3HardenedWinIsDesiredRootCA: Adding 0xd45980fbf0a0ac00 C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2006 thawte, Inc. - For authorized use only, CN=thawte Primary Root CA
136028fc.18f8: supR3HardenedWinIsDesiredRootCA: Adding 0x5a341635fb75d800 C=US, O=U.S. Government, OU=FPKI, CN=Federal Common Policy CA
136128fc.18f8: supR3HardenedWinIsDesiredRootCA: Adding 0x4d3835aa4180b200 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2011
136228fc.18f8: supR3HardenedWinIsDesiredRootCA: Adding 0xf5cd95e581a4ab00 C=US, O=SecureTrust Corporation, CN=SecureTrust CA
136328fc.18f8: supR3HardenedWinIsDesiredRootCA: Adding 0x298be035a30bab00 C=DE, O=Deutsche Telekom AG, OU=T-TeleSec Trust Center, CN=Deutsche Telekom Root CA 2
136428fc.18f8: supR3HardenedWinIsDesiredRootCA: Adding 0xabd0695c5d11d15e C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority - G2, OU=(c) 1998 VeriSign, Inc. - For authorized use only, OU=VeriSign Trust Network
136528fc.18f8: supR3HardenedWinIsDesiredRootCA: Adding 0x14018a1bf29e595c C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority
136628fc.18f8: supR3HardenedWinIsDesiredRootCA: Adding 0xab549401526569d3 L=Internet, O=VeriSign, Inc., OU=VeriSign Commercial Software Publishers CA
136728fc.18f8: supR3HardenedWinIsDesiredRootCA: Adding 0x9e5bc2d78b6a3636 C=ZA, ST=Western Cape, L=Cape Town, O=Thawte Consulting cc, OU=Certification Services Division, CN=Thawte Premium Server CA, [email protected]
136828fc.18f8: supR3HardenedWinIsDesiredRootCA: Adding 0xd4fbe673e5ccc600 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA
136928fc.18f8: supR3HardenedWinIsDesiredRootCA: Adding 0x16e64d2a56ccf200 C=US, ST=Arizona, L=Scottsdale, O=Starfield Technologies, Inc., OU=http://certificates.starfieldtech.com/repository/, CN=Starfield Services Root Certificate Authority
137028fc.18f8: supR3HardenedWinIsDesiredRootCA: Adding 0xb28612a94b4dad00 O=Entrust.net, OU=www.entrust.net/CPS_2048 incorp. by ref. (limits liab.), OU=(c) 1999 Entrust.net Limited, CN=Entrust.net Certification Authority (2048)
137128fc.18f8: supR3HardenedWinIsDesiredRootCA: Adding 0x14018a1bf29e595c C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority
137228fc.18f8: supR3HardenedWinIsDesiredRootCA: Adding 0x357a29080824af00 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2006 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G5
137328fc.18f8: supR3HardenedWinIsDesiredRootCA: Adding 0x59faf1086271bf00 C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com, Inc., CN=Go Daddy Root Certificate Authority - G2
137428fc.18f8: supR3HardenedWinIsDesiredRootCA: Adding 0x466cbc09db88c100 C=IL, O=StartCom Ltd., OU=Secure Digital Certificate Signing, CN=StartCom Certification Authority
137528fc.18f8: supR3HardenedWinIsDesiredRootCA: Adding 0xece4e4289e08b900 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010
137628fc.18f8: supR3HardenedWinIsDesiredRootCA: Adding 0x30669a4e82fa800 C=US, O=America Online Inc., CN=America Online Root Certification Authority 1
137728fc.18f8: supR3HardenedWinIsDesiredRootCA: Adding 0x7cd4ff7b15b8be00 C=US, O=GeoTrust Inc., CN=GeoTrust Primary Certification Authority
137828fc.18f8: supR3HardenedWinIsDesiredRootCA: Adding 0x9259c8abe5ca713a L=ValiCert Validation Network, O=ValiCert, Inc., OU=ValiCert Class 2 Policy Validation Authority, CN=http://www.valicert.com/, [email protected]
137928fc.18f8: supR3HardenedWinIsDesiredRootCA: Adding 0x491857ead79dde00 C=US, O=The Go Daddy Group, Inc., OU=Go Daddy Class 2 Certification Authority
138028fc.18f8: supR3HardenedWinIsDesiredRootCA: Adding 0xab549401526569d3 L=Internet, O=VeriSign, Inc., OU=VeriSign Commercial Software Publishers CA
138128fc.18f8: supR3HardenedWinIsDesiredRootCA: Adding 0xe66b56ffc86e50a4 C=ZA, ST=Western Cape, L=Cape Town, O=Thawte Consulting cc, OU=Certification Services Division, CN=Thawte Server CA, [email protected]
138228fc.18f8: supR3HardenedWinIsDesiredRootCA: Adding 0x92ac5ed85c2d0e9b C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2007 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G4
138328fc.18f8: supR3HardenedWinIsDesiredRootCA: Adding 0x1f78fc529cbacb00 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 1999 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G3
138428fc.18f8: supR3HardenedWinIsDesiredRootCA: Adding 0x8043e4ce150ead00 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID Root CA
138528fc.18f8: supR3HardenedWinIsDesiredRootCA: Adding 0xa8b43f38c3f7b100 C=US, ST=UT, L=Salt Lake City, O=The USERTRUST Network, OU=http://www.usertrust.com, CN=UTN-USERFirst-Hardware
138628fc.18f8: supR3HardenedWinIsDesiredRootCA: Adding 0xf2e6331af7b700 C=SE, O=AddTrust AB, OU=AddTrust External TTP Network, CN=AddTrust External CA Root
138728fc.18f8: supR3HardenedWinRetrieveTrustedRootCAs: cAdded=57
138828fc.18f8: SUPR3HardenedMain: Load Runtime...
138928fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
139028fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
139128fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ws2_32.dll'.
139228fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'rpcrt4.dll'.
139328fc.18f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll)WinVerifyTrust
139428fc.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
139528fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
139628fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
139728fc.18f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
139828fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
139928fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
140028fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000448 pwszName=\Device\HarddiskVolume2\Windows\System32\ws2_32.dll
140128fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000005fb770
140228fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000005fb770
140328fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=3EF3BDC1E84DFA17EA056313214EE88EC3E66F79
140428fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\ws2_32.dll'
140528fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
140628fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
140728fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'rpcrt4.dll'.
140828fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'nsi.dll'.
140928fc.18f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ws2_32.dll)WinVerifyTrust
141028fc.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
141128fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
141228fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
141328fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
141428fc.18f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll)WinVerifyTrust
141528fc.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
141628fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
141728fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
141828fc.18f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll)WinVerifyTrust
141928fc.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
142028fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
142128fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
142228fc.18f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
142328fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
142428fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume2\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
142528fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000460 pwszName=\Device\HarddiskVolume2\Windows\System32\nsi.dll
142628fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000005fb770
142728fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000005fb770
142828fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=7AFD8538945F2D05BC1AF949B9B19B7D2D9FBBF8
142928fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\nsi.dll'
143028fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
143128fc.18f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\nsi.dll)WinVerifyTrust
143228fc.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\nsi.dll
143328fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
143428fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
143528fc.18f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
143628fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
143728fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
143828fc.18f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
143928fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000098add0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
144028fc.18f8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
144128fc.18f8: supR3HardenedDllNotificationCallback: load 000007feef0b0000 LB 0x00531000 C:\Program Files\Oracle\VirtualBox\VBoxRT.dll [fFlags=0x0]
144228fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
144328fc.18f8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
144428fc.18f8: supR3HardenedDllNotificationCallback: load 000000006fed0000 LB 0x000d2000 C:\Program Files\Oracle\VirtualBox\MSVCR100.dll [fFlags=0x0]
144528fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
144628fc.18f8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
144728fc.18f8: supR3HardenedDllNotificationCallback: load 000000006fb50000 LB 0x00098000 C:\Program Files\Oracle\VirtualBox\MSVCP100.dll [fFlags=0x0]
144828fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
144928fc.18f8: supR3HardenedDllNotificationCallback: load 000007fefe7f0000 LB 0x0004d000 C:\Windows\system32\WS2_32.dll [fFlags=0x0]
145028fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
145128fc.18f8: supR3HardenedDllNotificationCallback: load 000007fefe450000 LB 0x00008000 C:\Windows\system32\NSI.dll [fFlags=0x0]
145228fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\nsi.dll
145328fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
145428fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000008e5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files\nodejs\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Users\rjs7\AppData\Roaming\npm [calling]
145528fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feef0b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
145628fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
145728fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000008e5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files\nodejs\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Users\rjs7\AppData\Roaming\npm [calling]
145828fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feef0b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
145928fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
146028fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000008e5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files\nodejs\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Users\rjs7\AppData\Roaming\npm [calling]
146128fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feef0b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
146228fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
146328fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000008e5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files\nodejs\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Users\rjs7\AppData\Roaming\npm [calling]
146428fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feef0b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
146528fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
146628fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000008e5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files\nodejs\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Users\rjs7\AppData\Roaming\npm [calling]
146728fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feef0b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
146828fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
146928fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000008e5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files\nodejs\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Users\rjs7\AppData\Roaming\npm [calling]
147028fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feef0b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
147128fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feef0b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
147228fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feef0b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
147328fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feef0b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
147428fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feef0b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
147528fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feef0b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
147628fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feef0b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
147728fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feef0b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
147828fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
147928fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000008e5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files\nodejs\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Users\rjs7\AppData\Roaming\npm [calling]
148028fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feef0b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
148128fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feef0b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
148228fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feef0b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
148328fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feef0b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
148428fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feef0b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
148528fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feef0b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
148628fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feef0b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
148728fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feef0b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
148828fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feef0b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
148928fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feef0b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
149028fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feef0b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
149128fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feef0b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
149228fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feef0b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
149328fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feef0b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
149428fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feef0b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
149528fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feef0b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
149628fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
149728fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000008e5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files\nodejs\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Users\rjs7\AppData\Roaming\npm [calling]
149828fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feef0b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
149928fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feef0b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
150028fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feef0b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
150128fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feef0b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
150228fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll
150328fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000965670:C:\Windows\system32 [calling]
150428fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcfa0000 'C:\Windows\system32\Wintrust.dll'
150528fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll
150628fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\crypt32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000965670:C:\Windows\system32 [calling]
150728fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd100000 'C:\Windows\system32\crypt32.dll'
150828fc.18f8: SUPR3HardenedMain: Load TrustedMain...
150928fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'opengl32.dll'.
151028fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
151128fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcp100.dll'.
151228fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcr100.dll'.
151328fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qtcorevbox4.dll'.
151428fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'qtguivbox4.dll'.
151528fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'qtnetworkvbox4.dll'.
151628fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'qtopenglvbox4.dll'.
151728fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'user32.dll'.
151828fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'gdi32.dll'.
151928fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'advapi32.dll'.
152028fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'shell32.dll'.
152128fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'ole32.dll'.
152228fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'oleaut32.dll'.
152328fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #15 'comdlg32.dll'.
152428fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'winmm.dll'.
152528fc.18f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.dll)WinVerifyTrust
152628fc.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.dll
152728fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
152828fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
152928fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004a0 pwszName=\Device\HarddiskVolume2\Windows\System32\winmm.dll
153028fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000005fb770
153128fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000005fb770
153228fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=82E2B2A7826F88BEB98FFF0540C9BDB0A12F001A
153328fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\winmm.dll'
153428fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
153528fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
153628fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
153728fc.18f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\winmm.dll)WinVerifyTrust
153828fc.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\winmm.dll
153928fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comdlg32.dll'...
154028fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'comdlg32.dll' -> '\Device\HarddiskVolume2\Windows\System32\comdlg32.dll' [rcNtRedir=0xc0150008]
154128fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000480 pwszName=\Device\HarddiskVolume2\Windows\System32\comdlg32.dll
154228fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000005fb770
154328fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000005fb770
154428fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=66EE5BDFFA413AEA9E1FE7838A08646E94136DA5
154528fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\comdlg32.dll'
154628fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
154728fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
154828fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'shlwapi.dll'.
154928fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
155028fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'gdi32.dll'.
155128fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'comctl32.dll'.
155228fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'shell32.dll'.
155328fc.18f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\comdlg32.dll)WinVerifyTrust
155428fc.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\comdlg32.dll
155528fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
155628fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
155728fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000494 pwszName=\Device\HarddiskVolume2\Windows\System32\oleaut32.dll
155828fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000005fb770
155928fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000005fb770
156028fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=59C9A3379D97CB80EFB9D9152AF4E0240DDF8B29
156128fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3006226~31bf3856ad364e35~amd64~~6.1.1.4.cat'; file='\Device\HarddiskVolume2\Windows\System32\oleaut32.dll'
156228fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
156328fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ole32.dll'.
156428fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
156528fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
156628fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'user32.dll'.
156728fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'gdi32.dll'.
156828fc.18f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\oleaut32.dll)WinVerifyTrust
156928fc.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
157028fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
157128fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
157228fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004ac pwszName=\Device\HarddiskVolume2\Windows\System32\ole32.dll
157328fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000005fb770
157428fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000005fb770
157528fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2E64AE329BD5124592BC8CB0B327AA3B95DC65B7
157628fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\ole32.dll'
157728fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
157828fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
157928fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
158028fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'user32.dll'.
158128fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'rpcrt4.dll'.
158228fc.18f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ole32.dll)WinVerifyTrust
158328fc.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ole32.dll
158428fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
158528fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
158628fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004a4 pwszName=\Device\HarddiskVolume2\Windows\System32\shell32.dll
158728fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000005fb770
158828fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000005fb770
158928fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=8D11B9B481EE916E64C94F8ECA71C2995A2999B7
159028fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_2_for_KB2980245~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\Windows\System32\shell32.dll'
159128fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
159228fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
159328fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #21 'shlwapi.dll'.
159428fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'user32.dll'.
159528fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #24 'gdi32.dll'.
159628fc.18f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\shell32.dll)WinVerifyTrust
159728fc.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\shell32.dll
159828fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
159928fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
160028fc.18f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
160128fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
160228fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
160328fc.18f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll
160428fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
160528fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
160628fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtopenglvbox4.dll'...
160728fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtopenglvbox4.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qtopenglvbox4.dll' [rcNtRedir=0xc0150008]
160828fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'opengl32.dll'.
160928fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
161028fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
161128fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qtguivbox4.dll'.
161228fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qtcorevbox4.dll'.
161328fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcr100.dll'.
161428fc.18f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll)WinVerifyTrust
161528fc.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll
161628fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtnetworkvbox4.dll'...
161728fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtnetworkvbox4.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qtnetworkvbox4.dll' [rcNtRedir=0xc0150008]
161828fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ws2_32.dll'.
161928fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'qtcorevbox4.dll'.
162028fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcr100.dll'.
162128fc.18f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtNetworkVBox4.dll)WinVerifyTrust
162228fc.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtNetworkVBox4.dll
162328fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtguivbox4.dll'...
162428fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtguivbox4.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qtguivbox4.dll' [rcNtRedir=0xc0150008]
162528fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
162628fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'comdlg32.dll'.
162728fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'oleaut32.dll'.
162828fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'imm32.dll'.
162928fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'winmm.dll'.
163028fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'winspool.drv'.
163128fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ole32.dll'.
163228fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'user32.dll'.
163328fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'advapi32.dll'.
163428fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'shell32.dll'.
163528fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'qtcorevbox4.dll'.
163628fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'msvcp100.dll'.
163728fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'msvcr100.dll'.
163828fc.18f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll)WinVerifyTrust
163928fc.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll
164028fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtcorevbox4.dll'...
164128fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtcorevbox4.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qtcorevbox4.dll' [rcNtRedir=0xc0150008]
164228fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
164328fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'ole32.dll'.
164428fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
164528fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ws2_32.dll'.
164628fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcp100.dll'.
164728fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcr100.dll'.
164828fc.18f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll)WinVerifyTrust
164928fc.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll
165028fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
165128fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
165228fc.18f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
165328fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
165428fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
165528fc.18f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
165628fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
165728fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
165828fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
165928fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
166028fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004e8 pwszName=\Device\HarddiskVolume2\Windows\System32\opengl32.dll
166128fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000005fb770
166228fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000005fb770
166328fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=608AC397FCC42B9FBAE25CB8C25EAF4C19AA384D
166428fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\opengl32.dll'
166528fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
166628fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
166728fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
166828fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'gdi32.dll'.
166928fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'glu32.dll'.
167028fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ddraw.dll'.
167128fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'user32.dll'.
167228fc.18f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\opengl32.dll)WinVerifyTrust
167328fc.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\opengl32.dll
167428fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
167528fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
167628fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ddraw.dll'...
167728fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ddraw.dll' -> '\Device\HarddiskVolume2\Windows\System32\ddraw.dll' [rcNtRedir=0xc0150008]
167828fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004dc pwszName=\Device\HarddiskVolume2\Windows\System32\ddraw.dll
167928fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000005fb770
168028fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000005fb770
168128fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=24C763EA54CD792A0F1618411061DC356EE31FF6
168228fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\ddraw.dll'
168328fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
168428fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
168528fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
168628fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'dciman32.dll'.
168728fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
168828fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'setupapi.dll'.
168928fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'dwmapi.dll'.
169028fc.18f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ddraw.dll)WinVerifyTrust
169128fc.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ddraw.dll
169228fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'glu32.dll'...
169328fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'glu32.dll' -> '\Device\HarddiskVolume2\Windows\System32\glu32.dll' [rcNtRedir=0xc0150008]
169428fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004d8 pwszName=\Device\HarddiskVolume2\Windows\System32\glu32.dll
169528fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000005fb770
169628fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000005fb770
169728fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=60E45AB914E06A11F44EA76C6EF750AF892F9EA2
169828fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\glu32.dll'
169928fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
170028fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
170128fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'opengl32.dll'.
170228fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
170328fc.18f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\glu32.dll)WinVerifyTrust
170428fc.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\glu32.dll
170528fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
170628fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
170728fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
170828fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
170928fc.18f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
171028fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
171128fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
171228fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
171328fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
171428fc.18f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
171528fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
171628fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
171728fc.18f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
171828fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
171928fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
172028fc.18f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
172128fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
172228fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
172328fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
172428fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
172528fc.18f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
172628fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
172728fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
172828fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
172928fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
173028fc.18f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
173128fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
173228fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
173328fc.18f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
173428fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtcorevbox4.dll'...
173528fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtcorevbox4.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qtcorevbox4.dll' [rcNtRedir=0xc0150008]
173628fc.18f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll
173728fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
173828fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
173928fc.18f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
174028fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
174128fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
174228fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
174328fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
174428fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
174528fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
174628fc.18f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
174728fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winspool.drv'...
174828fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'winspool.drv' -> '\Device\HarddiskVolume2\Windows\System32\winspool.drv' [rcNtRedir=0xc0150008]
174928fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004cc pwszName=\Device\HarddiskVolume2\Windows\System32\winspool.drv
175028fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000005fb770
175128fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000005fb770
175228fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=C89A2ED7B99A056D78CA6BAC9CCAB8B1FF119A14
175328fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\winspool.drv'
175428fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
175528fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
175628fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
175728fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
175828fc.18f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\winspool.drv)WinVerifyTrust
175928fc.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\winspool.drv
176028fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
176128fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
176228fc.18f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
176328fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
176428fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume2\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
176528fc.18f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\imm32.dll
176628fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
176728fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
176828fc.18f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
176928fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comdlg32.dll'...
177028fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'comdlg32.dll' -> '\Device\HarddiskVolume2\Windows\System32\comdlg32.dll' [rcNtRedir=0xc0150008]
177128fc.18f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\comdlg32.dll
177228fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
177328fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
177428fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
177528fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
177628fc.18f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
177728fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtcorevbox4.dll'...
177828fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtcorevbox4.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qtcorevbox4.dll' [rcNtRedir=0xc0150008]
177928fc.18f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll
178028fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
178128fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
178228fc.18f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
178328fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
178428fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
178528fc.18f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
178628fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtcorevbox4.dll'...
178728fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtcorevbox4.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qtcorevbox4.dll' [rcNtRedir=0xc0150008]
178828fc.18f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll
178928fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtguivbox4.dll'...
179028fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtguivbox4.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qtguivbox4.dll' [rcNtRedir=0xc0150008]
179128fc.18f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll
179228fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
179328fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
179428fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
179528fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
179628fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
179728fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
179828fc.18f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
179928fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
180028fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
180128fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
180228fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
180328fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
180428fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
180528fc.18f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll
180628fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
180728fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
180828fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
180928fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
181028fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
181128fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
181228fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
181328fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
181428fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
181528fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
181628fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
181728fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
181828fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
181928fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
182028fc.18f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll
182128fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
182228fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
182328fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
182428fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
182528fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
182628fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
182728fc.18f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
182828fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
182928fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
183028fc.18f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
183128fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comctl32.dll'...
183228fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'comctl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\comctl32.dll' [rcNtRedir=0x0]
183328fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004f8 pwszName=\Device\HarddiskVolume2\Windows\System32\comctl32.dll
183428fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000005fb770
183528fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000005fb770
183628fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=5A2FB6B10717AFC03CD9FE6E8F1337A8EA94BF9B
183728fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB2864058~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\comctl32.dll'
183828fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
183928fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'advapi32.dll'.
184028fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
184128fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
184228fc.18f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\comctl32.dll)WinVerifyTrust
184328fc.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\comctl32.dll
184428fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
184528fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
184628fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
184728fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
184828fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
184928fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
185028fc.18f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll
185128fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
185228fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
185328fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
185428fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
185528fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
185628fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
185728fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
185828fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
185928fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
186028fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
186128fc.18f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll
186228fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
186328fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
186428fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
186528fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
186628fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
186728fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
186828fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
186928fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
187028fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
187128fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
187228fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
187328fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
187428fc.18f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
187528fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
187628fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
187728fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dwmapi.dll'...
187828fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'dwmapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\dwmapi.dll' [rcNtRedir=0xc0150008]
187928fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004bc pwszName=\Device\HarddiskVolume2\Windows\System32\dwmapi.dll
188028fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000005fb770
188128fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000005fb770
188228fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B79EE7B5AD74EF51A849809202E043183A2C727E
188328fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\dwmapi.dll'
188428fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
188528fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
188628fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
188728fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
188828fc.18f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\dwmapi.dll)WinVerifyTrust
188928fc.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\dwmapi.dll
189028fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
189128fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
189228fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000500 pwszName=\Device\HarddiskVolume2\Windows\System32\setupapi.dll
189328fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000005fb770
189428fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000005fb770
189528fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=1499C4FEA6E143F9BEC35B4FFA098917D3A6EBF2
189628fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\setupapi.dll'
189728fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
189828fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'cfgmgr32.dll'.
189928fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcrt.dll'.
190028fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'gdi32.dll'.
190128fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
190228fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'user32.dll'.
190328fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'oleaut32.dll'.
190428fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'devobj.dll'.
190528fc.18f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\setupapi.dll)WinVerifyTrust
190628fc.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\setupapi.dll
190728fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
190828fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
190928fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dciman32.dll'...
191028fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'dciman32.dll' -> '\Device\HarddiskVolume2\Windows\System32\dciman32.dll' [rcNtRedir=0xc0150008]
191128fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004f0 pwszName=\Device\HarddiskVolume2\Windows\System32\dciman32.dll
191228fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000005fb770
191328fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000005fb770
191428fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F097BF0B081F54722F0A01EF1CC13AECA64B12F0
191528fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB2847311~31bf3856ad364e35~amd64~~6.1.1.2.cat'; file='\Device\HarddiskVolume2\Windows\System32\dciman32.dll'
191628fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
191728fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
191828fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'gdi32.dll'.
191928fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
192028fc.18f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\dciman32.dll)WinVerifyTrust
192128fc.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\dciman32.dll
192228fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
192328fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
192428fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
192528fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
192628fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
192728fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
192828fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
192928fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
193028fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
193128fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
193228fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'devobj.dll'...
193328fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'devobj.dll' -> '\Device\HarddiskVolume2\Windows\System32\devobj.dll' [rcNtRedir=0xc0150008]
193428fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000050c pwszName=\Device\HarddiskVolume2\Windows\System32\devobj.dll
193528fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000005fb770
193628fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000005fb770
193728fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B410A095222E69F0ECE7D66E4AC27A7125D2EB5A
193828fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\devobj.dll'
193928fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
194028fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
194128fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'cfgmgr32.dll'.
194228fc.18f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\devobj.dll)WinVerifyTrust
194328fc.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\devobj.dll
194428fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
194528fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
194628fc.18f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
194728fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
194828fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
194928fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
195028fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
195128fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
195228fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
195328fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
195428fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
195528fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
195628fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
195728fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000514 pwszName=\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll
195828fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000005fb770
195928fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000005fb770
196028fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=8F731777EFC4BC982C1E1467FBF29A74CC14D93A
196128fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll'
196228fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
196328fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
196428fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'rpcrt4.dll'.
196528fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
196628fc.18f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll)WinVerifyTrust
196728fc.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll
196828fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
196928fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
197028fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
197128fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
197228fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
197328fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
197428fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
197528fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
197628fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
197728fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
197828fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
197928fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
198028fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
198128fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
198228fc.18f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll
198328fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
198428fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
198528fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VirtualBox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000098add0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
198628fc.18f8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.dll
198728fc.18f8: supR3HardenedDllNotificationCallback: load 000007feed9c0000 LB 0x00871000 C:\Program Files\Oracle\VirtualBox\VirtualBox.dll [fFlags=0x0]
198828fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.dll
198928fc.18f8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
199028fc.18f8: supR3HardenedDllNotificationCallback: load 000007fef13d0000 LB 0x0011d000 C:\Windows\system32\OPENGL32.dll [fFlags=0x0]
199128fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
199228fc.18f8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\glu32.dll
199328fc.18f8: supR3HardenedDllNotificationCallback: load 000007fef85c0000 LB 0x0002d000 C:\Windows\system32\GLU32.dll [fFlags=0x0]
199428fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\glu32.dll
199528fc.18f8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ddraw.dll
199628fc.18f8: supR3HardenedDllNotificationCallback: load 000007fef1030000 LB 0x000f1000 C:\Windows\system32\DDRAW.dll [fFlags=0x0]
199728fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ddraw.dll
199828fc.18f8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dciman32.dll
199928fc.18f8: supR3HardenedDllNotificationCallback: load 000007fef85b0000 LB 0x00008000 C:\Windows\system32\DCIMAN32.dll [fFlags=0x0]
200028fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dciman32.dll
200128fc.18f8: supR3HardenedDllNotificationCallback: load 000007fefe460000 LB 0x001d7000 C:\Windows\system32\SETUPAPI.dll [fFlags=0x0]
200228fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\setupapi.dll
200328fc.18f8: supR3HardenedDllNotificationCallback: load 000007fefd0b0000 LB 0x00036000 C:\Windows\system32\CFGMGR32.dll [fFlags=0x0]
200428fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll
200528fc.18f8: supR3HardenedDllNotificationCallback: load 000007fefe640000 LB 0x000d7000 C:\Windows\system32\OLEAUT32.dll [fFlags=0x0]
200628fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
200728fc.18f8: supR3HardenedDllNotificationCallback: load 000007fefeca0000 LB 0x00203000 C:\Windows\system32\ole32.dll [fFlags=0x0]
200828fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
200928fc.18f8: supR3HardenedDllNotificationCallback: load 000007fefd280000 LB 0x0001a000 C:\Windows\system32\DEVOBJ.dll [fFlags=0x0]
201028fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\devobj.dll
201128fc.18f8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dwmapi.dll
201228fc.18f8: supR3HardenedDllNotificationCallback: load 000007fefb260000 LB 0x00018000 C:\Windows\system32\dwmapi.dll [fFlags=0x0]
201328fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dwmapi.dll
201428fc.18f8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll
201528fc.18f8: supR3HardenedDllNotificationCallback: load 000000006e2a0000 LB 0x002de000 C:\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll [fFlags=0x0]
201628fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll
201728fc.18f8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll
201828fc.18f8: supR3HardenedDllNotificationCallback: load 000000006d930000 LB 0x00969000 C:\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll [fFlags=0x0]
201928fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll
202028fc.18f8: supR3HardenedDllNotificationCallback: load 000007fefd3d0000 LB 0x00097000 C:\Windows\system32\COMDLG32.dll [fFlags=0x0]
202128fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\comdlg32.dll
202228fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'advapi32.dll'.
202328fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
202428fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
202528fc.18f8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18201_none_a4d3b9377117c3df\comctl32.dll)
202628fc.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18201_none_a4d3b9377117c3df\comctl32.dll
202728fc.18f8: supR3HardenedDllNotificationCallback: load 000007fef7fe0000 LB 0x000a0000 C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18201_none_a4d3b9377117c3df\COMCTL32.dll [fFlags=0x0]
202828fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18201_none_a4d3b9377117c3df\comctl32.dll [avoiding WinVerifyTrust]
202928fc.18f8: supR3HardenedDllNotificationCallback: load 000007fefd470000 LB 0x00d88000 C:\Windows\system32\SHELL32.dll [fFlags=0x0]
203028fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
203128fc.18f8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
203228fc.18f8: supR3HardenedDllNotificationCallback: load 000007fefa3c0000 LB 0x0003b000 C:\Windows\system32\WINMM.dll [fFlags=0x0]
203328fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
203428fc.18f8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winspool.drv
203528fc.18f8: supR3HardenedDllNotificationCallback: load 000007fef7db0000 LB 0x00071000 C:\Windows\system32\WINSPOOL.DRV [fFlags=0x0]
203628fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winspool.drv
203728fc.18f8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtNetworkVBox4.dll
203828fc.18f8: supR3HardenedDllNotificationCallback: load 000000006fa40000 LB 0x00105000 C:\Program Files\Oracle\VirtualBox\QtNetworkVBox4.dll [fFlags=0x0]
203928fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtNetworkVBox4.dll
204028fc.18f8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll
204128fc.18f8: supR3HardenedDllNotificationCallback: load 000000006d850000 LB 0x000dc000 C:\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll [fFlags=0x0]
204228fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll
204328fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000504 pwszName=\Device\HarddiskVolume2\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18201_none_a4d3b9377117c3df\comctl32.dll
204428fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000005fb770
204528fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000005fb770
204628fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=5A2FB6B10717AFC03CD9FE6E8F1337A8EA94BF9B
204728fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB2864058~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18201_none_a4d3b9377117c3df\comctl32.dll'
204828fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
204928fc.18f8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18201_none_a4d3b9377117c3df\comctl32.dll'
205028fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\imm32.dll
205128fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
205228fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
205328fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
205428fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
205528fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
205628fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
205728fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\imm32.dll (Input=imm32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000098b1c0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
205828fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe840000 'C:\Windows\system32\imm32.dll'
205928fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed9c0000 'C:\Program Files\Oracle\VirtualBox\VirtualBox.dll'
206028fc.18f8: SUPR3HardenedMain: Calling TrustedMain (000007feed9c1ca0)...
206128fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
206228fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\winmm.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000098add0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
206328fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa3c0000 'C:\Windows\system32\winmm.dll'
206428fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cryptbase.dll
206528fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTBASE.dll (Input=CRYPTBASE.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000098add0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
206628fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcdb0000 'C:\Windows\system32\CRYPTBASE.dll'
206728fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
206828fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000098add0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
206928fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd470000 'C:\Windows\system32\shell32.dll'
207028fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll
207128fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000098add0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
207228fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077070000 'C:\Windows\system32\kernel32.dll'
207328fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000005b8 pwszName=\Device\HarddiskVolume2\Windows\System32\uxtheme.dll
207428fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000005fb770
207528fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000005fb770
207628fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=936D45CC7026757A151F62882B557DD75D5FCB21
207728fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\uxtheme.dll'
207828fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
207928fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
208028fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
208128fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'gdi32.dll'.
208228fc.18f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\uxtheme.dll)WinVerifyTrust
208328fc.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
208428fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
208528fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
208628fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
208728fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
208828fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
208928fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
209028fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000098add0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
209128fc.18f8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
209228fc.18f8: supR3HardenedDllNotificationCallback: load 000007fefb690000 LB 0x00056000 C:\Windows\system32\uxtheme.dll [fFlags=0x0]
209328fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
209428fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefb690000 'C:\Windows\system32\uxtheme.dll'
209528fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
209628fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000098add0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
209728fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefb690000 'C:\Windows\system32\uxtheme.dll'
209828fc.18f8: supR3HardenedMonitor_LdrLoadDll: error opening 'C:\Windows\system32\wintab32.dll': 0 (NtPath=\??\C:\Windows\system32\wintab32.dll; Input=C:\Windows\system32\wintab32.dll; rcNtGetDll=0x0
209928fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wintab32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000098add0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
210028fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000135 'C:\Windows\system32\wintab32.dll'
210128fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000076f70000 'C:\Windows\system32\user32.dll'
210228fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
210328fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000098add0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
210428fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefb690000 'C:\Windows\system32\uxtheme.dll'
210528fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000076f70000 'C:\Windows\system32\user32.dll'
210628fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefeb50000 'C:\Windows\system32\advapi32.dll'
210728fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\userenv.dll
210828fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\userenv.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000098add0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
210928fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcff0000 'C:\Windows\system32\userenv.dll'
211028fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll
211128fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000098add0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
211228fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077070000 'C:\Windows\system32\kernel32.dll'
211328fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000005f0 pwszName=\Device\HarddiskVolume2\Windows\System32\clbcatq.dll
211428fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000005fb770
211528fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000005fb770
211628fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B01469787CE9D8C6FEE98FB207652B88B8494526
211728fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\clbcatq.dll'
211828fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
211928fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
212028fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'ole32.dll'.
212128fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
212228fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
212328fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
212428fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'rpcrt4.dll'.
212528fc.18f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\clbcatq.dll)WinVerifyTrust
212628fc.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\clbcatq.dll
212728fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
212828fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
212928fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
213028fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
213128fc.18f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
213228fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
213328fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
213428fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
213528fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
213628fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
213728fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
213828fc.18f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
213928fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
214028fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
214128fc.18f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
214228fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CLBCatQ.DLL (Input=CLBCatQ.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000098add0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
214328fc.18f8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\clbcatq.dll
214428fc.18f8: supR3HardenedDllNotificationCallback: load 000007fefd310000 LB 0x00099000 C:\Windows\system32\CLBCatQ.DLL [fFlags=0x0]
214528fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\clbcatq.dll
214628fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd310000 'C:\Windows\system32\CLBCatQ.DLL'
214728fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
214828fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ADVAPI32.dll (Input=ADVAPI32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000098b520:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
214928fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefeb50000 'C:\Windows\system32\ADVAPI32.dll'
215028fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cryptsp.dll
215128fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTSP.dll (Input=CRYPTSP.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000098b400:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
215228fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc750000 'C:\Windows\system32\CRYPTSP.dll'
215328fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000610 pwszName=\Device\HarddiskVolume2\Windows\System32\RpcRtRemote.dll
215428fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000005fb770
215528fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000005fb770
215628fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=DFC4A7C7E103D324218E6EF5D219B953746D6EC1
215728fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\RpcRtRemote.dll'
215828fc.18f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
215928fc.18f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'rpcrt4.dll'.
216028fc.18f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\RpcRtRemote.dll)WinVerifyTrust
216128fc.18f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\RpcRtRemote.dll
216228fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
216328fc.18f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
216428fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\RpcRtRemote.dll (Input=RpcRtRemote.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000098b400:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
216528fc.18f8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\RpcRtRemote.dll
216628fc.18f8: supR3HardenedDllNotificationCallback: load 000007fefce60000 LB 0x00014000 C:\Windows\system32\RpcRtRemote.dll [fFlags=0x0]
216728fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\RpcRtRemote.dll
216828fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefce60000 'C:\Windows\system32\RpcRtRemote.dll'
216928fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff3b0000 'C:\Windows\system32\gdi32.dll'
217028fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
217128fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000098b880:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
217228fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd470000 'C:\Windows\system32\shell32.dll'
217328fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
217428fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000098b880:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
217528fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd470000 'C:\Windows\system32\shell32.dll'
217628fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
217728fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000098b880:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
217828fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd470000 'C:\Windows\system32\shell32.dll'
217928fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
218028fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000098b880:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
218128fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd470000 'C:\Windows\system32\shell32.dll'
218228fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd470000 'C:\Windows\system32\shell32.dll'
218328fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd470000 'C:\Windows\system32\shell32.dll'
218428fc.18f8: supR3HardenedMonitor_LdrLoadDll: error opening 'C:\Windows\system32\wintab32.dll': 0 (NtPath=\??\C:\Windows\system32\wintab32.dll; Input=C:\Windows\system32\wintab32.dll; rcNtGetDll=0x0
218528fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wintab32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000098b880:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
218628fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000135 'C:\Windows\system32\wintab32.dll'
218728fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000076f70000 'C:\Windows\system32\user32.dll'
218828fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
218928fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ole32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000098b880:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
219028fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefeca0000 'C:\Windows\system32\ole32.dll'
219128fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
219228fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ole32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000098bac0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
219328fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefeca0000 'C:\Windows\system32\ole32.dll'
219428fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msctf.dll
219528fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\MSCTF.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000006b69d0:C:\Windows\system32;C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
219628fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe910000 'C:\Windows\system32\MSCTF.dll'
219728fc.18f8: supR3HardenedMonitor_LdrLoadDll: 'C:\Windows\system32\comctl32.dll' -> 'C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18201_none_a4d3b9377117c3df\comctl32.dll' [redir]
219828fc.18f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18201_none_a4d3b9377117c3df\comctl32.dll
219928fc.18f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18201_none_a4d3b9377117c3df\comctl32.dll (Input=C:\Windows\system32\comctl32.dll, rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=000000000098bac0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
220028fc.18f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef7fe0000 'C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18201_none_a4d3b9377117c3df\comctl32.dll'
220128fc.18f8: Terminating the normal way: rcExit=1
22021d08.99c: supR3HardNtChildWaitFor[2]: Quitting: ExitCode=0x1 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 8773 ms, the end);
22031558.1090: supR3HardNtChildWaitFor[1]: Quitting: ExitCode=0x1 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 9371 ms, the end);

© 2024 Oracle Support Privacy / Do Not Sell My Info Terms of Use Trademark Policy Automated Access Etiquette