VirtualBox

Ticket #13807: VBoxStartup.log

File VBoxStartup.log, 287.2 KB (added by mnman, 10 years ago)
Line 
11080.1084: Log file opened: 4.3.21r97963 g_hStartupLog=00000000000000c0 g_uNtVerCombined=0x611db110
21080.1084: \SystemRoot\System32\ntdll.dll:
31080.1084: CreationTime: 2013-10-11T00:27:08.898984800Z
41080.1084: LastWriteTime: 2013-08-29T02:16:35.515578900Z
51080.1084: ChangeTime: 2014-12-15T16:32:10.938403200Z
61080.1084: FileAttributes: 0x20
71080.1084: Size: 0x1a6dc0
81080.1084: NT Headers: 0xe0
91080.1084: Timestamp: 0x521eaf24
101080.1084: Machine: 0x8664 - amd64
111080.1084: Timestamp: 0x521eaf24
121080.1084: Image Version: 6.1
131080.1084: SizeOfImage: 0x1a9000 (1740800)
141080.1084: Resource Dir: 0x151000 LB 0x560d8
151080.1084: ProductName: Microsoft® Windows® Operating System
161080.1084: ProductVersion: 6.1.7601.18247
171080.1084: FileVersion: 6.1.7601.18247 (win7sp1_gdr.130828-1532)
181080.1084: FileDescription: NT Layer DLL
191080.1084: \SystemRoot\System32\kernel32.dll:
201080.1084: CreationTime: 2014-04-08T17:52:11.563330500Z
211080.1084: LastWriteTime: 2014-03-04T09:44:00.336000000Z
221080.1084: ChangeTime: 2014-12-15T16:32:06.941796100Z
231080.1084: FileAttributes: 0x20
241080.1084: Size: 0x11c000
251080.1084: NT Headers: 0xe8
261080.1084: Timestamp: 0x5315a059
271080.1084: Machine: 0x8664 - amd64
281080.1084: Timestamp: 0x5315a059
291080.1084: Image Version: 6.1
301080.1084: SizeOfImage: 0x11f000 (1175552)
311080.1084: Resource Dir: 0x116000 LB 0x528
321080.1084: ProductName: Microsoft® Windows® Operating System
331080.1084: ProductVersion: 6.1.7601.18409
341080.1084: FileVersion: 6.1.7601.18409 (win7sp1_gdr.140303-2144)
351080.1084: FileDescription: Windows NT BASE API Client DLL
361080.1084: \SystemRoot\System32\KernelBase.dll:
371080.1084: CreationTime: 2014-05-14T14:19:49.655911900Z
381080.1084: LastWriteTime: 2014-03-04T09:44:00.336000000Z
391080.1084: ChangeTime: 2014-12-15T16:32:06.972996100Z
401080.1084: FileAttributes: 0x20
411080.1084: Size: 0x67c00
421080.1084: NT Headers: 0xe8
431080.1084: Timestamp: 0x5315a05a
441080.1084: Machine: 0x8664 - amd64
451080.1084: Timestamp: 0x5315a05a
461080.1084: Image Version: 6.1
471080.1084: SizeOfImage: 0x6c000 (442368)
481080.1084: Resource Dir: 0x6a000 LB 0x530
491080.1084: ProductName: Microsoft® Windows® Operating System
501080.1084: ProductVersion: 6.1.7601.18409
511080.1084: FileVersion: 6.1.7601.18409 (win7sp1_gdr.140303-2144)
521080.1084: FileDescription: Windows NT BASE API Client DLL
531080.1084: \SystemRoot\System32\apisetschema.dll:
541080.1084: CreationTime: 2013-09-13T00:27:27.125703100Z
551080.1084: LastWriteTime: 2013-08-02T02:12:20.275000000Z
561080.1084: ChangeTime: 2014-12-15T16:32:16.182012500Z
571080.1084: FileAttributes: 0x20
581080.1084: Size: 0x1a00
591080.1084: NT Headers: 0xc0
601080.1084: Timestamp: 0x51fb15ca
611080.1084: Machine: 0x8664 - amd64
621080.1084: Timestamp: 0x51fb15ca
631080.1084: Image Version: 6.1
641080.1084: SizeOfImage: 0x50000 (327680)
651080.1084: Resource Dir: 0x30000 LB 0x3f8
661080.1084: ProductName: Microsoft® Windows® Operating System
671080.1084: ProductVersion: 6.1.7601.18229
681080.1084: FileVersion: 6.1.7601.18229 (win7sp1_gdr.130801-1533)
691080.1084: FileDescription: ApiSet Schema DLL
701080.1084: Found driver NisDrv (0x400)
711080.1084: supR3HardenedWinFindAdversaries: 0x480
721080.1084: \SystemRoot\System32\drivers\MBAMSwissArmy.sys:
731080.1084: CreationTime: 2014-08-29T14:06:38.460628200Z
741080.1084: LastWriteTime: 2015-01-29T06:47:45.918771800Z
751080.1084: ChangeTime: 2015-01-29T06:47:45.918771800Z
761080.1084: FileAttributes: 0x20
771080.1084: Size: 0x1fad8
781080.1084: NT Headers: 0xd8
791080.1084: Timestamp: 0x541caaaf
801080.1084: Machine: 0x8664 - amd64
811080.1084: Timestamp: 0x541caaaf
821080.1084: Image Version: 6.1
831080.1084: SizeOfImage: 0x23000 (143360)
841080.1084: Resource Dir: 0x22000 LB 0x3f0
851080.1084: ProductName: Malwarebytes Anti-Malware
861080.1084: ProductVersion: 0.2.13.0
871080.1084: FileVersion: 0.2.13.0
881080.1084: FileDescription: Malwarebytes Anti-Malware
891080.1084: \SystemRoot\System32\drivers\mwac.sys:
901080.1084: CreationTime: 2014-08-29T14:06:17.837392200Z
911080.1084: LastWriteTime: 2014-11-21T12:14:22.000000000Z
921080.1084: ChangeTime: 2014-12-05T05:38:29.313527300Z
931080.1084: FileAttributes: 0x20
941080.1084: Size: 0xf8d8
951080.1084: NT Headers: 0xf8
961080.1084: Timestamp: 0x53a0f42a
971080.1084: Machine: 0x8664 - amd64
981080.1084: Timestamp: 0x53a0f42a
991080.1084: Image Version: 6.2
1001080.1084: SizeOfImage: 0x12000 (73728)
1011080.1084: Resource Dir: 0x10000 LB 0x3e0
1021080.1084: ProductName: Malwarebytes Web Access Control
1031080.1084: ProductVersion: 1.0.6.0
1041080.1084: FileVersion: 1.0.6.0
1051080.1084: FileDescription: Malwarebytes Web Access Control
1061080.1084: \SystemRoot\System32\drivers\mbamchameleon.sys:
1071080.1084: CreationTime: 2014-08-29T14:06:17.868592300Z
1081080.1084: LastWriteTime: 2014-11-21T12:14:12.000000000Z
1091080.1084: ChangeTime: 2014-12-05T05:38:29.516327600Z
1101080.1084: FileAttributes: 0x20
1111080.1084: Size: 0x16cd8
1121080.1084: NT Headers: 0xe0
1131080.1084: Timestamp: 0x53f2136a
1141080.1084: Machine: 0x8664 - amd64
1151080.1084: Timestamp: 0x53f2136a
1161080.1084: Image Version: 6.1
1171080.1084: SizeOfImage: 0x1a000 (106496)
1181080.1084: Resource Dir: 0x18000 LB 0xbd0
1191080.1084: ProductName: Malwarebytes Chameleon
1201080.1084: ProductVersion: 1.1.4.0
1211080.1084: FileVersion: 1.1.4.0
1221080.1084: FileDescription: Malwarebytes Chameleon Protection Driver
1231080.1084: \SystemRoot\System32\drivers\mbam.sys:
1241080.1084: CreationTime: 2014-08-29T14:06:17.821792200Z
1251080.1084: LastWriteTime: 2014-11-21T12:14:08.000000000Z
1261080.1084: ChangeTime: 2014-12-05T05:38:29.297927200Z
1271080.1084: FileAttributes: 0x20
1281080.1084: Size: 0x64d8
1291080.1084: NT Headers: 0xd8
1301080.1084: Timestamp: 0x540754e1
1311080.1084: Machine: 0x8664 - amd64
1321080.1084: Timestamp: 0x540754e1
1331080.1084: Image Version: 6.1
1341080.1084: SizeOfImage: 0xa000 (40960)
1351080.1084: Resource Dir: 0x8000 LB 0x3d0
1361080.1084: ProductName: Malwarebytes Anti-Malware
1371080.1084: ProductVersion: 0.1.15.0
1381080.1084: FileVersion: 0.1.15.0
1391080.1084: FileDescription: Malwarebytes Anti-Malware
1401080.1084: \SystemRoot\System32\drivers\MpFilter.sys:
1411080.1084: CreationTime: 2014-07-17T23:05:06.000000000Z
1421080.1084: LastWriteTime: 2014-07-17T23:05:06.000000000Z
1431080.1084: ChangeTime: 2014-09-09T23:22:15.541298400Z
1441080.1084: FileAttributes: 0x20
1451080.1084: Size: 0x41ad0
1461080.1084: NT Headers: 0xf0
1471080.1084: Timestamp: 0x53bdfdba
1481080.1084: Machine: 0x8664 - amd64
1491080.1084: Timestamp: 0x53bdfdba
1501080.1084: Image Version: 6.3
1511080.1084: SizeOfImage: 0x42000 (270336)
1521080.1084: Resource Dir: 0x40000 LB 0xd50
1531080.1084: ProductName: Microsoft Malware Protection
1541080.1084: ProductVersion: 4.6.0300.0
1551080.1084: FileVersion: 4.6.0300.0
1561080.1084: FileDescription: Microsoft antimalware file system filter driver
1571080.1084: \SystemRoot\System32\drivers\NisDrvWFP.sys:
1581080.1084: CreationTime: 2014-03-11T14:52:30.000000000Z
1591080.1084: LastWriteTime: 2014-07-17T23:05:06.000000000Z
1601080.1084: ChangeTime: 2014-09-09T23:22:14.801256100Z
1611080.1084: FileAttributes: 0x20
1621080.1084: Size: 0x1ea90
1631080.1084: NT Headers: 0xe0
1641080.1084: Timestamp: 0x53bdfde3
1651080.1084: Machine: 0x8664 - amd64
1661080.1084: Timestamp: 0x53bdfde3
1671080.1084: Image Version: 6.3
1681080.1084: SizeOfImage: 0x1f000 (126976)
1691080.1084: Resource Dir: 0x1c000 LB 0x1b90
1701080.1084: ProductName: Microsoft Malware Protection
1711080.1084: ProductVersion: 4.6.0300.0
1721080.1084: FileVersion: 4.6.0300.0
1731080.1084: FileDescription: Microsoft Network Realtime Inspection Driver
1741080.1084: Calling main()
1751080.1084: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
1761080.1084: SUPR3HardenedMain: Respawn #1
1771080.1084: System32: \Device\HarddiskVolume2\Windows\System32
1781080.1084: WinSxS: \Device\HarddiskVolume2\Windows\winsxs
1791080.1084: KnownDllPath: C:\Windows\system32
1801080.1084: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
1811080.1084: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe)
1821080.1084: supR3HardNtEnableThreadCreation:
1831080.1084: supR3HardNtDisableThreadCreation: pvLdrInitThunk=000000007773c340 pvNtTerminateThread=00000000777617e0
1841080.1084: supR3HardenedWinDoReSpawn(1): New child 1088.108c [kernel32].
1851080.1084: supR3HardNtChildGatherData: PebBaseAddress=000007fffffd4000 cbPeb=0x380
1861080.1084: supR3HardNtPuChFindNtdll: uNtDllParentAddr=0000000077710000 uNtDllChildAddr=0000000077710000
1871080.1084: supR3HardenedWinSetupChildInit: uLdrInitThunk=000000007773c340
1881080.1084: supR3HardenedWinSetupChildInit: Start child.
1891080.1084: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 10 ms.
1901080.1084: supR3HardNtChildPurify: Startup delay kludge #1/0: 520 ms, 52 sleeps
1911080.1084: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
1921080.1084: *0000000000000000-fffffffffffeffff 0x0001/0x0000 0x0000000
1931080.1084: *0000000000010000-fffffffffffeffff 0x0004/0x0004 0x0020000
1941080.1084: *0000000000030000-000000000002bfff 0x0002/0x0002 0x0040000
1951080.1084: 0000000000034000-0000000000027fff 0x0001/0x0000 0x0000000
1961080.1084: *0000000000040000-000000000003efff 0x0004/0x0004 0x0020000
1971080.1084: 0000000000041000-0000000000031fff 0x0001/0x0000 0x0000000
1981080.1084: *0000000000050000-000000000004efff 0x0004/0x0004 0x0020000
1991080.1084: 0000000000051000-ffffffffffee1fff 0x0001/0x0000 0x0000000
2001080.1084: *00000000001c0000-00000000000c3fff 0x0000/0x0004 0x0020000
2011080.1084: 00000000002bc000-00000000002b8fff 0x0104/0x0004 0x0020000
2021080.1084: 00000000002bf000-00000000002bdfff 0x0004/0x0004 0x0020000
2031080.1084: 00000000002c0000-ffffffff88e6ffff 0x0001/0x0000 0x0000000
2041080.1084: *0000000077710000-000000007770efff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
2051080.1084: 0000000077711000-000000007760efff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
2061080.1084: 0000000077813000-00000000777e3fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
2071080.1084: 0000000077842000-0000000077839fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
2081080.1084: 000000007784a000-0000000077848fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
2091080.1084: 000000007784b000-0000000077847fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
2101080.1084: 000000007784e000-00000000777e2fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
2111080.1084: 00000000778b9000-0000000070191fff 0x0001/0x0000 0x0000000
2121080.1084: *000000007efe0000-000000007dfdffff 0x0000/0x0002 0x0020000
2131080.1084: *000000007ffe0000-000000007ffdefff 0x0002/0x0002 0x0020000
2141080.1084: 000000007ffe1000-000000007ffd1fff 0x0000/0x0002 0x0020000
2151080.1084: 000000007fff0000-ffffffffc0a5ffff 0x0001/0x0000 0x0000000
2161080.1084: *000000013f580000-000000013f57efff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
2171080.1084: 000000013f581000-000000013f4fcfff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
2181080.1084: 000000013f605000-000000013f603fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
2191080.1084: 000000013f606000-000000013f5c8fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
2201080.1084: 000000013f643000-000000013f641fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
2211080.1084: 000000013f644000-000000013f642fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
2221080.1084: 000000013f645000-000000013f642fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
2231080.1084: 000000013f647000-000000013f645fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
2241080.1084: 000000013f648000-000000013f646fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
2251080.1084: 000000013f649000-000000013f644fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
2261080.1084: 000000013f64d000-000000013f613fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
2271080.1084: 000000013f686000-fffff8037f2dbfff 0x0001/0x0000 0x0000000
2281080.1084: *000007feffa30000-000007feffa2efff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\apisetschema.dll
2291080.1084: 000007feffa31000-000007fdff4b1fff 0x0001/0x0000 0x0000000
2301080.1084: *000007fffffb0000-000007fffff8cfff 0x0002/0x0002 0x0040000
2311080.1084: 000007fffffd3000-000007fffffd1fff 0x0001/0x0000 0x0000000
2321080.1084: *000007fffffd4000-000007fffffd2fff 0x0004/0x0004 0x0020000
2331080.1084: 000007fffffd5000-000007fffffcbfff 0x0001/0x0000 0x0000000
2341080.1084: *000007fffffde000-000007fffffdbfff 0x0004/0x0004 0x0020000
2351080.1084: *000007fffffe0000-000007fffffcffff 0x0001/0x0002 0x0020000
2361080.1084: apisetschema.dll: timestamp 0x51fb15ca (rc=VINF_SUCCESS)
2371080.1084: VirtualBox.exe: timestamp 0x54cb639b (rc=VINF_SUCCESS)
2381080.1084: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
2391080.1084: '\Device\HarddiskVolume2\Windows\System32\apisetschema.dll' has no imports
2401080.1084: '\Device\HarddiskVolume2\Windows\System32\ntdll.dll' has no imports
2411080.1084: supR3HardNtChildPurify: Done after 540 ms and 0 fixes (loop #0).
2421080.1084: supR3HardNtEnableThreadCreation:
2431088.108c: Log file opened: 4.3.21r97963 g_hStartupLog=0000000000000004 g_uNtVerCombined=0x611db110
2441088.108c: supR3HardenedVmProcessInit: uNtDllAddr=0000000077710000
2451088.108c: ntdll.dll: timestamp 0x521eaf24 (rc=VINF_SUCCESS)
2461088.108c: New simple heap: #1 00000000002c0000 LB 0x400000 (for 1740800 allocation)
2471088.108c: System32: \Device\HarddiskVolume2\Windows\System32
2481088.108c: WinSxS: \Device\HarddiskVolume2\Windows\winsxs
2491088.108c: KnownDllPath: C:\Windows\system32
2501088.108c: supR3HardenedVmProcessInit: Opening vboxdrv stub...
2511088.108c: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
2521088.108c: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
2531088.108c: Registered Dll notification callback with NTDLL.
2541088.108c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\kernel32.dll)
2551088.108c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\kernel32.dll
2561088.108c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
2571088.108c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
2581088.108c: supR3HardenedDllNotificationCallback: load 00000000774f0000 LB 0x0011f000 C:\Windows\system32\kernel32.dll [fFlags=0x0]
2591088.108c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
2601088.108c: supR3HardenedDllNotificationCallback: load 000007fefd7d0000 LB 0x0006c000 C:\Windows\system32\KERNELBASE.dll [fFlags=0x0]
2611088.108c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\KernelBase.dll)
2621088.108c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\KernelBase.dll
2631088.108c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00000000774f0000 'C:\Windows\system32\kernel32.dll'
2641088.108c: supR3HardNtDisableThreadCreation: pvLdrInitThunk=000000007773c340 pvNtTerminateThread=00000000777617e0
2651080.1084: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 50 ms.
2661088.108c: \SystemRoot\System32\ntdll.dll:
2671088.108c: CreationTime: 2013-10-11T00:27:08.898984800Z
2681088.108c: LastWriteTime: 2013-08-29T02:16:35.515578900Z
2691088.108c: ChangeTime: 2014-12-15T16:32:10.938403200Z
2701088.108c: FileAttributes: 0x20
2711088.108c: Size: 0x1a6dc0
2721088.108c: NT Headers: 0xe0
2731088.108c: Timestamp: 0x521eaf24
2741088.108c: Machine: 0x8664 - amd64
2751088.108c: Timestamp: 0x521eaf24
2761088.108c: Image Version: 6.1
2771088.108c: SizeOfImage: 0x1a9000 (1740800)
2781088.108c: Resource Dir: 0x151000 LB 0x560d8
2791088.108c: ProductName: Microsoft® Windows® Operating System
2801088.108c: ProductVersion: 6.1.7601.18247
2811088.108c: FileVersion: 6.1.7601.18247 (win7sp1_gdr.130828-1532)
2821088.108c: FileDescription: NT Layer DLL
2831088.108c: \SystemRoot\System32\kernel32.dll:
2841088.108c: CreationTime: 2014-04-08T17:52:11.563330500Z
2851088.108c: LastWriteTime: 2014-03-04T09:44:00.336000000Z
2861088.108c: ChangeTime: 2014-12-15T16:32:06.941796100Z
2871088.108c: FileAttributes: 0x20
2881088.108c: Size: 0x11c000
2891088.108c: NT Headers: 0xe8
2901088.108c: Timestamp: 0x5315a059
2911088.108c: Machine: 0x8664 - amd64
2921088.108c: Timestamp: 0x5315a059
2931088.108c: Image Version: 6.1
2941088.108c: SizeOfImage: 0x11f000 (1175552)
2951088.108c: Resource Dir: 0x116000 LB 0x528
2961088.108c: ProductName: Microsoft® Windows® Operating System
2971088.108c: ProductVersion: 6.1.7601.18409
2981088.108c: FileVersion: 6.1.7601.18409 (win7sp1_gdr.140303-2144)
2991088.108c: FileDescription: Windows NT BASE API Client DLL
3001088.108c: \SystemRoot\System32\KernelBase.dll:
3011088.108c: CreationTime: 2014-05-14T14:19:49.655911900Z
3021088.108c: LastWriteTime: 2014-03-04T09:44:00.336000000Z
3031088.108c: ChangeTime: 2014-12-15T16:32:06.972996100Z
3041088.108c: FileAttributes: 0x20
3051088.108c: Size: 0x67c00
3061088.108c: NT Headers: 0xe8
3071088.108c: Timestamp: 0x5315a05a
3081088.108c: Machine: 0x8664 - amd64
3091088.108c: Timestamp: 0x5315a05a
3101088.108c: Image Version: 6.1
3111088.108c: SizeOfImage: 0x6c000 (442368)
3121088.108c: Resource Dir: 0x6a000 LB 0x530
3131088.108c: ProductName: Microsoft® Windows® Operating System
3141088.108c: ProductVersion: 6.1.7601.18409
3151088.108c: FileVersion: 6.1.7601.18409 (win7sp1_gdr.140303-2144)
3161088.108c: FileDescription: Windows NT BASE API Client DLL
3171088.108c: \SystemRoot\System32\apisetschema.dll:
3181088.108c: CreationTime: 2013-09-13T00:27:27.125703100Z
3191088.108c: LastWriteTime: 2013-08-02T02:12:20.275000000Z
3201088.108c: ChangeTime: 2014-12-15T16:32:16.182012500Z
3211088.108c: FileAttributes: 0x20
3221088.108c: Size: 0x1a00
3231088.108c: NT Headers: 0xc0
3241088.108c: Timestamp: 0x51fb15ca
3251088.108c: Machine: 0x8664 - amd64
3261088.108c: Timestamp: 0x51fb15ca
3271088.108c: Image Version: 6.1
3281088.108c: SizeOfImage: 0x50000 (327680)
3291088.108c: Resource Dir: 0x30000 LB 0x3f8
3301088.108c: ProductName: Microsoft® Windows® Operating System
3311088.108c: ProductVersion: 6.1.7601.18229
3321088.108c: FileVersion: 6.1.7601.18229 (win7sp1_gdr.130801-1533)
3331088.108c: FileDescription: ApiSet Schema DLL
3341088.108c: Found driver NisDrv (0x400)
3351088.108c: supR3HardenedWinFindAdversaries: 0x480
3361088.108c: \SystemRoot\System32\drivers\MBAMSwissArmy.sys:
3371088.108c: CreationTime: 2014-08-29T14:06:38.460628200Z
3381088.108c: LastWriteTime: 2015-01-29T06:47:45.918771800Z
3391088.108c: ChangeTime: 2015-01-29T06:47:45.918771800Z
3401088.108c: FileAttributes: 0x20
3411088.108c: Size: 0x1fad8
3421088.108c: NT Headers: 0xd8
3431088.108c: Timestamp: 0x541caaaf
3441088.108c: Machine: 0x8664 - amd64
3451088.108c: Timestamp: 0x541caaaf
3461088.108c: Image Version: 6.1
3471088.108c: SizeOfImage: 0x23000 (143360)
3481088.108c: Resource Dir: 0x22000 LB 0x3f0
3491088.108c: ProductName: Malwarebytes Anti-Malware
3501088.108c: ProductVersion: 0.2.13.0
3511088.108c: FileVersion: 0.2.13.0
3521088.108c: FileDescription: Malwarebytes Anti-Malware
3531088.108c: \SystemRoot\System32\drivers\mwac.sys:
3541088.108c: CreationTime: 2014-08-29T14:06:17.837392200Z
3551088.108c: LastWriteTime: 2014-11-21T12:14:22.000000000Z
3561088.108c: ChangeTime: 2014-12-05T05:38:29.313527300Z
3571088.108c: FileAttributes: 0x20
3581088.108c: Size: 0xf8d8
3591088.108c: NT Headers: 0xf8
3601088.108c: Timestamp: 0x53a0f42a
3611088.108c: Machine: 0x8664 - amd64
3621088.108c: Timestamp: 0x53a0f42a
3631088.108c: Image Version: 6.2
3641088.108c: SizeOfImage: 0x12000 (73728)
3651088.108c: Resource Dir: 0x10000 LB 0x3e0
3661088.108c: ProductName: Malwarebytes Web Access Control
3671088.108c: ProductVersion: 1.0.6.0
3681088.108c: FileVersion: 1.0.6.0
3691088.108c: FileDescription: Malwarebytes Web Access Control
3701088.108c: \SystemRoot\System32\drivers\mbamchameleon.sys:
3711088.108c: CreationTime: 2014-08-29T14:06:17.868592300Z
3721088.108c: LastWriteTime: 2014-11-21T12:14:12.000000000Z
3731088.108c: ChangeTime: 2014-12-05T05:38:29.516327600Z
3741088.108c: FileAttributes: 0x20
3751088.108c: Size: 0x16cd8
3761088.108c: NT Headers: 0xe0
3771088.108c: Timestamp: 0x53f2136a
3781088.108c: Machine: 0x8664 - amd64
3791088.108c: Timestamp: 0x53f2136a
3801088.108c: Image Version: 6.1
3811088.108c: SizeOfImage: 0x1a000 (106496)
3821088.108c: Resource Dir: 0x18000 LB 0xbd0
3831088.108c: ProductName: Malwarebytes Chameleon
3841088.108c: ProductVersion: 1.1.4.0
3851088.108c: FileVersion: 1.1.4.0
3861088.108c: FileDescription: Malwarebytes Chameleon Protection Driver
3871088.108c: \SystemRoot\System32\drivers\mbam.sys:
3881088.108c: CreationTime: 2014-08-29T14:06:17.821792200Z
3891088.108c: LastWriteTime: 2014-11-21T12:14:08.000000000Z
3901088.108c: ChangeTime: 2014-12-05T05:38:29.297927200Z
3911088.108c: FileAttributes: 0x20
3921088.108c: Size: 0x64d8
3931088.108c: NT Headers: 0xd8
3941088.108c: Timestamp: 0x540754e1
3951088.108c: Machine: 0x8664 - amd64
3961088.108c: Timestamp: 0x540754e1
3971088.108c: Image Version: 6.1
3981088.108c: SizeOfImage: 0xa000 (40960)
3991088.108c: Resource Dir: 0x8000 LB 0x3d0
4001088.108c: ProductName: Malwarebytes Anti-Malware
4011088.108c: ProductVersion: 0.1.15.0
4021088.108c: FileVersion: 0.1.15.0
4031088.108c: FileDescription: Malwarebytes Anti-Malware
4041088.108c: \SystemRoot\System32\drivers\MpFilter.sys:
4051088.108c: CreationTime: 2014-07-17T23:05:06.000000000Z
4061088.108c: LastWriteTime: 2014-07-17T23:05:06.000000000Z
4071088.108c: ChangeTime: 2014-09-09T23:22:15.541298400Z
4081088.108c: FileAttributes: 0x20
4091088.108c: Size: 0x41ad0
4101088.108c: NT Headers: 0xf0
4111088.108c: Timestamp: 0x53bdfdba
4121088.108c: Machine: 0x8664 - amd64
4131088.108c: Timestamp: 0x53bdfdba
4141088.108c: Image Version: 6.3
4151088.108c: SizeOfImage: 0x42000 (270336)
4161088.108c: Resource Dir: 0x40000 LB 0xd50
4171088.108c: ProductName: Microsoft Malware Protection
4181088.108c: ProductVersion: 4.6.0300.0
4191088.108c: FileVersion: 4.6.0300.0
4201088.108c: FileDescription: Microsoft antimalware file system filter driver
4211088.108c: \SystemRoot\System32\drivers\NisDrvWFP.sys:
4221088.108c: CreationTime: 2014-03-11T14:52:30.000000000Z
4231088.108c: LastWriteTime: 2014-07-17T23:05:06.000000000Z
4241088.108c: ChangeTime: 2014-09-09T23:22:14.801256100Z
4251088.108c: FileAttributes: 0x20
4261088.108c: Size: 0x1ea90
4271088.108c: NT Headers: 0xe0
4281088.108c: Timestamp: 0x53bdfde3
4291088.108c: Machine: 0x8664 - amd64
4301088.108c: Timestamp: 0x53bdfde3
4311088.108c: Image Version: 6.3
4321088.108c: SizeOfImage: 0x1f000 (126976)
4331088.108c: Resource Dir: 0x1c000 LB 0x1b90
4341088.108c: ProductName: Microsoft Malware Protection
4351088.108c: ProductVersion: 4.6.0300.0
4361088.108c: FileVersion: 4.6.0300.0
4371088.108c: FileDescription: Microsoft Network Realtime Inspection Driver
4381088.108c: Calling main()
4391088.108c: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
4401088.108c: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
4411088.108c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe)
4421088.108c: SUPR3HardenedMain: Respawn #2
4431088.108c: supR3HardNtEnableThreadCreation:
4441088.108c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\apphelp.dll)
4451088.108c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\apphelp.dll
4461088.108c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\apphelp.dll (rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
4471088.108c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\apphelp.dll [lacks WinVerifyTrust]
4481088.108c: supR3HardenedDllNotificationCallback: load 000007fefd2d0000 LB 0x00057000 C:\Windows\system32\apphelp.dll [fFlags=0x0]
4491088.108c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\apphelp.dll [lacks WinVerifyTrust]
4501088.108c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd2d0000 'C:\Windows\system32\apphelp.dll'
4511088.108c: supR3HardNtDisableThreadCreation: pvLdrInitThunk=000000007773c340 pvNtTerminateThread=00000000777617e0
4521088.108c: supR3HardenedWinDoReSpawn(2): New child 10b8.10bc [kernel32].
4531088.108c: supR3HardNtChildGatherData: PebBaseAddress=000007fffffdf000 cbPeb=0x380
4541088.108c: supR3HardNtPuChFindNtdll: uNtDllParentAddr=0000000077710000 uNtDllChildAddr=0000000077710000
4551088.108c: supR3HardenedWinSetupChildInit: uLdrInitThunk=000000007773c340
4561088.108c: supR3HardenedWinSetupChildInit: Start child.
4571088.108c: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
4581088.108c: supR3HardNtChildPurify: Startup delay kludge #1/0: 520 ms, 52 sleeps
4591088.108c: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
4601088.108c: *0000000000000000-fffffffffffeffff 0x0001/0x0000 0x0000000
4611088.108c: *0000000000010000-fffffffffffeffff 0x0004/0x0004 0x0020000
4621088.108c: *0000000000030000-000000000002bfff 0x0002/0x0002 0x0040000
4631088.108c: 0000000000034000-0000000000027fff 0x0001/0x0000 0x0000000
4641088.108c: *0000000000040000-000000000003efff 0x0004/0x0004 0x0020000
4651088.108c: 0000000000041000-0000000000031fff 0x0001/0x0000 0x0000000
4661088.108c: *0000000000050000-000000000004efff 0x0004/0x0004 0x0020000
4671088.108c: 0000000000051000-fffffffffff61fff 0x0001/0x0000 0x0000000
4681088.108c: *0000000000140000-0000000000043fff 0x0000/0x0004 0x0020000
4691088.108c: 000000000023c000-0000000000238fff 0x0104/0x0004 0x0020000
4701088.108c: 000000000023f000-000000000023dfff 0x0004/0x0004 0x0020000
4711088.108c: 0000000000240000-ffffffff88d6ffff 0x0001/0x0000 0x0000000
4721088.108c: *0000000077710000-000000007770efff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
4731088.108c: 0000000077711000-000000007760efff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
4741088.108c: 0000000077813000-00000000777e3fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
4751088.108c: 0000000077842000-0000000077839fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
4761088.108c: 000000007784a000-0000000077848fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
4771088.108c: 000000007784b000-0000000077847fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
4781088.108c: 000000007784e000-00000000777e2fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
4791088.108c: 00000000778b9000-0000000070191fff 0x0001/0x0000 0x0000000
4801088.108c: *000000007efe0000-000000007dfdffff 0x0000/0x0002 0x0020000
4811088.108c: *000000007ffe0000-000000007ffdefff 0x0002/0x0002 0x0020000
4821088.108c: 000000007ffe1000-000000007ffd1fff 0x0000/0x0002 0x0020000
4831088.108c: 000000007fff0000-ffffffffc0a5ffff 0x0001/0x0000 0x0000000
4841088.108c: *000000013f580000-000000013f57efff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
4851088.108c: 000000013f581000-000000013f4fcfff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
4861088.108c: 000000013f605000-000000013f603fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
4871088.108c: 000000013f606000-000000013f5c8fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
4881088.108c: 000000013f643000-000000013f641fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
4891088.108c: 000000013f644000-000000013f642fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
4901088.108c: 000000013f645000-000000013f642fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
4911088.108c: 000000013f647000-000000013f645fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
4921088.108c: 000000013f648000-000000013f646fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
4931088.108c: 000000013f649000-000000013f644fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
4941088.108c: 000000013f64d000-000000013f613fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
4951088.108c: 000000013f686000-fffff8037f2dbfff 0x0001/0x0000 0x0000000
4961088.108c: *000007feffa30000-000007feffa2efff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\apisetschema.dll
4971088.108c: 000007feffa31000-000007fdff4b1fff 0x0001/0x0000 0x0000000
4981088.108c: *000007fffffb0000-000007fffff8cfff 0x0002/0x0002 0x0040000
4991088.108c: 000007fffffd3000-000007fffffc8fff 0x0001/0x0000 0x0000000
5001088.108c: *000007fffffdd000-000007fffffdafff 0x0004/0x0004 0x0020000
5011088.108c: *000007fffffdf000-000007fffffddfff 0x0004/0x0004 0x0020000
5021088.108c: *000007fffffe0000-000007fffffcffff 0x0001/0x0002 0x0020000
5031088.108c: apisetschema.dll: timestamp 0x51fb15ca (rc=VINF_SUCCESS)
5041088.108c: VirtualBox.exe: timestamp 0x54cb639b (rc=VINF_SUCCESS)
5051088.108c: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
5061088.108c: '\Device\HarddiskVolume2\Windows\System32\apisetschema.dll' has no imports
5071088.108c: '\Device\HarddiskVolume2\Windows\System32\ntdll.dll' has no imports
5081088.108c: supR3HardNtChildPurify: Done after 540 ms and 0 fixes (loop #0).
5091088.108c: supR3HardenedEarlyCompact: Removed heap 1 (0x000000002c0000 LB 0x400000)
5101088.108c: supR3HardNtEnableThreadCreation:
51110b8.10bc: Log file opened: 4.3.21r97963 g_hStartupLog=0000000000000004 g_uNtVerCombined=0x611db110
51210b8.10bc: supR3HardenedVmProcessInit: uNtDllAddr=0000000077710000
51310b8.10bc: ntdll.dll: timestamp 0x521eaf24 (rc=VINF_SUCCESS)
51410b8.10bc: New simple heap: #1 0000000000340000 LB 0x400000 (for 1740800 allocation)
51510b8.10bc: System32: \Device\HarddiskVolume2\Windows\System32
51610b8.10bc: WinSxS: \Device\HarddiskVolume2\Windows\winsxs
51710b8.10bc: KnownDllPath: C:\Windows\system32
51810b8.10bc: supR3HardenedVmProcessInit: Opening vboxdrv...
51910b8.10bc: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
52010b8.10bc: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
52110b8.10bc: Registered Dll notification callback with NTDLL.
52210b8.10bc: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\kernel32.dll)
52310b8.10bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\kernel32.dll
52410b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
52510b8.10bc: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
52610b8.10bc: supR3HardenedDllNotificationCallback: load 00000000774f0000 LB 0x0011f000 C:\Windows\system32\kernel32.dll [fFlags=0x0]
52710b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
52810b8.10bc: supR3HardenedDllNotificationCallback: load 000007fefd7d0000 LB 0x0006c000 C:\Windows\system32\KERNELBASE.dll [fFlags=0x0]
52910b8.10bc: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\KernelBase.dll)
53010b8.10bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\KernelBase.dll
53110b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00000000774f0000 'C:\Windows\system32\kernel32.dll'
53210b8.10bc: supR3HardNtDisableThreadCreation: pvLdrInitThunk=000000007773c340 pvNtTerminateThread=00000000777617e0
5331088.108c: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 30 ms.
53410b8.10bc: \SystemRoot\System32\ntdll.dll:
53510b8.10bc: CreationTime: 2013-10-11T00:27:08.898984800Z
53610b8.10bc: LastWriteTime: 2013-08-29T02:16:35.515578900Z
53710b8.10bc: ChangeTime: 2014-12-15T16:32:10.938403200Z
53810b8.10bc: FileAttributes: 0x20
53910b8.10bc: Size: 0x1a6dc0
54010b8.10bc: NT Headers: 0xe0
54110b8.10bc: Timestamp: 0x521eaf24
54210b8.10bc: Machine: 0x8664 - amd64
54310b8.10bc: Timestamp: 0x521eaf24
54410b8.10bc: Image Version: 6.1
54510b8.10bc: SizeOfImage: 0x1a9000 (1740800)
54610b8.10bc: Resource Dir: 0x151000 LB 0x560d8
54710b8.10bc: ProductName: Microsoft® Windows® Operating System
54810b8.10bc: ProductVersion: 6.1.7601.18247
54910b8.10bc: FileVersion: 6.1.7601.18247 (win7sp1_gdr.130828-1532)
55010b8.10bc: FileDescription: NT Layer DLL
55110b8.10bc: \SystemRoot\System32\kernel32.dll:
55210b8.10bc: CreationTime: 2014-04-08T17:52:11.563330500Z
55310b8.10bc: LastWriteTime: 2014-03-04T09:44:00.336000000Z
55410b8.10bc: ChangeTime: 2014-12-15T16:32:06.941796100Z
55510b8.10bc: FileAttributes: 0x20
55610b8.10bc: Size: 0x11c000
55710b8.10bc: NT Headers: 0xe8
55810b8.10bc: Timestamp: 0x5315a059
55910b8.10bc: Machine: 0x8664 - amd64
56010b8.10bc: Timestamp: 0x5315a059
56110b8.10bc: Image Version: 6.1
56210b8.10bc: SizeOfImage: 0x11f000 (1175552)
56310b8.10bc: Resource Dir: 0x116000 LB 0x528
56410b8.10bc: ProductName: Microsoft® Windows® Operating System
56510b8.10bc: ProductVersion: 6.1.7601.18409
56610b8.10bc: FileVersion: 6.1.7601.18409 (win7sp1_gdr.140303-2144)
56710b8.10bc: FileDescription: Windows NT BASE API Client DLL
56810b8.10bc: \SystemRoot\System32\KernelBase.dll:
56910b8.10bc: CreationTime: 2014-05-14T14:19:49.655911900Z
57010b8.10bc: LastWriteTime: 2014-03-04T09:44:00.336000000Z
57110b8.10bc: ChangeTime: 2014-12-15T16:32:06.972996100Z
57210b8.10bc: FileAttributes: 0x20
57310b8.10bc: Size: 0x67c00
57410b8.10bc: NT Headers: 0xe8
57510b8.10bc: Timestamp: 0x5315a05a
57610b8.10bc: Machine: 0x8664 - amd64
57710b8.10bc: Timestamp: 0x5315a05a
57810b8.10bc: Image Version: 6.1
57910b8.10bc: SizeOfImage: 0x6c000 (442368)
58010b8.10bc: Resource Dir: 0x6a000 LB 0x530
58110b8.10bc: ProductName: Microsoft® Windows® Operating System
58210b8.10bc: ProductVersion: 6.1.7601.18409
58310b8.10bc: FileVersion: 6.1.7601.18409 (win7sp1_gdr.140303-2144)
58410b8.10bc: FileDescription: Windows NT BASE API Client DLL
58510b8.10bc: \SystemRoot\System32\apisetschema.dll:
58610b8.10bc: CreationTime: 2013-09-13T00:27:27.125703100Z
58710b8.10bc: LastWriteTime: 2013-08-02T02:12:20.275000000Z
58810b8.10bc: ChangeTime: 2014-12-15T16:32:16.182012500Z
58910b8.10bc: FileAttributes: 0x20
59010b8.10bc: Size: 0x1a00
59110b8.10bc: NT Headers: 0xc0
59210b8.10bc: Timestamp: 0x51fb15ca
59310b8.10bc: Machine: 0x8664 - amd64
59410b8.10bc: Timestamp: 0x51fb15ca
59510b8.10bc: Image Version: 6.1
59610b8.10bc: SizeOfImage: 0x50000 (327680)
59710b8.10bc: Resource Dir: 0x30000 LB 0x3f8
59810b8.10bc: ProductName: Microsoft® Windows® Operating System
59910b8.10bc: ProductVersion: 6.1.7601.18229
60010b8.10bc: FileVersion: 6.1.7601.18229 (win7sp1_gdr.130801-1533)
60110b8.10bc: FileDescription: ApiSet Schema DLL
60210b8.10bc: Found driver NisDrv (0x400)
60310b8.10bc: supR3HardenedWinFindAdversaries: 0x480
60410b8.10bc: \SystemRoot\System32\drivers\MBAMSwissArmy.sys:
60510b8.10bc: CreationTime: 2014-08-29T14:06:38.460628200Z
60610b8.10bc: LastWriteTime: 2015-01-29T06:47:45.918771800Z
60710b8.10bc: ChangeTime: 2015-01-29T06:47:45.918771800Z
60810b8.10bc: FileAttributes: 0x20
60910b8.10bc: Size: 0x1fad8
61010b8.10bc: NT Headers: 0xd8
61110b8.10bc: Timestamp: 0x541caaaf
61210b8.10bc: Machine: 0x8664 - amd64
61310b8.10bc: Timestamp: 0x541caaaf
61410b8.10bc: Image Version: 6.1
61510b8.10bc: SizeOfImage: 0x23000 (143360)
61610b8.10bc: Resource Dir: 0x22000 LB 0x3f0
61710b8.10bc: ProductName: Malwarebytes Anti-Malware
61810b8.10bc: ProductVersion: 0.2.13.0
61910b8.10bc: FileVersion: 0.2.13.0
62010b8.10bc: FileDescription: Malwarebytes Anti-Malware
62110b8.10bc: \SystemRoot\System32\drivers\mwac.sys:
62210b8.10bc: CreationTime: 2014-08-29T14:06:17.837392200Z
62310b8.10bc: LastWriteTime: 2014-11-21T12:14:22.000000000Z
62410b8.10bc: ChangeTime: 2014-12-05T05:38:29.313527300Z
62510b8.10bc: FileAttributes: 0x20
62610b8.10bc: Size: 0xf8d8
62710b8.10bc: NT Headers: 0xf8
62810b8.10bc: Timestamp: 0x53a0f42a
62910b8.10bc: Machine: 0x8664 - amd64
63010b8.10bc: Timestamp: 0x53a0f42a
63110b8.10bc: Image Version: 6.2
63210b8.10bc: SizeOfImage: 0x12000 (73728)
63310b8.10bc: Resource Dir: 0x10000 LB 0x3e0
63410b8.10bc: ProductName: Malwarebytes Web Access Control
63510b8.10bc: ProductVersion: 1.0.6.0
63610b8.10bc: FileVersion: 1.0.6.0
63710b8.10bc: FileDescription: Malwarebytes Web Access Control
63810b8.10bc: \SystemRoot\System32\drivers\mbamchameleon.sys:
63910b8.10bc: CreationTime: 2014-08-29T14:06:17.868592300Z
64010b8.10bc: LastWriteTime: 2014-11-21T12:14:12.000000000Z
64110b8.10bc: ChangeTime: 2014-12-05T05:38:29.516327600Z
64210b8.10bc: FileAttributes: 0x20
64310b8.10bc: Size: 0x16cd8
64410b8.10bc: NT Headers: 0xe0
64510b8.10bc: Timestamp: 0x53f2136a
64610b8.10bc: Machine: 0x8664 - amd64
64710b8.10bc: Timestamp: 0x53f2136a
64810b8.10bc: Image Version: 6.1
64910b8.10bc: SizeOfImage: 0x1a000 (106496)
65010b8.10bc: Resource Dir: 0x18000 LB 0xbd0
65110b8.10bc: ProductName: Malwarebytes Chameleon
65210b8.10bc: ProductVersion: 1.1.4.0
65310b8.10bc: FileVersion: 1.1.4.0
65410b8.10bc: FileDescription: Malwarebytes Chameleon Protection Driver
65510b8.10bc: \SystemRoot\System32\drivers\mbam.sys:
65610b8.10bc: CreationTime: 2014-08-29T14:06:17.821792200Z
65710b8.10bc: LastWriteTime: 2014-11-21T12:14:08.000000000Z
65810b8.10bc: ChangeTime: 2014-12-05T05:38:29.297927200Z
65910b8.10bc: FileAttributes: 0x20
66010b8.10bc: Size: 0x64d8
66110b8.10bc: NT Headers: 0xd8
66210b8.10bc: Timestamp: 0x540754e1
66310b8.10bc: Machine: 0x8664 - amd64
66410b8.10bc: Timestamp: 0x540754e1
66510b8.10bc: Image Version: 6.1
66610b8.10bc: SizeOfImage: 0xa000 (40960)
66710b8.10bc: Resource Dir: 0x8000 LB 0x3d0
66810b8.10bc: ProductName: Malwarebytes Anti-Malware
66910b8.10bc: ProductVersion: 0.1.15.0
67010b8.10bc: FileVersion: 0.1.15.0
67110b8.10bc: FileDescription: Malwarebytes Anti-Malware
67210b8.10bc: \SystemRoot\System32\drivers\MpFilter.sys:
67310b8.10bc: CreationTime: 2014-07-17T23:05:06.000000000Z
67410b8.10bc: LastWriteTime: 2014-07-17T23:05:06.000000000Z
67510b8.10bc: ChangeTime: 2014-09-09T23:22:15.541298400Z
67610b8.10bc: FileAttributes: 0x20
67710b8.10bc: Size: 0x41ad0
67810b8.10bc: NT Headers: 0xf0
67910b8.10bc: Timestamp: 0x53bdfdba
68010b8.10bc: Machine: 0x8664 - amd64
68110b8.10bc: Timestamp: 0x53bdfdba
68210b8.10bc: Image Version: 6.3
68310b8.10bc: SizeOfImage: 0x42000 (270336)
68410b8.10bc: Resource Dir: 0x40000 LB 0xd50
68510b8.10bc: ProductName: Microsoft Malware Protection
68610b8.10bc: ProductVersion: 4.6.0300.0
68710b8.10bc: FileVersion: 4.6.0300.0
68810b8.10bc: FileDescription: Microsoft antimalware file system filter driver
68910b8.10bc: \SystemRoot\System32\drivers\NisDrvWFP.sys:
69010b8.10bc: CreationTime: 2014-03-11T14:52:30.000000000Z
69110b8.10bc: LastWriteTime: 2014-07-17T23:05:06.000000000Z
69210b8.10bc: ChangeTime: 2014-09-09T23:22:14.801256100Z
69310b8.10bc: FileAttributes: 0x20
69410b8.10bc: Size: 0x1ea90
69510b8.10bc: NT Headers: 0xe0
69610b8.10bc: Timestamp: 0x53bdfde3
69710b8.10bc: Machine: 0x8664 - amd64
69810b8.10bc: Timestamp: 0x53bdfde3
69910b8.10bc: Image Version: 6.3
70010b8.10bc: SizeOfImage: 0x1f000 (126976)
70110b8.10bc: Resource Dir: 0x1c000 LB 0x1b90
70210b8.10bc: ProductName: Microsoft Malware Protection
70310b8.10bc: ProductVersion: 4.6.0300.0
70410b8.10bc: FileVersion: 4.6.0300.0
70510b8.10bc: FileDescription: Microsoft Network Realtime Inspection Driver
70610b8.10bc: Calling main()
70710b8.10bc: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
70810b8.10bc: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
70910b8.10bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe)
71010b8.10bc: SUPR3HardenedMain: Final process, opening VBoxDrv...
71110b8.10bc: supR3HardenedEarlyCompact: Removed heap 1 (0x00000000340000 LB 0x400000)
71210b8.10bc: supR3HardNtEnableThreadCreation:
71310b8.10bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll)
71410b8.10bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll
71510b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d4fd0:C:\Windows\system32 [calling]
71610b8.10bc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
71710b8.10bc: supR3HardenedDllNotificationCallback: load 000007fef0450000 LB 0x00005000 C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL [fFlags=0x0]
71810b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
71910b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
72010b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Program Files\nodejs\;C:\Users\rjs7\AppData\Roaming\npm [calling]
72110b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef0450000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
72210b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
72310b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Program Files\nodejs\;C:\Users\rjs7\AppData\Roaming\npm [calling]
72410b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef0450000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
72510b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef0450000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
72610b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
72710b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'crypt32.dll'.
72810b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msasn1.dll'.
72910b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
73010b8.10bc: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\wintrust.dll)
73110b8.10bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wintrust.dll
73210b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
73310b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
73410b8.10bc: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll)
73510b8.10bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
73610b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
73710b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume2\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
73810b8.10bc: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\msasn1.dll)
73910b8.10bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msasn1.dll
74010b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
74110b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume2\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
74210b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
74310b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msasn1.dll'.
74410b8.10bc: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\crypt32.dll)
74510b8.10bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\crypt32.dll
74610b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
74710b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
74810b8.10bc: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\msvcrt.dll)
74910b8.10bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
75010b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
75110b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume2\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
75210b8.10bc: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
75310b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
75410b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
75510b8.10bc: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
75610b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d4fd0:C:\Windows\system32 [calling]
75710b8.10bc: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
75810b8.10bc: supR3HardenedDllNotificationCallback: load 000007fefd840000 LB 0x0003b000 C:\Windows\system32\Wintrust.dll [fFlags=0x0]
75910b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
76010b8.10bc: supR3HardenedDllNotificationCallback: load 000007fefdc40000 LB 0x0009f000 C:\Windows\system32\msvcrt.dll [fFlags=0x0]
76110b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
76210b8.10bc: supR3HardenedDllNotificationCallback: load 000007fefd520000 LB 0x0016d000 C:\Windows\system32\CRYPT32.dll [fFlags=0x0]
76310b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
76410b8.10bc: supR3HardenedDllNotificationCallback: load 000007fefd4e0000 LB 0x0000f000 C:\Windows\system32\MSASN1.dll [fFlags=0x0]
76510b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
76610b8.10bc: supR3HardenedDllNotificationCallback: load 000007fefee60000 LB 0x0012d000 C:\Windows\system32\RPCRT4.dll [fFlags=0x0]
76710b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
76810b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd840000 'C:\Windows\system32\Wintrust.dll'
76910b8.10bc: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\cryptsp.dll)
77010b8.10bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cryptsp.dll
77110b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTSP.dll (Input=CRYPTSP.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Program Files\nodejs\;C:\Users\rjs7\AppData\Roaming\npm [calling]
77210b8.10bc: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
77310b8.10bc: supR3HardenedDllNotificationCallback: load 000007fefcca0000 LB 0x00018000 C:\Windows\system32\CRYPTSP.dll [fFlags=0x0]
77410b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
77510b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcca0000 'C:\Windows\system32\CRYPTSP.dll'
77610b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
77710b8.10bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\rsaenh.dll)
77810b8.10bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\rsaenh.dll
77910b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
78010b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
78110b8.10bc: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
78210b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Program Files\nodejs\;C:\Users\rjs7\AppData\Roaming\npm [calling]
78310b8.10bc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
78410b8.10bc: supR3HardenedDllNotificationCallback: load 000007fefc9b0000 LB 0x00047000 C:\Windows\system32\rsaenh.dll [fFlags=0x0]
78510b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
78610b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc9b0000 'C:\Windows\system32\rsaenh.dll'
78710b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
78810b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'rpcrt4.dll'.
78910b8.10bc: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\advapi32.dll)
79010b8.10bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\advapi32.dll
79110b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
79210b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
79310b8.10bc: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
79410b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
79510b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
79610b8.10bc: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
79710b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ADVAPI32.dll (Input=ADVAPI32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Program Files\nodejs\;C:\Users\rjs7\AppData\Roaming\npm [calling]
79810b8.10bc: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
79910b8.10bc: supR3HardenedDllNotificationCallback: load 000007feff470000 LB 0x000db000 C:\Windows\system32\ADVAPI32.dll [fFlags=0x0]
80010b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
80110b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msvcrt.dll'.
80210b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'rpcrt4.dll'.
80310b8.10bc: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\sechost.dll)
80410b8.10bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\sechost.dll
80510b8.10bc: supR3HardenedDllNotificationCallback: load 000007fefef90000 LB 0x0001f000 C:\Windows\SYSTEM32\sechost.dll [fFlags=0x0]
80610b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\sechost.dll [lacks WinVerifyTrust]
80710b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff470000 'C:\Windows\system32\ADVAPI32.dll'
80810b8.10bc: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\cryptbase.dll)
80910b8.10bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cryptbase.dll
81010b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
81110b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
81210b8.10bc: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
81310b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
81410b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
81510b8.10bc: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
81610b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTBASE.dll (Input=CRYPTBASE.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Program Files\nodejs\;C:\Users\rjs7\AppData\Roaming\npm [calling]
81710b8.10bc: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptbase.dll [lacks WinVerifyTrust]
81810b8.10bc: supR3HardenedDllNotificationCallback: load 000007fefd330000 LB 0x0000f000 C:\Windows\system32\CRYPTBASE.dll [fFlags=0x0]
81910b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptbase.dll [lacks WinVerifyTrust]
82010b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd330000 'C:\Windows\system32\CRYPTBASE.dll'
82110b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
82210b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Program Files\nodejs\;C:\Users\rjs7\AppData\Roaming\npm [calling]
82310b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00000000774f0000 'C:\Windows\system32\kernel32.dll'
82410b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
82510b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\WINTRUST.DLL (Input=WINTRUST.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Program Files\nodejs\;C:\Users\rjs7\AppData\Roaming\npm [calling]
82610b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd840000 'C:\Windows\system32\WINTRUST.DLL'
82710b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
82810b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPT32.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00000000007d5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Program Files\nodejs\;C:\Users\rjs7\AppData\Roaming\npm [calling]
82910b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd520000 'C:\Windows\system32\CRYPT32.dll'
83010b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
83110b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'advapi32.dll'.
83210b8.10bc: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\imagehlp.dll)
83310b8.10bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\imagehlp.dll
83410b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
83510b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
83610b8.10bc: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
83710b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
83810b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
83910b8.10bc: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
84010b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\imagehlp.dll (Input=imagehlp.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Program Files\nodejs\;C:\Users\rjs7\AppData\Roaming\npm [calling]
84110b8.10bc: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\imagehlp.dll [lacks WinVerifyTrust]
84210b8.10bc: supR3HardenedDllNotificationCallback: load 000007fefeba0000 LB 0x00019000 C:\Windows\system32\imagehlp.dll [fFlags=0x0]
84310b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\imagehlp.dll [lacks WinVerifyTrust]
84410b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefeba0000 'C:\Windows\system32\imagehlp.dll'
84510b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
84610b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTSP.dll (Input=CRYPTSP.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Program Files\nodejs\;C:\Users\rjs7\AppData\Roaming\npm [calling]
84710b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcca0000 'C:\Windows\system32\CRYPTSP.dll'
84810b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
84910b8.10bc: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\user32.dll)
85010b8.10bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\user32.dll
85110b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
85210b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
85310b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
85410b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'lpk.dll'.
85510b8.10bc: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\gdi32.dll)
85610b8.10bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\gdi32.dll
85710b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'lpk.dll'...
85810b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'lpk.dll' -> '\Device\HarddiskVolume2\Windows\System32\lpk.dll' [rcNtRedir=0xc0150008]
85910b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'gdi32.dll'.
86010b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'user32.dll'.
86110b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'usp10.dll'.
86210b8.10bc: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\lpk.dll)
86310b8.10bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\lpk.dll
86410b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
86510b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
86610b8.10bc: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
86710b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'usp10.dll'...
86810b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'usp10.dll' -> '\Device\HarddiskVolume2\Windows\System32\usp10.dll' [rcNtRedir=0xc0150008]
86910b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
87010b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
87110b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'gdi32.dll'.
87210b8.10bc: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\usp10.dll)
87310b8.10bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\usp10.dll
87410b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
87510b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
87610b8.10bc: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
87710b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
87810b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
87910b8.10bc: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
88010b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
88110b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
88210b8.10bc: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
88310b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
88410b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
88510b8.10bc: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
88610b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
88710b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
88810b8.10bc: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
88910b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\USER32.dll (Input=USER32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Program Files\nodejs\;C:\Users\rjs7\AppData\Roaming\npm [calling]
89010b8.10bc: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
89110b8.10bc: supR3HardenedDllNotificationCallback: load 0000000077610000 LB 0x000fa000 C:\Windows\system32\USER32.dll [fFlags=0x0]
89210b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
89310b8.10bc: supR3HardenedDllNotificationCallback: load 000007fefdb30000 LB 0x00067000 C:\Windows\system32\GDI32.dll [fFlags=0x0]
89410b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
89510b8.10bc: supR3HardenedDllNotificationCallback: load 000007feff5d0000 LB 0x0000e000 C:\Windows\system32\LPK.dll [fFlags=0x0]
89610b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\lpk.dll [lacks WinVerifyTrust]
89710b8.10bc: supR3HardenedDllNotificationCallback: load 000007fefdce0000 LB 0x000c9000 C:\Windows\system32\USP10.dll [fFlags=0x0]
89810b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\usp10.dll [lacks WinVerifyTrust]
89910b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
90010b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\gdi32.dll (Input=gdi32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Program Files\nodejs\;C:\Users\rjs7\AppData\Roaming\npm [calling]
90110b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdb30000 'C:\Windows\system32\gdi32.dll'
90210b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'user32.dll'.
90310b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
90410b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msctf.dll'.
90510b8.10bc: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\imm32.dll)
90610b8.10bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\imm32.dll
90710b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msctf.dll'...
90810b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msctf.dll' -> '\Device\HarddiskVolume2\Windows\System32\msctf.dll' [rcNtRedir=0xc0150008]
90910b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
91010b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
91110b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'gdi32.dll'.
91210b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'imm32.dll'.
91310b8.10bc: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\msctf.dll)
91410b8.10bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msctf.dll
91510b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
91610b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
91710b8.10bc: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
91810b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
91910b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
92010b8.10bc: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
92110b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
92210b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume2\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
92310b8.10bc: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\imm32.dll [lacks WinVerifyTrust]
92410b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
92510b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
92610b8.10bc: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
92710b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
92810b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
92910b8.10bc: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
93010b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
93110b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
93210b8.10bc: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
93310b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\IMM32.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Program Files\nodejs\;C:\Users\rjs7\AppData\Roaming\npm [calling]
93410b8.10bc: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\imm32.dll [lacks WinVerifyTrust]
93510b8.10bc: supR3HardenedDllNotificationCallback: load 000007fefda80000 LB 0x0002e000 C:\Windows\system32\IMM32.DLL [fFlags=0x0]
93610b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\imm32.dll [lacks WinVerifyTrust]
93710b8.10bc: supR3HardenedDllNotificationCallback: load 000007feff090000 LB 0x00109000 C:\Windows\system32\MSCTF.dll [fFlags=0x0]
93810b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msctf.dll [lacks WinVerifyTrust]
93910b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefda80000 'C:\Windows\system32\IMM32.DLL'
94010b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077610000 'C:\Windows\system32\USER32.dll'
94110b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'bcrypt.dll'.
94210b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
94310b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msasn1.dll'.
94410b8.10bc: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\ncrypt.dll)
94510b8.10bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ncrypt.dll
94610b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
94710b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume2\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
94810b8.10bc: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
94910b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
95010b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
95110b8.10bc: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
95210b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
95310b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume2\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
95410b8.10bc: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\bcrypt.dll)
95510b8.10bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\bcrypt.dll
95610b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ncrypt.dll (Input=ncrypt.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Program Files\nodejs\;C:\Users\rjs7\AppData\Roaming\npm [calling]
95710b8.10bc: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\ncrypt.dll [lacks WinVerifyTrust]
95810b8.10bc: supR3HardenedDllNotificationCallback: load 000007fefce50000 LB 0x00050000 C:\Windows\system32\ncrypt.dll [fFlags=0x0]
95910b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\ncrypt.dll [lacks WinVerifyTrust]
96010b8.10bc: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
96110b8.10bc: supR3HardenedDllNotificationCallback: load 000007fefce20000 LB 0x00022000 C:\Windows\system32\bcrypt.dll [fFlags=0x0]
96210b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
96310b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefce50000 'C:\Windows\system32\ncrypt.dll'
96410b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
96510b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'bcrypt.dll'.
96610b8.10bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll)
96710b8.10bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll
96810b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
96910b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume2\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
97010b8.10bc: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
97110b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
97210b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
97310b8.10bc: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
97410b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcryptprimitives.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Program Files\nodejs\;C:\Users\rjs7\AppData\Roaming\npm [calling]
97510b8.10bc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
97610b8.10bc: supR3HardenedDllNotificationCallback: load 000007fefc8f0000 LB 0x0004c000 C:\Windows\system32\bcryptprimitives.dll [fFlags=0x0]
97710b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
97810b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc8f0000 'C:\Windows\system32\bcryptprimitives.dll'
97910b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
98010b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcrypt.dll (Input=bcrypt.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Program Files\nodejs\;C:\Users\rjs7\AppData\Roaming\npm [calling]
98110b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefce20000 'C:\Windows\system32\bcrypt.dll'
98210b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
98310b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'rpcrt4.dll'.
98410b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'profapi.dll'.
98510b8.10bc: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\userenv.dll)
98610b8.10bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\userenv.dll
98710b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'profapi.dll'...
98810b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'profapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\profapi.dll' [rcNtRedir=0xc0150008]
98910b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
99010b8.10bc: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\profapi.dll)
99110b8.10bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\profapi.dll
99210b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
99310b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
99410b8.10bc: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
99510b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
99610b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
99710b8.10bc: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
99810b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
99910b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
100010b8.10bc: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
100110b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\USERENV.dll (Input=USERENV.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Program Files\nodejs\;C:\Users\rjs7\AppData\Roaming\npm [calling]
100210b8.10bc: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\userenv.dll [lacks WinVerifyTrust]
100310b8.10bc: supR3HardenedDllNotificationCallback: load 000007fefd7b0000 LB 0x0001e000 C:\Windows\system32\USERENV.dll [fFlags=0x0]
100410b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\userenv.dll [lacks WinVerifyTrust]
100510b8.10bc: supR3HardenedDllNotificationCallback: load 000007fefd4d0000 LB 0x0000f000 C:\Windows\system32\profapi.dll [fFlags=0x0]
100610b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\profapi.dll [lacks WinVerifyTrust]
100710b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd7b0000 'C:\Windows\system32\USERENV.dll'
100810b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007d5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Program Files\nodejs\;C:\Users\rjs7\AppData\Roaming\npm [calling]
100910b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefef90000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
101010b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007d5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Program Files\nodejs\;C:\Users\rjs7\AppData\Roaming\npm [calling]
101110b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefef90000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
101210b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
101310b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'rpcrt4.dll'.
101410b8.10bc: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\gpapi.dll)
101510b8.10bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\gpapi.dll
101610b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
101710b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
101810b8.10bc: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
101910b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
102010b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
102110b8.10bc: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
102210b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\GPAPI.dll (Input=GPAPI.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Program Files\nodejs\;C:\Users\rjs7\AppData\Roaming\npm [calling]
102310b8.10bc: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gpapi.dll [lacks WinVerifyTrust]
102410b8.10bc: supR3HardenedDllNotificationCallback: load 000007fefc7c0000 LB 0x0001b000 C:\Windows\system32\GPAPI.dll [fFlags=0x0]
102510b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gpapi.dll [lacks WinVerifyTrust]
102610b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc7c0000 'C:\Windows\system32\GPAPI.dll'
102710b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-Management-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007d5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Program Files\nodejs\;C:\Users\rjs7\AppData\Roaming\npm [calling]
102810b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefef90000 'API-MS-WIN-Service-Management-L1-1-0.dll'
102910b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
103010b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rpcrt4.dll (Input=rpcrt4.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Program Files\nodejs\;C:\Users\rjs7\AppData\Roaming\npm [calling]
103110b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefee60000 'C:\Windows\system32\rpcrt4.dll'
103210b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-Management-L2-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007d5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Program Files\nodejs\;C:\Users\rjs7\AppData\Roaming\npm [calling]
103310b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefef90000 'API-MS-WIN-Service-Management-L2-1-0.dll'
103410b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007d5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Program Files\nodejs\;C:\Users\rjs7\AppData\Roaming\npm [calling]
103510b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefef90000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
103610b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
103710b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'advapi32.dll'.
103810b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'crypt32.dll'.
103910b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'wldap32.dll'.
104010b8.10bc: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\cryptnet.dll)
104110b8.10bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cryptnet.dll
104210b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wldap32.dll'...
104310b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'wldap32.dll' -> '\Device\HarddiskVolume2\Windows\System32\wldap32.dll' [rcNtRedir=0xc0150008]
104410b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
104510b8.10bc: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\Wldap32.dll)
104610b8.10bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\Wldap32.dll
104710b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
104810b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume2\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
104910b8.10bc: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
105010b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
105110b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
105210b8.10bc: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
105310b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
105410b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
105510b8.10bc: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
105610b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
105710b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
105810b8.10bc: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
105910b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (Input=cryptnet.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Program Files\nodejs\;C:\Users\rjs7\AppData\Roaming\npm [calling]
106010b8.10bc: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
106110b8.10bc: supR3HardenedDllNotificationCallback: load 000007fef9a20000 LB 0x00027000 C:\Windows\system32\cryptnet.dll [fFlags=0x0]
106210b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
106310b8.10bc: supR3HardenedDllNotificationCallback: load 000007fefeb40000 LB 0x00052000 C:\Windows\system32\WLDAP32.dll [fFlags=0x0]
106410b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\Wldap32.dll [lacks WinVerifyTrust]
106510b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
106610b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00000000007d5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Program Files\nodejs\;C:\Users\rjs7\AppData\Roaming\npm [calling]
106710b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef9a20000 'C:\Windows\system32\cryptnet.dll'
106810b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
106910b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00000000007d5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Program Files\nodejs\;C:\Users\rjs7\AppData\Roaming\npm [calling]
107010b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef9a20000 'C:\Windows\system32\cryptnet.dll'
107110b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
107210b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00000000007d5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Program Files\nodejs\;C:\Users\rjs7\AppData\Roaming\npm [calling]
107310b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef9a20000 'C:\Windows\system32\cryptnet.dll'
107410b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
107510b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00000000007d5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Program Files\nodejs\;C:\Users\rjs7\AppData\Roaming\npm [calling]
107610b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef9a20000 'C:\Windows\system32\cryptnet.dll'
107710b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
107810b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00000000007d5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Program Files\nodejs\;C:\Users\rjs7\AppData\Roaming\npm [calling]
107910b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef9a20000 'C:\Windows\system32\cryptnet.dll'
108010b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
108110b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00000000007d5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Program Files\nodejs\;C:\Users\rjs7\AppData\Roaming\npm [calling]
108210b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef9a20000 'C:\Windows\system32\cryptnet.dll'
108310b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
108410b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef9a20000 'C:\Windows\system32\cryptnet.dll'
108510b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
108610b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef9a20000 'C:\Windows\system32\cryptnet.dll'
108710b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
108810b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef9a20000 'C:\Windows\system32\cryptnet.dll'
108910b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
109010b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef9a20000 'C:\Windows\system32\cryptnet.dll'
109110b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
109210b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef9a20000 'C:\Windows\system32\cryptnet.dll'
109310b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef9a20000 'C:\Windows\system32\cryptnet.dll'
109410b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
109510b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef9a20000 'C:\Windows\system32\cryptnet.dll'
109610b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007d5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Program Files\nodejs\;C:\Users\rjs7\AppData\Roaming\npm [calling]
109710b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefef90000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
109810b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\profapi.dll [lacks WinVerifyTrust]
109910b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\profapi.dll (Input=profapi.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Program Files\nodejs\;C:\Users\rjs7\AppData\Roaming\npm [calling]
110010b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd4d0000 'C:\Windows\system32\profapi.dll'
110110b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
110210b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
110310b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msvcrt.dll'.
110410b8.10bc: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\shlwapi.dll)
110510b8.10bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\shlwapi.dll
110610b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
110710b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
110810b8.10bc: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
110910b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
111010b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
111110b8.10bc: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
111210b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
111310b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
111410b8.10bc: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
111510b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\SHLWAPI.dll (Input=SHLWAPI.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Program Files\nodejs\;C:\Users\rjs7\AppData\Roaming\npm [calling]
111610b8.10bc: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll [lacks WinVerifyTrust]
111710b8.10bc: supR3HardenedDllNotificationCallback: load 000007feff550000 LB 0x00071000 C:\Windows\system32\SHLWAPI.dll [fFlags=0x0]
111810b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll [lacks WinVerifyTrust]
111910b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff550000 'C:\Windows\system32\SHLWAPI.dll'
112010b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000000 pwszName=\SystemRoot\System32\ntdll.dll
112110b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: New context 00000000008572b0
112210b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008572b0
112310b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=771D512B7B1C39F0393BD4EF9FC62F442783FB35
112410b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007d5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Program Files\nodejs\;C:\Users\rjs7\AppData\Roaming\npm [calling]
112510b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefef90000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
112610b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-Management-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007d5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Program Files\nodejs\;C:\Users\rjs7\AppData\Roaming\npm [calling]
112710b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefef90000 'API-MS-WIN-Service-Management-L1-1-0.dll'
112810b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-winsvc-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007d5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Program Files\nodejs\;C:\Users\rjs7\AppData\Roaming\npm [calling]
112910b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefef90000 'API-MS-WIN-Service-winsvc-L1-1-0.dll'
113010b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
113110b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ADVAPI32.dll (Input=ADVAPI32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Program Files\nodejs\;C:\Users\rjs7\AppData\Roaming\npm [calling]
113210b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff470000 'C:\Windows\system32\ADVAPI32.dll'
113310b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-LSALookup-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007d5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Program Files\nodejs\;C:\Users\rjs7\AppData\Roaming\npm [calling]
113410b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefef90000 'API-MS-Win-Security-LSALookup-L1-1-0.dll'
113510b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-LSALookup-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007d5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Program Files\nodejs\;C:\Users\rjs7\AppData\Roaming\npm [calling]
113610b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefef90000 'API-MS-Win-Security-LSALookup-L1-1-0.dll'
113710b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_5_for_KB2882822~31bf3856ad364e35~amd64~~6.1.1.2.cat'; file='\SystemRoot\System32\ntdll.dll'
113810b8.10bc: g_pfnWinVerifyTrust=000007fefd841010
113910b8.10bc: supR3HardenedScreenImage/preload: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [redoing WinVerifyTrust]
114010b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000e0 pwszName=\Device\HarddiskVolume2\Windows\System32\crypt32.dll
114110b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008572b0
114210b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008572b0
114310b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=E4581771CBFFF32DF331EF17B5C5FD7E1F614302
114410b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_136_for_KB2949927~31bf3856ad364e35~amd64~~6.1.1.5.cat'; file='\Device\HarddiskVolume2\Windows\System32\crypt32.dll'
114510b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
114610b8.10bc: supR3HardenedScreenImage/preload: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\crypt32.dll'
114710b8.10bc: supR3HardenedScreenImage/preload: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [redoing WinVerifyTrust]
114810b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000d4 pwszName=\Device\HarddiskVolume2\Windows\System32\wintrust.dll
114910b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008572b0
115010b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008572b0
115110b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=108407301192217C74BC9FE609CA642A66DBE98B
115210b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_91_for_KB2949927~31bf3856ad364e35~amd64~~6.1.1.5.cat'; file='\Device\HarddiskVolume2\Windows\System32\wintrust.dll'
115310b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
115410b8.10bc: supR3HardenedScreenImage/preload: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\wintrust.dll'
115510b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000003a4 pwszName=\Device\HarddiskVolume2\Windows\System32\shlwapi.dll
115610b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008572b0
115710b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008572b0
115810b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=0AB8D9C9D3E1FC95D01F9A984B16ED031BB40CD8
115910b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\shlwapi.dll'
116010b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
116110b8.10bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll'
116210b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000398 pwszName=\Device\HarddiskVolume2\Windows\System32\Wldap32.dll
116310b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008572b0
116410b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008572b0
116510b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=87E73086F2528CF31D3AD5F0D71E04F8B942D5D8
116610b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\Wldap32.dll'
116710b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
116810b8.10bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\Wldap32.dll'
116910b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000394 pwszName=\Device\HarddiskVolume2\Windows\System32\cryptnet.dll
117010b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008572b0
117110b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008572b0
117210b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=C1C670A9871F2BD448B2F0FA6127AC7A486B8D8F
117310b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_91_for_KB2949927~31bf3856ad364e35~amd64~~6.1.1.5.cat'; file='\Device\HarddiskVolume2\Windows\System32\cryptnet.dll'
117410b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
117510b8.10bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\cryptnet.dll'
117610b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000260 pwszName=\Device\HarddiskVolume2\Windows\System32\gpapi.dll
117710b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008572b0
117810b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008572b0
117910b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=470795C189226F7BDB8E50F42104CC34488B9340
118010b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\gpapi.dll'
118110b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
118210b8.10bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\gpapi.dll'
118310b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000001cc pwszName=\Device\HarddiskVolume2\Windows\System32\profapi.dll
118410b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008572b0
118510b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008572b0
118610b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2449672745D9BA339420451D13FA0380AA768231
118710b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\profapi.dll'
118810b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
118910b8.10bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\profapi.dll'
119010b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000001c8 pwszName=\Device\HarddiskVolume2\Windows\System32\userenv.dll
119110b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008572b0
119210b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008572b0
119310b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=D3E1A2CC7367F751C19EBF4E6EDF5E9A10E47313
119410b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\userenv.dll'
119510b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
119610b8.10bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\userenv.dll'
119710b8.10bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll'
119810b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000001a0 pwszName=\Device\HarddiskVolume2\Windows\System32\bcrypt.dll
119910b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008572b0
120010b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008572b0
120110b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=62E377A1F0AD0C2EDC0A73CB3EFF841FF18D00D2
120210b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\bcrypt.dll'
120310b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
120410b8.10bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\bcrypt.dll'
120510b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000019c pwszName=\Device\HarddiskVolume2\Windows\System32\ncrypt.dll
120610b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008572b0
120710b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008572b0
120810b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=D68DA0EBD4E0AA6C401CF7C54CEA904099DD3933
120910b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_52_for_KB2992611~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\Windows\System32\ncrypt.dll'
121010b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
121110b8.10bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\ncrypt.dll'
121210b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000184 pwszName=\Device\HarddiskVolume2\Windows\System32\msctf.dll
121310b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008572b0
121410b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008572b0
121510b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=803AF52F95A9EFDFDA06C595023831EE36ACD3A8
121610b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\msctf.dll'
121710b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
121810b8.10bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\msctf.dll'
121910b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000180 pwszName=\Device\HarddiskVolume2\Windows\System32\imm32.dll
122010b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008572b0
122110b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008572b0
122210b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=6EEE1AB3B6D79AFF857940FF5F51ED27698153EC
122310b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\imm32.dll'
122410b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
122510b8.10bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\imm32.dll'
122610b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000017c pwszName=\Device\HarddiskVolume2\Windows\System32\usp10.dll
122710b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008572b0
122810b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008572b0
122910b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=1F1AA8340DE02FC1B6341EE2706E55D56EDF63B8
123010b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB2957509~31bf3856ad364e35~amd64~~6.1.1.2.cat'; file='\Device\HarddiskVolume2\Windows\System32\usp10.dll'
123110b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
123210b8.10bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\usp10.dll'
123310b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000178 pwszName=\Device\HarddiskVolume2\Windows\System32\lpk.dll
123410b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008572b0
123510b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008572b0
123610b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=6FCA4D678614C8615E6E5C082BF3A4562FCF14EB
123710b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB2847311~31bf3856ad364e35~amd64~~6.1.1.2.cat'; file='\Device\HarddiskVolume2\Windows\System32\lpk.dll'
123810b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
123910b8.10bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\lpk.dll'
124010b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000174 pwszName=\Device\HarddiskVolume2\Windows\System32\gdi32.dll
124110b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008572b0
124210b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008572b0
124310b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=7AEB59C2353484ADF282BEA358113ABD82C223B9
124410b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB2993651~31bf3856ad364e35~amd64~~6.1.1.3.cat'; file='\Device\HarddiskVolume2\Windows\System32\gdi32.dll'
124510b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
124610b8.10bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\gdi32.dll'
124710b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000170 pwszName=\Device\HarddiskVolume2\Windows\System32\user32.dll
124810b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008572b0
124910b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008572b0
125010b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B723D1B8AD72750B0CF5F6BEC66171B1254ED879
125110b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\user32.dll'
125210b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
125310b8.10bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\user32.dll'
125410b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000016c pwszName=\Device\HarddiskVolume2\Windows\System32\imagehlp.dll
125510b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008572b0
125610b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008572b0
125710b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2702EE05F1B717B0F2CE0FBE32784A47B8419DCA
125810b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_2_for_KB2893294~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\imagehlp.dll'
125910b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
126010b8.10bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\imagehlp.dll'
126110b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000120 pwszName=\Device\HarddiskVolume2\Windows\System32\cryptbase.dll
126210b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008572b0
126310b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008572b0
126410b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=A965CC5DB13A5FB23BBB1B6B5FA6D400DC49462F
126510b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\cryptbase.dll'
126610b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
126710b8.10bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\cryptbase.dll'
126810b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000114 pwszName=\Device\HarddiskVolume2\Windows\System32\sechost.dll
126910b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008572b0
127010b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008572b0
127110b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=3FA2A014BF360CDC0E203A174FFC9DC5343C5323
127210b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\sechost.dll'
127310b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
127410b8.10bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\sechost.dll'
127510b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000108 pwszName=\Device\HarddiskVolume2\Windows\System32\advapi32.dll
127610b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008572b0
127710b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008572b0
127810b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=7C0A1C638CE7C1160F49C473EC1420BD3AB693C4
127910b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_5_for_KB2882822~31bf3856ad364e35~amd64~~6.1.1.2.cat'; file='\Device\HarddiskVolume2\Windows\System32\advapi32.dll'
128010b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
128110b8.10bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\advapi32.dll'
128210b8.10bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\rsaenh.dll'
128310b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000104 pwszName=\Device\HarddiskVolume2\Windows\System32\cryptsp.dll
128410b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008572b0
128510b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008572b0
128610b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=FE601E1BC89E11CA16D1CA31315BC348EFAF0C74
128710b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_91_for_KB2949927~31bf3856ad364e35~amd64~~6.1.1.5.cat'; file='\Device\HarddiskVolume2\Windows\System32\cryptsp.dll'
128810b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
128910b8.10bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\cryptsp.dll'
129010b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000e4 pwszName=\Device\HarddiskVolume2\Windows\System32\msvcrt.dll
129110b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008572b0
129210b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008572b0
129310b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2CA2FD632B264C063162F71474266E3615B6420C
129410b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB2654428~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\Windows\System32\msvcrt.dll'
129510b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
129610b8.10bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll'
129710b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000dc pwszName=\Device\HarddiskVolume2\Windows\System32\msasn1.dll
129810b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008572b0
129910b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008572b0
130010b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F2FF57DC30D774F93061607060DAA0DD15E39CCE
130110b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\msasn1.dll'
130210b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
130310b8.10bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\msasn1.dll'
130410b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000d8 pwszName=\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
130510b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008572b0
130610b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008572b0
130710b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=03E871CFC4A3E7194619AFC99CEEA1EC75982D12
130810b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB2978668~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll'
130910b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
131010b8.10bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll'
131110b8.10bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll'
131210b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000028 pwszName=\Device\HarddiskVolume2\Windows\System32\KernelBase.dll
131310b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008572b0
131410b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008572b0
131510b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=57EB6F834C5A5D9585A660D91756134028A3B089
131610b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_54_for_KB2871997~31bf3856ad364e35~amd64~~6.1.2.5.cat'; file='\Device\HarddiskVolume2\Windows\System32\KernelBase.dll'
131710b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
131810b8.10bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\KernelBase.dll'
131910b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000020 pwszName=\Device\HarddiskVolume2\Windows\System32\kernel32.dll
132010b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008572b0
132110b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008572b0
132210b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=5349346AE66DA4E3A7206628F484AC3B3AA43776
132310b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_54_for_KB2871997~31bf3856ad364e35~amd64~~6.1.2.5.cat'; file='\Device\HarddiskVolume2\Windows\System32\kernel32.dll'
132410b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
132510b8.10bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\kernel32.dll'
132610b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll
132710b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\crypt32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000114ec10:C:\Windows\system32 [calling]
132810b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd520000 'C:\Windows\system32\crypt32.dll'
132910b8.10bc: supR3HardenedWinIsDesiredRootCA: Adding 0xc0f405ab4fb0ba00 CN=localhost, O=Skype Click to Call, OU=Skype Click to Call
133010b8.10bc: supR3HardenedWinIsDesiredRootCA: Adding 0x5ad46780fa5df300 DC=com, DC=microsoft, CN=Microsoft Root Certificate Authority
133110b8.10bc: supR3HardenedWinIsDesiredRootCA: Adding 0xea5386456178582b C=ZA, ST=Western Cape, L=Durbanville, O=Thawte, OU=Thawte Certification, CN=Thawte Timestamping CA
133210b8.10bc: supR3HardenedWinIsDesiredRootCA: Adding 0x3be670c1bd02a900 OU=Copyright (c) 1997 Microsoft Corp., OU=Microsoft Corporation, CN=Microsoft Root Authority
133310b8.10bc: supR3HardenedWinIsDesiredRootCA: Adding 0x4d3835aa4180b200 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2011
133410b8.10bc: supR3HardenedWinIsDesiredRootCA: Adding 0x646e3fe3ba08df00 C=US, O=MSFT, CN=Microsoft Authenticode(tm) Root Authority
133510b8.10bc: supR3HardenedWinIsDesiredRootCA: Adding 0xbf1f81e5a97406aa CN=USB\VID_0781&PID_5150 (libwdi autogenerated)
133610b8.10bc: supR3HardenedWinIsDesiredRootCA: Adding 0xece4e4289e08b900 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010
133710b8.10bc: supR3HardenedWinIsDesiredRootCA: Adding 0x5675ad49101bb3f2 CN=USB\VID_0764&PID_0501 (libwdi autogenerated)
133810b8.10bc: supR3HardenedWinIsDesiredRootCA: Adding 0x43a9cc371ff5385a O=Microsoft Trust Network, OU=Microsoft Corporation, OU=Microsoft Time Stamping Service Root, OU=Copyright (c) 1997 Microsoft Corp.
133910b8.10bc: supR3HardenedWinIsDesiredRootCA: Adding 0x2e2d2c7c68f0202e O=VeriSign Trust Network, OU=VeriSign, Inc., OU=VeriSign Time Stamping Service Root, OU=NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.
134010b8.10bc: supR3HardenedWinIsDesiredRootCA: Adding 0x91e3728b8b40d000 C=GB, ST=Greater Manchester, L=Salford, O=COMODO CA Limited, CN=COMODO Certification Authority
134110b8.10bc: supR3HardenedWinIsDesiredRootCA: Adding 0x61a3a33f81aace00 C=US, ST=UT, L=Salt Lake City, O=The USERTRUST Network, OU=http://www.usertrust.com, CN=UTN-USERFirst-Object
134210b8.10bc: supR3HardenedWinIsDesiredRootCA: Adding 0x9e5bc2d78b6a3636 C=ZA, ST=Western Cape, L=Cape Town, O=Thawte Consulting cc, OU=Certification Services Division, CN=Thawte Premium Server CA, [email protected]
134310b8.10bc: supR3HardenedWinIsDesiredRootCA: Adding 0xf4fd306318ccda00 C=US, O=GeoTrust Inc., CN=GeoTrust Global CA
134410b8.10bc: supR3HardenedWinIsDesiredRootCA: Adding 0x83085097e9afdf00 O=Digital Signature Trust Co., CN=DST Root CA X3
134510b8.10bc: supR3HardenedWinIsDesiredRootCA: Adding 0xe248b7eeee4af00 C=CH, O=SwissSign AG, CN=SwissSign Gold CA - G2
134610b8.10bc: supR3HardenedWinIsDesiredRootCA: Adding 0x780679907625cc00 OU=GlobalSign Root CA - R3, O=GlobalSign, CN=GlobalSign
134710b8.10bc: supR3HardenedWinIsDesiredRootCA: Adding 0x3d98ab22bb04a300 C=IE, O=Baltimore, OU=CyberTrust, CN=Baltimore CyberTrust Root
134810b8.10bc: supR3HardenedWinIsDesiredRootCA: Adding 0xa0ee62086758b15d C=US, O=Equifax, OU=Equifax Secure Certificate Authority
134910b8.10bc: supR3HardenedWinIsDesiredRootCA: Adding 0x8ff6fc03c1edbd00 C=US, ST=Arizona, L=Scottsdale, O=Starfield Technologies, Inc., CN=Starfield Root Certificate Authority - G2
135010b8.10bc: supR3HardenedWinIsDesiredRootCA: Adding 0xc6fa4243b695b600 C=US, O=Entrust, Inc., OU=www.entrust.net/CPS is incorporated by reference, OU=(c) 2006 Entrust, Inc., CN=Entrust Root Certification Authority
135110b8.10bc: supR3HardenedWinIsDesiredRootCA: Adding 0xa3ce8d99e60eda00 C=BE, O=GlobalSign nv-sa, OU=Root CA, CN=GlobalSign Root CA
135210b8.10bc: supR3HardenedWinIsDesiredRootCA: Adding 0xa671e9fec832b700 C=US, O=Starfield Technologies, Inc., OU=Starfield Class 2 Certification Authority
135310b8.10bc: supR3HardenedWinIsDesiredRootCA: Adding 0xa8de7211e13be200 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root CA
135410b8.10bc: supR3HardenedWinIsDesiredRootCA: Adding 0x14018a1bf29e595c C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority
135510b8.10bc: supR3HardenedWinIsDesiredRootCA: Adding 0xff3891b54348328 C=US, O=Entrust.net, OU=www.entrust.net/CPS incorp. by ref. (limits liab.), OU=(c) 1999 Entrust.net Limited, CN=Entrust.net Secure Server Certification Authority
135610b8.10bc: supR3HardenedWinIsDesiredRootCA: Adding 0xabd0695c5d11d15e C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority - G2, OU=(c) 1998 VeriSign, Inc. - For authorized use only, OU=VeriSign Trust Network
135710b8.10bc: supR3HardenedWinIsDesiredRootCA: Adding 0x7ae89c50f0b6a00f C=US, O=GTE Corporation, OU=GTE CyberTrust Solutions, Inc., CN=GTE CyberTrust Global Root
135810b8.10bc: supR3HardenedWinIsDesiredRootCA: Adding 0xd45980fbf0a0ac00 C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2006 thawte, Inc. - For authorized use only, CN=thawte Primary Root CA
135910b8.10bc: supR3HardenedWinIsDesiredRootCA: Adding 0x5a341635fb75d800 C=US, O=U.S. Government, OU=FPKI, CN=Federal Common Policy CA
136010b8.10bc: supR3HardenedWinIsDesiredRootCA: Adding 0x4d3835aa4180b200 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2011
136110b8.10bc: supR3HardenedWinIsDesiredRootCA: Adding 0xf5cd95e581a4ab00 C=US, O=SecureTrust Corporation, CN=SecureTrust CA
136210b8.10bc: supR3HardenedWinIsDesiredRootCA: Adding 0x298be035a30bab00 C=DE, O=Deutsche Telekom AG, OU=T-TeleSec Trust Center, CN=Deutsche Telekom Root CA 2
136310b8.10bc: supR3HardenedWinIsDesiredRootCA: Adding 0xabd0695c5d11d15e C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority - G2, OU=(c) 1998 VeriSign, Inc. - For authorized use only, OU=VeriSign Trust Network
136410b8.10bc: supR3HardenedWinIsDesiredRootCA: Adding 0x14018a1bf29e595c C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority
136510b8.10bc: supR3HardenedWinIsDesiredRootCA: Adding 0xab549401526569d3 L=Internet, O=VeriSign, Inc., OU=VeriSign Commercial Software Publishers CA
136610b8.10bc: supR3HardenedWinIsDesiredRootCA: Adding 0x9e5bc2d78b6a3636 C=ZA, ST=Western Cape, L=Cape Town, O=Thawte Consulting cc, OU=Certification Services Division, CN=Thawte Premium Server CA, [email protected]
136710b8.10bc: supR3HardenedWinIsDesiredRootCA: Adding 0xd4fbe673e5ccc600 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA
136810b8.10bc: supR3HardenedWinIsDesiredRootCA: Adding 0x16e64d2a56ccf200 C=US, ST=Arizona, L=Scottsdale, O=Starfield Technologies, Inc., OU=http://certificates.starfieldtech.com/repository/, CN=Starfield Services Root Certificate Authority
136910b8.10bc: supR3HardenedWinIsDesiredRootCA: Adding 0xb28612a94b4dad00 O=Entrust.net, OU=www.entrust.net/CPS_2048 incorp. by ref. (limits liab.), OU=(c) 1999 Entrust.net Limited, CN=Entrust.net Certification Authority (2048)
137010b8.10bc: supR3HardenedWinIsDesiredRootCA: Adding 0x14018a1bf29e595c C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority
137110b8.10bc: supR3HardenedWinIsDesiredRootCA: Adding 0x357a29080824af00 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2006 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G5
137210b8.10bc: supR3HardenedWinIsDesiredRootCA: Adding 0x59faf1086271bf00 C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com, Inc., CN=Go Daddy Root Certificate Authority - G2
137310b8.10bc: supR3HardenedWinIsDesiredRootCA: Adding 0x466cbc09db88c100 C=IL, O=StartCom Ltd., OU=Secure Digital Certificate Signing, CN=StartCom Certification Authority
137410b8.10bc: supR3HardenedWinIsDesiredRootCA: Adding 0xece4e4289e08b900 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010
137510b8.10bc: supR3HardenedWinIsDesiredRootCA: Adding 0x30669a4e82fa800 C=US, O=America Online Inc., CN=America Online Root Certification Authority 1
137610b8.10bc: supR3HardenedWinIsDesiredRootCA: Adding 0x7cd4ff7b15b8be00 C=US, O=GeoTrust Inc., CN=GeoTrust Primary Certification Authority
137710b8.10bc: supR3HardenedWinIsDesiredRootCA: Adding 0x9259c8abe5ca713a L=ValiCert Validation Network, O=ValiCert, Inc., OU=ValiCert Class 2 Policy Validation Authority, CN=http://www.valicert.com/, [email protected]
137810b8.10bc: supR3HardenedWinIsDesiredRootCA: Adding 0x491857ead79dde00 C=US, O=The Go Daddy Group, Inc., OU=Go Daddy Class 2 Certification Authority
137910b8.10bc: supR3HardenedWinIsDesiredRootCA: Adding 0xab549401526569d3 L=Internet, O=VeriSign, Inc., OU=VeriSign Commercial Software Publishers CA
138010b8.10bc: supR3HardenedWinIsDesiredRootCA: Adding 0xe66b56ffc86e50a4 C=ZA, ST=Western Cape, L=Cape Town, O=Thawte Consulting cc, OU=Certification Services Division, CN=Thawte Server CA, [email protected]
138110b8.10bc: supR3HardenedWinIsDesiredRootCA: Adding 0x92ac5ed85c2d0e9b C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2007 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G4
138210b8.10bc: supR3HardenedWinIsDesiredRootCA: Adding 0x1f78fc529cbacb00 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 1999 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G3
138310b8.10bc: supR3HardenedWinIsDesiredRootCA: Adding 0x8043e4ce150ead00 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID Root CA
138410b8.10bc: supR3HardenedWinIsDesiredRootCA: Adding 0xa8b43f38c3f7b100 C=US, ST=UT, L=Salt Lake City, O=The USERTRUST Network, OU=http://www.usertrust.com, CN=UTN-USERFirst-Hardware
138510b8.10bc: supR3HardenedWinIsDesiredRootCA: Adding 0xf2e6331af7b700 C=SE, O=AddTrust AB, OU=AddTrust External TTP Network, CN=AddTrust External CA Root
138610b8.10bc: supR3HardenedWinRetrieveTrustedRootCAs: cAdded=57
138710b8.10bc: SUPR3HardenedMain: Load Runtime...
138810b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
138910b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
139010b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ws2_32.dll'.
139110b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'rpcrt4.dll'.
139210b8.10bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll)WinVerifyTrust
139310b8.10bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
139410b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
139510b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
139610b8.10bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
139710b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
139810b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
139910b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000448 pwszName=\Device\HarddiskVolume2\Windows\System32\ws2_32.dll
140010b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008572b0
140110b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008572b0
140210b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=3EF3BDC1E84DFA17EA056313214EE88EC3E66F79
140310b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\ws2_32.dll'
140410b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
140510b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
140610b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'rpcrt4.dll'.
140710b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'nsi.dll'.
140810b8.10bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ws2_32.dll)WinVerifyTrust
140910b8.10bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
141010b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
141110b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
141210b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
141310b8.10bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll)WinVerifyTrust
141410b8.10bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
141510b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
141610b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
141710b8.10bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll)WinVerifyTrust
141810b8.10bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
141910b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
142010b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
142110b8.10bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
142210b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
142310b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume2\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
142410b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000460 pwszName=\Device\HarddiskVolume2\Windows\System32\nsi.dll
142510b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008572b0
142610b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008572b0
142710b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=7AFD8538945F2D05BC1AF949B9B19B7D2D9FBBF8
142810b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\nsi.dll'
142910b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
143010b8.10bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\nsi.dll)WinVerifyTrust
143110b8.10bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\nsi.dll
143210b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
143310b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
143410b8.10bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
143510b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
143610b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
143710b8.10bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
143810b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000087a420:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
143910b8.10bc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
144010b8.10bc: supR3HardenedDllNotificationCallback: load 000007feeff10000 LB 0x00531000 C:\Program Files\Oracle\VirtualBox\VBoxRT.dll [fFlags=0x0]
144110b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
144210b8.10bc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
144310b8.10bc: supR3HardenedDllNotificationCallback: load 0000000070360000 LB 0x000d2000 C:\Program Files\Oracle\VirtualBox\MSVCR100.dll [fFlags=0x0]
144410b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
144510b8.10bc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
144610b8.10bc: supR3HardenedDllNotificationCallback: load 00000000702c0000 LB 0x00098000 C:\Program Files\Oracle\VirtualBox\MSVCP100.dll [fFlags=0x0]
144710b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
144810b8.10bc: supR3HardenedDllNotificationCallback: load 000007fefebc0000 LB 0x0004d000 C:\Windows\system32\WS2_32.dll [fFlags=0x0]
144910b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
145010b8.10bc: supR3HardenedDllNotificationCallback: load 000007fefda70000 LB 0x00008000 C:\Windows\system32\NSI.dll [fFlags=0x0]
145110b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\nsi.dll
145210b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
145310b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Program Files\nodejs\;C:\Users\rjs7\AppData\Roaming\npm [calling]
145410b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeff10000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
145510b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
145610b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Program Files\nodejs\;C:\Users\rjs7\AppData\Roaming\npm [calling]
145710b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeff10000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
145810b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
145910b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Program Files\nodejs\;C:\Users\rjs7\AppData\Roaming\npm [calling]
146010b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeff10000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
146110b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
146210b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Program Files\nodejs\;C:\Users\rjs7\AppData\Roaming\npm [calling]
146310b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeff10000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
146410b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
146510b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Program Files\nodejs\;C:\Users\rjs7\AppData\Roaming\npm [calling]
146610b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeff10000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
146710b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
146810b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Program Files\nodejs\;C:\Users\rjs7\AppData\Roaming\npm [calling]
146910b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeff10000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
147010b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeff10000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
147110b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeff10000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
147210b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeff10000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
147310b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeff10000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
147410b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeff10000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
147510b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeff10000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
147610b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeff10000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
147710b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
147810b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Program Files\nodejs\;C:\Users\rjs7\AppData\Roaming\npm [calling]
147910b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeff10000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
148010b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeff10000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
148110b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeff10000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
148210b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeff10000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
148310b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeff10000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
148410b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeff10000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
148510b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeff10000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
148610b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeff10000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
148710b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeff10000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
148810b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeff10000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
148910b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeff10000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
149010b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeff10000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
149110b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeff10000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
149210b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeff10000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
149310b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeff10000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
149410b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeff10000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
149510b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
149610b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5c90:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\Tools\Binn\;c:\Program Files\Microsoft SQL Server\100\DTS\Binn\;c:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;c:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\;c:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Windows\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\Microsoft ASP.NET\ASP.NET Web Pages\v1.0\;C:\Program Files\Microsoft SQL Server\110\Tools\Binn\;C:\utils\;C:\Program Files (x86)\Common Files\Seagate\SnapAPI\;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft\Web Platform Installer\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Microsoft SDKs\TypeScript\1.0\;C:\Program Files\nodejs\;C:\Users\rjs7\AppData\Roaming\npm [calling]
149710b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeff10000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
149810b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeff10000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
149910b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeff10000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
150010b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeff10000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
150110b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll
150210b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000033b6f30:C:\Windows\system32 [calling]
150310b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd840000 'C:\Windows\system32\Wintrust.dll'
150410b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll
150510b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\crypt32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000033b6f30:C:\Windows\system32 [calling]
150610b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd520000 'C:\Windows\system32\crypt32.dll'
150710b8.10bc: SUPR3HardenedMain: Load TrustedMain...
150810b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'opengl32.dll'.
150910b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
151010b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcp100.dll'.
151110b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcr100.dll'.
151210b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qtcorevbox4.dll'.
151310b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'qtguivbox4.dll'.
151410b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'qtnetworkvbox4.dll'.
151510b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'qtopenglvbox4.dll'.
151610b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'user32.dll'.
151710b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'gdi32.dll'.
151810b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'advapi32.dll'.
151910b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'shell32.dll'.
152010b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'ole32.dll'.
152110b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'oleaut32.dll'.
152210b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #15 'comdlg32.dll'.
152310b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'winmm.dll'.
152410b8.10bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.dll)WinVerifyTrust
152510b8.10bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.dll
152610b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
152710b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
152810b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004a0 pwszName=\Device\HarddiskVolume2\Windows\System32\winmm.dll
152910b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008572b0
153010b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008572b0
153110b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=82E2B2A7826F88BEB98FFF0540C9BDB0A12F001A
153210b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\winmm.dll'
153310b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
153410b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
153510b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
153610b8.10bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\winmm.dll)WinVerifyTrust
153710b8.10bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\winmm.dll
153810b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comdlg32.dll'...
153910b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'comdlg32.dll' -> '\Device\HarddiskVolume2\Windows\System32\comdlg32.dll' [rcNtRedir=0xc0150008]
154010b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000480 pwszName=\Device\HarddiskVolume2\Windows\System32\comdlg32.dll
154110b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008572b0
154210b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008572b0
154310b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=66EE5BDFFA413AEA9E1FE7838A08646E94136DA5
154410b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\comdlg32.dll'
154510b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
154610b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
154710b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'shlwapi.dll'.
154810b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
154910b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'gdi32.dll'.
155010b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'comctl32.dll'.
155110b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'shell32.dll'.
155210b8.10bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\comdlg32.dll)WinVerifyTrust
155310b8.10bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\comdlg32.dll
155410b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
155510b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
155610b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000494 pwszName=\Device\HarddiskVolume2\Windows\System32\oleaut32.dll
155710b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008572b0
155810b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008572b0
155910b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=59C9A3379D97CB80EFB9D9152AF4E0240DDF8B29
156010b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3006226~31bf3856ad364e35~amd64~~6.1.1.4.cat'; file='\Device\HarddiskVolume2\Windows\System32\oleaut32.dll'
156110b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
156210b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ole32.dll'.
156310b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
156410b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
156510b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'user32.dll'.
156610b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'gdi32.dll'.
156710b8.10bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\oleaut32.dll)WinVerifyTrust
156810b8.10bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
156910b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
157010b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
157110b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004ac pwszName=\Device\HarddiskVolume2\Windows\System32\ole32.dll
157210b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008572b0
157310b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008572b0
157410b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2E64AE329BD5124592BC8CB0B327AA3B95DC65B7
157510b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\ole32.dll'
157610b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
157710b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
157810b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
157910b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'user32.dll'.
158010b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'rpcrt4.dll'.
158110b8.10bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ole32.dll)WinVerifyTrust
158210b8.10bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ole32.dll
158310b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
158410b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
158510b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004a4 pwszName=\Device\HarddiskVolume2\Windows\System32\shell32.dll
158610b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008572b0
158710b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008572b0
158810b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=8D11B9B481EE916E64C94F8ECA71C2995A2999B7
158910b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_2_for_KB2980245~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\Windows\System32\shell32.dll'
159010b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
159110b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
159210b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #21 'shlwapi.dll'.
159310b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'user32.dll'.
159410b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #24 'gdi32.dll'.
159510b8.10bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\shell32.dll)WinVerifyTrust
159610b8.10bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\shell32.dll
159710b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
159810b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
159910b8.10bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
160010b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
160110b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
160210b8.10bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll
160310b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
160410b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
160510b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtopenglvbox4.dll'...
160610b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtopenglvbox4.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qtopenglvbox4.dll' [rcNtRedir=0xc0150008]
160710b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'opengl32.dll'.
160810b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
160910b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
161010b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qtguivbox4.dll'.
161110b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qtcorevbox4.dll'.
161210b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcr100.dll'.
161310b8.10bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll)WinVerifyTrust
161410b8.10bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll
161510b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtnetworkvbox4.dll'...
161610b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtnetworkvbox4.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qtnetworkvbox4.dll' [rcNtRedir=0xc0150008]
161710b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ws2_32.dll'.
161810b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'qtcorevbox4.dll'.
161910b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcr100.dll'.
162010b8.10bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtNetworkVBox4.dll)WinVerifyTrust
162110b8.10bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtNetworkVBox4.dll
162210b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtguivbox4.dll'...
162310b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtguivbox4.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qtguivbox4.dll' [rcNtRedir=0xc0150008]
162410b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
162510b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'comdlg32.dll'.
162610b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'oleaut32.dll'.
162710b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'imm32.dll'.
162810b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'winmm.dll'.
162910b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'winspool.drv'.
163010b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ole32.dll'.
163110b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'user32.dll'.
163210b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'advapi32.dll'.
163310b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'shell32.dll'.
163410b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'qtcorevbox4.dll'.
163510b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'msvcp100.dll'.
163610b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'msvcr100.dll'.
163710b8.10bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll)WinVerifyTrust
163810b8.10bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll
163910b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtcorevbox4.dll'...
164010b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtcorevbox4.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qtcorevbox4.dll' [rcNtRedir=0xc0150008]
164110b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
164210b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'ole32.dll'.
164310b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
164410b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ws2_32.dll'.
164510b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcp100.dll'.
164610b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcr100.dll'.
164710b8.10bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll)WinVerifyTrust
164810b8.10bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll
164910b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
165010b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
165110b8.10bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
165210b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
165310b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
165410b8.10bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
165510b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
165610b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
165710b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
165810b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
165910b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004e8 pwszName=\Device\HarddiskVolume2\Windows\System32\opengl32.dll
166010b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008572b0
166110b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008572b0
166210b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=608AC397FCC42B9FBAE25CB8C25EAF4C19AA384D
166310b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\opengl32.dll'
166410b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
166510b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
166610b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
166710b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'gdi32.dll'.
166810b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'glu32.dll'.
166910b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ddraw.dll'.
167010b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'user32.dll'.
167110b8.10bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\opengl32.dll)WinVerifyTrust
167210b8.10bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\opengl32.dll
167310b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
167410b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
167510b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ddraw.dll'...
167610b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'ddraw.dll' -> '\Device\HarddiskVolume2\Windows\System32\ddraw.dll' [rcNtRedir=0xc0150008]
167710b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004dc pwszName=\Device\HarddiskVolume2\Windows\System32\ddraw.dll
167810b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008572b0
167910b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008572b0
168010b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=24C763EA54CD792A0F1618411061DC356EE31FF6
168110b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\ddraw.dll'
168210b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
168310b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
168410b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
168510b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'dciman32.dll'.
168610b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
168710b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'setupapi.dll'.
168810b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'dwmapi.dll'.
168910b8.10bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ddraw.dll)WinVerifyTrust
169010b8.10bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ddraw.dll
169110b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'glu32.dll'...
169210b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'glu32.dll' -> '\Device\HarddiskVolume2\Windows\System32\glu32.dll' [rcNtRedir=0xc0150008]
169310b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004d8 pwszName=\Device\HarddiskVolume2\Windows\System32\glu32.dll
169410b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008572b0
169510b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008572b0
169610b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=60E45AB914E06A11F44EA76C6EF750AF892F9EA2
169710b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\glu32.dll'
169810b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
169910b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
170010b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'opengl32.dll'.
170110b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
170210b8.10bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\glu32.dll)WinVerifyTrust
170310b8.10bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\glu32.dll
170410b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
170510b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
170610b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
170710b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
170810b8.10bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
170910b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
171010b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
171110b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
171210b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
171310b8.10bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
171410b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
171510b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
171610b8.10bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
171710b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
171810b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
171910b8.10bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
172010b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
172110b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
172210b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
172310b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
172410b8.10bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
172510b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
172610b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
172710b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
172810b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
172910b8.10bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
173010b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
173110b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
173210b8.10bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
173310b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtcorevbox4.dll'...
173410b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtcorevbox4.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qtcorevbox4.dll' [rcNtRedir=0xc0150008]
173510b8.10bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll
173610b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
173710b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
173810b8.10bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
173910b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
174010b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
174110b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
174210b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
174310b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
174410b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
174510b8.10bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
174610b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winspool.drv'...
174710b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'winspool.drv' -> '\Device\HarddiskVolume2\Windows\System32\winspool.drv' [rcNtRedir=0xc0150008]
174810b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004cc pwszName=\Device\HarddiskVolume2\Windows\System32\winspool.drv
174910b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008572b0
175010b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008572b0
175110b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=C89A2ED7B99A056D78CA6BAC9CCAB8B1FF119A14
175210b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\winspool.drv'
175310b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
175410b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
175510b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
175610b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
175710b8.10bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\winspool.drv)WinVerifyTrust
175810b8.10bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\winspool.drv
175910b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
176010b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
176110b8.10bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
176210b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
176310b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume2\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
176410b8.10bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\imm32.dll
176510b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
176610b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
176710b8.10bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
176810b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comdlg32.dll'...
176910b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'comdlg32.dll' -> '\Device\HarddiskVolume2\Windows\System32\comdlg32.dll' [rcNtRedir=0xc0150008]
177010b8.10bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\comdlg32.dll
177110b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
177210b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
177310b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
177410b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
177510b8.10bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
177610b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtcorevbox4.dll'...
177710b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtcorevbox4.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qtcorevbox4.dll' [rcNtRedir=0xc0150008]
177810b8.10bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll
177910b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
178010b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
178110b8.10bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
178210b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
178310b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
178410b8.10bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
178510b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtcorevbox4.dll'...
178610b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtcorevbox4.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qtcorevbox4.dll' [rcNtRedir=0xc0150008]
178710b8.10bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll
178810b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtguivbox4.dll'...
178910b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtguivbox4.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qtguivbox4.dll' [rcNtRedir=0xc0150008]
179010b8.10bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll
179110b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
179210b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
179310b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
179410b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
179510b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
179610b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
179710b8.10bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
179810b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
179910b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
180010b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
180110b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
180210b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
180310b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
180410b8.10bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll
180510b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
180610b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
180710b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
180810b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
180910b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
181010b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
181110b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
181210b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
181310b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
181410b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
181510b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
181610b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
181710b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
181810b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
181910b8.10bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll
182010b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
182110b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
182210b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
182310b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
182410b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
182510b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
182610b8.10bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
182710b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
182810b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
182910b8.10bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
183010b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comctl32.dll'...
183110b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'comctl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\comctl32.dll' [rcNtRedir=0x0]
183210b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004f8 pwszName=\Device\HarddiskVolume2\Windows\System32\comctl32.dll
183310b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008572b0
183410b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008572b0
183510b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=5A2FB6B10717AFC03CD9FE6E8F1337A8EA94BF9B
183610b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB2864058~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\comctl32.dll'
183710b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
183810b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'advapi32.dll'.
183910b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
184010b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
184110b8.10bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\comctl32.dll)WinVerifyTrust
184210b8.10bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\comctl32.dll
184310b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
184410b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
184510b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
184610b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
184710b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
184810b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
184910b8.10bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll
185010b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
185110b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
185210b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
185310b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
185410b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
185510b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
185610b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
185710b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
185810b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
185910b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
186010b8.10bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll
186110b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
186210b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
186310b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
186410b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
186510b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
186610b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
186710b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
186810b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
186910b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
187010b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
187110b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
187210b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
187310b8.10bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
187410b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
187510b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
187610b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dwmapi.dll'...
187710b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'dwmapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\dwmapi.dll' [rcNtRedir=0xc0150008]
187810b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004bc pwszName=\Device\HarddiskVolume2\Windows\System32\dwmapi.dll
187910b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008572b0
188010b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008572b0
188110b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B79EE7B5AD74EF51A849809202E043183A2C727E
188210b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\dwmapi.dll'
188310b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
188410b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
188510b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
188610b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
188710b8.10bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\dwmapi.dll)WinVerifyTrust
188810b8.10bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\dwmapi.dll
188910b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
189010b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
189110b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000500 pwszName=\Device\HarddiskVolume2\Windows\System32\setupapi.dll
189210b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008572b0
189310b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008572b0
189410b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=1499C4FEA6E143F9BEC35B4FFA098917D3A6EBF2
189510b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\setupapi.dll'
189610b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
189710b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'cfgmgr32.dll'.
189810b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcrt.dll'.
189910b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'gdi32.dll'.
190010b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
190110b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'user32.dll'.
190210b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'oleaut32.dll'.
190310b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'devobj.dll'.
190410b8.10bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\setupapi.dll)WinVerifyTrust
190510b8.10bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\setupapi.dll
190610b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
190710b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
190810b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dciman32.dll'...
190910b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'dciman32.dll' -> '\Device\HarddiskVolume2\Windows\System32\dciman32.dll' [rcNtRedir=0xc0150008]
191010b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004f0 pwszName=\Device\HarddiskVolume2\Windows\System32\dciman32.dll
191110b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008572b0
191210b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008572b0
191310b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F097BF0B081F54722F0A01EF1CC13AECA64B12F0
191410b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB2847311~31bf3856ad364e35~amd64~~6.1.1.2.cat'; file='\Device\HarddiskVolume2\Windows\System32\dciman32.dll'
191510b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
191610b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
191710b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'gdi32.dll'.
191810b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
191910b8.10bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\dciman32.dll)WinVerifyTrust
192010b8.10bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\dciman32.dll
192110b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
192210b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
192310b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
192410b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
192510b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
192610b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
192710b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
192810b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
192910b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
193010b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
193110b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'devobj.dll'...
193210b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'devobj.dll' -> '\Device\HarddiskVolume2\Windows\System32\devobj.dll' [rcNtRedir=0xc0150008]
193310b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000050c pwszName=\Device\HarddiskVolume2\Windows\System32\devobj.dll
193410b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008572b0
193510b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008572b0
193610b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B410A095222E69F0ECE7D66E4AC27A7125D2EB5A
193710b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\devobj.dll'
193810b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
193910b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
194010b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'cfgmgr32.dll'.
194110b8.10bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\devobj.dll)WinVerifyTrust
194210b8.10bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\devobj.dll
194310b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
194410b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
194510b8.10bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
194610b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
194710b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
194810b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
194910b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
195010b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
195110b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
195210b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
195310b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
195410b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
195510b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
195610b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000514 pwszName=\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll
195710b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008572b0
195810b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008572b0
195910b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=8F731777EFC4BC982C1E1467FBF29A74CC14D93A
196010b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll'
196110b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
196210b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
196310b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'rpcrt4.dll'.
196410b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
196510b8.10bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll)WinVerifyTrust
196610b8.10bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll
196710b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
196810b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
196910b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
197010b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
197110b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
197210b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
197310b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
197410b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
197510b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
197610b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
197710b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
197810b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
197910b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
198010b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
198110b8.10bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll
198210b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
198310b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
198410b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VirtualBox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000087a420:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
198510b8.10bc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.dll
198610b8.10bc: supR3HardenedDllNotificationCallback: load 000007feef690000 LB 0x00871000 C:\Program Files\Oracle\VirtualBox\VirtualBox.dll [fFlags=0x0]
198710b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.dll
198810b8.10bc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
198910b8.10bc: supR3HardenedDllNotificationCallback: load 000007feef570000 LB 0x0011d000 C:\Windows\system32\OPENGL32.dll [fFlags=0x0]
199010b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
199110b8.10bc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\glu32.dll
199210b8.10bc: supR3HardenedDllNotificationCallback: load 000007feef540000 LB 0x0002d000 C:\Windows\system32\GLU32.dll [fFlags=0x0]
199310b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\glu32.dll
199410b8.10bc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ddraw.dll
199510b8.10bc: supR3HardenedDllNotificationCallback: load 000007feef440000 LB 0x000f1000 C:\Windows\system32\DDRAW.dll [fFlags=0x0]
199610b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ddraw.dll
199710b8.10bc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dciman32.dll
199810b8.10bc: supR3HardenedDllNotificationCallback: load 000007feef430000 LB 0x00008000 C:\Windows\system32\DCIMAN32.dll [fFlags=0x0]
199910b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dciman32.dll
200010b8.10bc: supR3HardenedDllNotificationCallback: load 000007fefd890000 LB 0x001d7000 C:\Windows\system32\SETUPAPI.dll [fFlags=0x0]
200110b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\setupapi.dll
200210b8.10bc: supR3HardenedDllNotificationCallback: load 000007fefd750000 LB 0x00036000 C:\Windows\system32\CFGMGR32.dll [fFlags=0x0]
200310b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll
200410b8.10bc: supR3HardenedDllNotificationCallback: load 000007fefefb0000 LB 0x000d7000 C:\Windows\system32\OLEAUT32.dll [fFlags=0x0]
200510b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
200610b8.10bc: supR3HardenedDllNotificationCallback: load 000007feff5e0000 LB 0x00203000 C:\Windows\system32\ole32.dll [fFlags=0x0]
200710b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
200810b8.10bc: supR3HardenedDllNotificationCallback: load 000007fefd790000 LB 0x0001a000 C:\Windows\system32\DEVOBJ.dll [fFlags=0x0]
200910b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\devobj.dll
201010b8.10bc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dwmapi.dll
201110b8.10bc: supR3HardenedDllNotificationCallback: load 000007fefb7b0000 LB 0x00018000 C:\Windows\system32\dwmapi.dll [fFlags=0x0]
201210b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dwmapi.dll
201310b8.10bc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll
201410b8.10bc: supR3HardenedDllNotificationCallback: load 000000006e6d0000 LB 0x002de000 C:\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll [fFlags=0x0]
201510b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll
201610b8.10bc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll
201710b8.10bc: supR3HardenedDllNotificationCallback: load 000000006dd60000 LB 0x00969000 C:\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll [fFlags=0x0]
201810b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll
201910b8.10bc: supR3HardenedDllNotificationCallback: load 000007feff980000 LB 0x00097000 C:\Windows\system32\COMDLG32.dll [fFlags=0x0]
202010b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\comdlg32.dll
202110b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'advapi32.dll'.
202210b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
202310b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
202410b8.10bc: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18201_none_a4d3b9377117c3df\comctl32.dll)
202510b8.10bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18201_none_a4d3b9377117c3df\comctl32.dll
202610b8.10bc: supR3HardenedDllNotificationCallback: load 000007fef84d0000 LB 0x000a0000 C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18201_none_a4d3b9377117c3df\COMCTL32.dll [fFlags=0x0]
202710b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18201_none_a4d3b9377117c3df\comctl32.dll [avoiding WinVerifyTrust]
202810b8.10bc: supR3HardenedDllNotificationCallback: load 000007fefddb0000 LB 0x00d88000 C:\Windows\system32\SHELL32.dll [fFlags=0x0]
202910b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
203010b8.10bc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
203110b8.10bc: supR3HardenedDllNotificationCallback: load 000007fefac30000 LB 0x0003b000 C:\Windows\system32\WINMM.dll [fFlags=0x0]
203210b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
203310b8.10bc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winspool.drv
203410b8.10bc: supR3HardenedDllNotificationCallback: load 000007fef8350000 LB 0x00071000 C:\Windows\system32\WINSPOOL.DRV [fFlags=0x0]
203510b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winspool.drv
203610b8.10bc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtNetworkVBox4.dll
203710b8.10bc: supR3HardenedDllNotificationCallback: load 0000000070060000 LB 0x00105000 C:\Program Files\Oracle\VirtualBox\QtNetworkVBox4.dll [fFlags=0x0]
203810b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtNetworkVBox4.dll
203910b8.10bc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll
204010b8.10bc: supR3HardenedDllNotificationCallback: load 000000006ff80000 LB 0x000dc000 C:\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll [fFlags=0x0]
204110b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll
204210b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000504 pwszName=\Device\HarddiskVolume2\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18201_none_a4d3b9377117c3df\comctl32.dll
204310b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008572b0
204410b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008572b0
204510b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=5A2FB6B10717AFC03CD9FE6E8F1337A8EA94BF9B
204610b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB2864058~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18201_none_a4d3b9377117c3df\comctl32.dll'
204710b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
204810b8.10bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18201_none_a4d3b9377117c3df\comctl32.dll'
204910b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\imm32.dll
205010b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
205110b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
205210b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
205310b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
205410b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
205510b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
205610b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\imm32.dll (Input=imm32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000087a810:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
205710b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefda80000 'C:\Windows\system32\imm32.dll'
205810b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feef690000 'C:\Program Files\Oracle\VirtualBox\VirtualBox.dll'
205910b8.10bc: SUPR3HardenedMain: Calling TrustedMain (000007feef691ca0)...
206010b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
206110b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\winmm.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000087a420:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
206210b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefac30000 'C:\Windows\system32\winmm.dll'
206310b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cryptbase.dll
206410b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTBASE.dll (Input=CRYPTBASE.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000087a420:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
206510b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd330000 'C:\Windows\system32\CRYPTBASE.dll'
206610b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
206710b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000087a420:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
206810b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefddb0000 'C:\Windows\system32\shell32.dll'
206910b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll
207010b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000087a420:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
207110b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00000000774f0000 'C:\Windows\system32\kernel32.dll'
207210b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000005b8 pwszName=\Device\HarddiskVolume2\Windows\System32\uxtheme.dll
207310b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008572b0
207410b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008572b0
207510b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=936D45CC7026757A151F62882B557DD75D5FCB21
207610b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\uxtheme.dll'
207710b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
207810b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
207910b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
208010b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'gdi32.dll'.
208110b8.10bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\uxtheme.dll)WinVerifyTrust
208210b8.10bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
208310b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
208410b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
208510b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
208610b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
208710b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
208810b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
208910b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000087a420:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
209010b8.10bc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
209110b8.10bc: supR3HardenedDllNotificationCallback: load 000007fefbc10000 LB 0x00056000 C:\Windows\system32\uxtheme.dll [fFlags=0x0]
209210b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
209310b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbc10000 'C:\Windows\system32\uxtheme.dll'
209410b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
209510b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000087a420:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
209610b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbc10000 'C:\Windows\system32\uxtheme.dll'
209710b8.10bc: supR3HardenedMonitor_LdrLoadDll: error opening 'C:\Windows\system32\wintab32.dll': 0 (NtPath=\??\C:\Windows\system32\wintab32.dll; Input=C:\Windows\system32\wintab32.dll; rcNtGetDll=0x0
209810b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wintab32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000087a420:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
209910b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000135 'C:\Windows\system32\wintab32.dll'
210010b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077610000 'C:\Windows\system32\user32.dll'
210110b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
210210b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000087a420:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
210310b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbc10000 'C:\Windows\system32\uxtheme.dll'
210410b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077610000 'C:\Windows\system32\user32.dll'
210510b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff470000 'C:\Windows\system32\advapi32.dll'
210610b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\userenv.dll
210710b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\userenv.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000087a420:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
210810b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd7b0000 'C:\Windows\system32\userenv.dll'
210910b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll
211010b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000087a420:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
211110b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00000000774f0000 'C:\Windows\system32\kernel32.dll'
211210b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000005f0 pwszName=\Device\HarddiskVolume2\Windows\System32\clbcatq.dll
211310b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008572b0
211410b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008572b0
211510b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B01469787CE9D8C6FEE98FB207652B88B8494526
211610b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\clbcatq.dll'
211710b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
211810b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
211910b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'ole32.dll'.
212010b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
212110b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
212210b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
212310b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'rpcrt4.dll'.
212410b8.10bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\clbcatq.dll)WinVerifyTrust
212510b8.10bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\clbcatq.dll
212610b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
212710b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
212810b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
212910b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
213010b8.10bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
213110b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
213210b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
213310b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
213410b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
213510b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
213610b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
213710b8.10bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
213810b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
213910b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
214010b8.10bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
214110b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CLBCatQ.DLL (Input=CLBCatQ.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000087a420:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
214210b8.10bc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\clbcatq.dll
214310b8.10bc: supR3HardenedDllNotificationCallback: load 000007fefdba0000 LB 0x00099000 C:\Windows\system32\CLBCatQ.DLL [fFlags=0x0]
214410b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\clbcatq.dll
214510b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdba0000 'C:\Windows\system32\CLBCatQ.DLL'
214610b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
214710b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ADVAPI32.dll (Input=ADVAPI32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000087ab70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
214810b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff470000 'C:\Windows\system32\ADVAPI32.dll'
214910b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cryptsp.dll
215010b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTSP.dll (Input=CRYPTSP.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000087ab70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
215110b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcca0000 'C:\Windows\system32\CRYPTSP.dll'
215210b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000610 pwszName=\Device\HarddiskVolume2\Windows\System32\RpcRtRemote.dll
215310b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008572b0
215410b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008572b0
215510b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=DFC4A7C7E103D324218E6EF5D219B953746D6EC1
215610b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\RpcRtRemote.dll'
215710b8.10bc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
215810b8.10bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'rpcrt4.dll'.
215910b8.10bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\RpcRtRemote.dll)WinVerifyTrust
216010b8.10bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\RpcRtRemote.dll
216110b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
216210b8.10bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
216310b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\RpcRtRemote.dll (Input=RpcRtRemote.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000087ab70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
216410b8.10bc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\RpcRtRemote.dll
216510b8.10bc: supR3HardenedDllNotificationCallback: load 000007fefd3e0000 LB 0x00014000 C:\Windows\system32\RpcRtRemote.dll [fFlags=0x0]
216610b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\RpcRtRemote.dll
216710b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd3e0000 'C:\Windows\system32\RpcRtRemote.dll'
216810b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdb30000 'C:\Windows\system32\gdi32.dll'
216910b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
217010b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000087af60:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
217110b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefddb0000 'C:\Windows\system32\shell32.dll'
217210b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
217310b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000087af60:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
217410b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefddb0000 'C:\Windows\system32\shell32.dll'
217510b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
217610b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000087af60:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
217710b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefddb0000 'C:\Windows\system32\shell32.dll'
217810b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
217910b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000087af60:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
218010b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefddb0000 'C:\Windows\system32\shell32.dll'
218110b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefddb0000 'C:\Windows\system32\shell32.dll'
218210b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefddb0000 'C:\Windows\system32\shell32.dll'
218310b8.10bc: supR3HardenedMonitor_LdrLoadDll: error opening 'C:\Windows\system32\wintab32.dll': 0 (NtPath=\??\C:\Windows\system32\wintab32.dll; Input=C:\Windows\system32\wintab32.dll; rcNtGetDll=0x0
218410b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wintab32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000087af60:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
218510b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000135 'C:\Windows\system32\wintab32.dll'
218610b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077610000 'C:\Windows\system32\user32.dll'
218710b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
218810b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ole32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000087af60:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
218910b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff5e0000 'C:\Windows\system32\ole32.dll'
219010b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
219110b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ole32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000087b1a0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
219210b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff5e0000 'C:\Windows\system32\ole32.dll'
219310b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msctf.dll
219410b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\MSCTF.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000032e4960:C:\Windows\system32;C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
219510b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff090000 'C:\Windows\system32\MSCTF.dll'
219610b8.10bc: supR3HardenedMonitor_LdrLoadDll: 'C:\Windows\system32\comctl32.dll' -> 'C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18201_none_a4d3b9377117c3df\comctl32.dll' [redir]
219710b8.10bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18201_none_a4d3b9377117c3df\comctl32.dll
219810b8.10bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18201_none_a4d3b9377117c3df\comctl32.dll (Input=C:\Windows\system32\comctl32.dll, rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=000000000087b1a0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
219910b8.10bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef84d0000 'C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18201_none_a4d3b9377117c3df\comctl32.dll'
220010b8.10bc: Terminating the normal way: rcExit=1
22011088.108c: supR3HardNtChildWaitFor[2]: Quitting: ExitCode=0x1 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 277399 ms, the end);
22021080.1084: supR3HardNtChildWaitFor[1]: Quitting: ExitCode=0x1 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 277994 ms, the end);

© 2025 Oracle Support Privacy / Do Not Sell My Info Terms of Use Trademark Policy Automated Access Etiquette