VirtualBox

Ticket #13847: VBoxStartup - 4.3.28.log

File VBoxStartup - 4.3.28.log, 308.3 KB (added by keithf4, 10 years ago)
Line 
11364.1888: Log file opened: 4.3.28r100309 g_hStartupLog=0000000000000010 g_uNtVerCombined=0x63258000
21364.1888: \SystemRoot\System32\ntdll.dll:
31364.1888: CreationTime: 2015-04-15T12:54:24.332363000Z
41364.1888: LastWriteTime: 2015-03-23T21:59:25.551884100Z
51364.1888: ChangeTime: 2015-05-06T14:01:01.710325500Z
61364.1888: FileAttributes: 0x20
71364.1888: Size: 0x1a7540
81364.1888: NT Headers: 0xd8
91364.1888: Timestamp: 0x550f4336
101364.1888: Machine: 0x8664 - amd64
111364.1888: Timestamp: 0x550f4336
121364.1888: Image Version: 6.3
131364.1888: SizeOfImage: 0x1ac000 (1753088)
141364.1888: Resource Dir: 0x148000 LB 0x62450
151364.1888: ProductName: Microsoft® Windows® Operating System
161364.1888: ProductVersion: 6.3.9600.17736
171364.1888: FileVersion: 6.3.9600.17736 (winblue_r9.150322-1500)
181364.1888: FileDescription: NT Layer DLL
191364.1888: \SystemRoot\System32\kernel32.dll:
201364.1888: CreationTime: 2015-03-28T18:43:10.880167300Z
211364.1888: LastWriteTime: 2014-10-29T04:09:24.572407200Z
221364.1888: ChangeTime: 2015-03-30T13:34:43.087928400Z
231364.1888: FileAttributes: 0x20
241364.1888: Size: 0x13fc30
251364.1888: NT Headers: 0xf8
261364.1888: Timestamp: 0x545054ca
271364.1888: Machine: 0x8664 - amd64
281364.1888: Timestamp: 0x545054ca
291364.1888: Image Version: 6.3
301364.1888: SizeOfImage: 0x13e000 (1302528)
311364.1888: Resource Dir: 0x12e000 LB 0x518
321364.1888: ProductName: Microsoft® Windows® Operating System
331364.1888: ProductVersion: 6.3.9600.17415
341364.1888: FileVersion: 6.3.9600.17415 (winblue_r4.141028-1500)
351364.1888: FileDescription: Windows NT BASE API Client DLL
361364.1888: \SystemRoot\System32\KernelBase.dll:
371364.1888: CreationTime: 2015-03-28T18:43:59.209819500Z
381364.1888: LastWriteTime: 2014-10-29T03:55:08.402989600Z
391364.1888: ChangeTime: 2015-03-30T13:33:05.602192500Z
401364.1888: FileAttributes: 0x20
411364.1888: Size: 0x114a90
421364.1888: NT Headers: 0xf0
431364.1888: Timestamp: 0x54505737
441364.1888: Machine: 0x8664 - amd64
451364.1888: Timestamp: 0x54505737
461364.1888: Image Version: 6.3
471364.1888: SizeOfImage: 0x115000 (1134592)
481364.1888: Resource Dir: 0x110000 LB 0x3528
491364.1888: ProductName: Microsoft® Windows® Operating System
501364.1888: ProductVersion: 6.3.9600.17415
511364.1888: FileVersion: 6.3.9600.17415 (winblue_r4.141028-1500)
521364.1888: FileDescription: Windows NT BASE API Client DLL
531364.1888: \SystemRoot\System32\apisetschema.dll:
541364.1888: CreationTime: 2013-08-22T12:13:09.745625900Z
551364.1888: LastWriteTime: 2013-08-22T12:35:12.091034400Z
561364.1888: ChangeTime: 2014-05-10T19:29:38.590798500Z
571364.1888: FileAttributes: 0x20
581364.1888: Size: 0x11360
591364.1888: NT Headers: 0xd0
601364.1888: Timestamp: 0x52160049
611364.1888: Machine: 0x8664 - amd64
621364.1888: Timestamp: 0x52160049
631364.1888: Image Version: 6.3
641364.1888: SizeOfImage: 0x13000 (77824)
651364.1888: Resource Dir: 0x11000 LB 0x3f8
661364.1888: ProductName: Microsoft® Windows® Operating System
671364.1888: ProductVersion: 6.3.9600.16384
681364.1888: FileVersion: 6.3.9600.16384 (winblue_rtm.130821-1623)
691364.1888: FileDescription: ApiSet Schema DLL
701364.1888: NtOpenDirectoryObject failed on \Driver: 0xc0000022
711364.1888: supR3HardenedWinFindAdversaries: 0x0
721364.1888: Calling main()
731364.1888: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
741364.1888: SUPR3HardenedMain: Respawn #1
751364.1888: System32: \Device\HarddiskVolume4\Windows\System32
761364.1888: WinSxS: \Device\HarddiskVolume4\Windows\WinSxS
771364.1888: KnownDllPath: C:\Windows\system32
781364.1888: '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
791364.1888: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe)
801364.1888: supR3HardNtEnableThreadCreation:
811364.1888: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ff8a4e48eb0 pvNtTerminateThread=00007ff8a4ec16f0
821364.1888: supR3HardenedWinDoReSpawn(1): New child dcc.e28 [kernel32].
831364.1888: supR3HardNtChildGatherData: PebBaseAddress=00007ff6d0f1c000 cbPeb=0x388
841364.1888: supR3HardNtPuChFindNtdll: uNtDllParentAddr=00007ff8a4e30000 uNtDllChildAddr=00007ff8a4e30000
851364.1888: supR3HardenedWinSetupChildInit: uLdrInitThunk=00007ff8a4e48eb0
861364.1888: supR3HardenedWinSetupChildInit: Start child.
871364.1888: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
881364.1888: supR3HardNtChildPurify: Startup delay kludge #1/0: 266 ms, 17 sleeps
891364.1888: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
901364.1888: *0000000000000000-ffffffffff85ffff 0x0001/0x0000 0x0000000
911364.1888: *00000000007a0000-000000000077ffff 0x0004/0x0004 0x0020000
921364.1888: *00000000007c0000-00000000007b0fff 0x0002/0x0002 0x0040000
931364.1888: 00000000007cf000-00000000007cdfff 0x0001/0x0000 0x0000000
941364.1888: *00000000007d0000-00000000006d3fff 0x0000/0x0004 0x0020000
951364.1888: 00000000008cc000-00000000008c8fff 0x0104/0x0004 0x0020000
961364.1888: 00000000008cf000-00000000008cdfff 0x0004/0x0004 0x0020000
971364.1888: *00000000008d0000-00000000008cbfff 0x0002/0x0002 0x0040000
981364.1888: 00000000008d4000-00000000008c7fff 0x0001/0x0000 0x0000000
991364.1888: *00000000008e0000-00000000008ddfff 0x0004/0x0004 0x0020000
1001364.1888: 00000000008e2000-ffffffff811e3fff 0x0001/0x0000 0x0000000
1011364.1888: *000000007ffe0000-000000007ffdefff 0x0002/0x0002 0x0020000
1021364.1888: 000000007ffe1000-000000007ffd1fff 0x0000/0x0002 0x0020000
1031364.1888: 000000007fff0000-ffff800a2f0effff 0x0001/0x0000 0x0000000
1041364.1888: *00007ff6d0ef0000-00007ff6d0eccfff 0x0002/0x0002 0x0040000
1051364.1888: 00007ff6d0f13000-00007ff6d0f09fff 0x0001/0x0000 0x0000000
1061364.1888: *00007ff6d0f1c000-00007ff6d0f1afff 0x0004/0x0004 0x0020000
1071364.1888: 00007ff6d0f1d000-00007ff6d0f1bfff 0x0001/0x0000 0x0000000
1081364.1888: *00007ff6d0f1e000-00007ff6d0f1bfff 0x0004/0x0004 0x0020000
1091364.1888: 00007ff6d0f20000-00007ff6d08effff 0x0001/0x0000 0x0000000
1101364.1888: *00007ff6d1550000-00007ff6d1550fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
1111364.1888: 00007ff6d1551000-00007ff6d15d5fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
1121364.1888: 00007ff6d15d6000-00007ff6d15d6fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
1131364.1888: 00007ff6d15d7000-00007ff6d1614fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
1141364.1888: 00007ff6d1615000-00007ff6d1615fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
1151364.1888: 00007ff6d1616000-00007ff6d1616fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
1161364.1888: 00007ff6d1617000-00007ff6d1618fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
1171364.1888: 00007ff6d1619000-00007ff6d1619fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
1181364.1888: 00007ff6d161a000-00007ff6d161afff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
1191364.1888: 00007ff6d161b000-00007ff6d161efff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
1201364.1888: 00007ff6d161f000-00007ff6d1657fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
1211364.1888: 00007ff6d1658000-00007ff4fde7ffff 0x0001/0x0000 0x0000000
1221364.1888: *00007ff8a4e30000-00007ff8a4e30fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
1231364.1888: 00007ff8a4e31000-00007ff8a4f5cfff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
1241364.1888: 00007ff8a4f5d000-00007ff8a4f62fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
1251364.1888: 00007ff8a4f63000-00007ff8a4f6ffff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
1261364.1888: 00007ff8a4f70000-00007ff8a4f70fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
1271364.1888: 00007ff8a4f71000-00007ff8a4f73fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
1281364.1888: 00007ff8a4f74000-00007ff8a4f74fff 0x0010/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
1291364.1888: 00007ff8a4f75000-00007ff8a4fdbfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
1301364.1888: 00007ff8a4fdc000-00007ff149fd7fff 0x0001/0x0000 0x0000000
1311364.1888: *00007ffffffe0000-00007ffffffcffff 0x0001/0x0002 0x0020000
1321364.1888: VirtualBox.exe: timestamp 0x555369a5 (rc=VINF_SUCCESS)
1331364.1888: '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
1341364.1888: '\Device\HarddiskVolume4\Windows\System32\ntdll.dll' has no imports
1351364.1888: supR3HardNtChildPurify: Done after 313 ms and 0 fixes (loop #0).
136dcc.e28: Log file opened: 4.3.28r100309 g_hStartupLog=0000000000000004 g_uNtVerCombined=0x63258000
137dcc.e28: supR3HardenedVmProcessInit: uNtDllAddr=00007ff8a4e30000
138dcc.e28: ntdll.dll: timestamp 0x550f4336 (rc=VINF_SUCCESS)
139dcc.e28: New simple heap: #1 00000000009f0000 LB 0x400000 (for 1753088 allocation)
1401364.1888: supR3HardNtEnableThreadCreation:
141dcc.e28: System32: \Device\HarddiskVolume4\Windows\System32
142dcc.e28: WinSxS: \Device\HarddiskVolume4\Windows\WinSxS
143dcc.e28: KnownDllPath: C:\Windows\system32
144dcc.e28: supR3HardenedVmProcessInit: Opening vboxdrv stub...
145dcc.e28: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
146dcc.e28: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
147dcc.e28: Registered Dll notification callback with NTDLL.
148dcc.e28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\kernel32.dll)
149dcc.e28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\kernel32.dll
150dcc.e28: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\KERNEL32.DLL (Input=KERNEL32.DLL, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000801:<flags> [calling]
151dcc.e28: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
152dcc.e28: supR3HardenedDllNotificationCallback: load 00007ff8a22e0000 LB 0x00115000 C:\Windows\system32\KERNELBASE.dll [fFlags=0x0]
153dcc.e28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\KernelBase.dll)
154dcc.e28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\KernelBase.dll
155dcc.e28: supR3HardenedDllNotificationCallback: load 00007ff8a4b10000 LB 0x0013e000 C:\Windows\system32\KERNEL32.DLL [fFlags=0x0]
156dcc.e28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
157dcc.e28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a4b10000 'C:\Windows\system32\KERNEL32.DLL'
158dcc.e28: supR3HardenedDllNotificationCallback: load 00007ff6d1550000 LB 0x00108000 C:\Program Files\Oracle\VirtualBox\VirtualBox.exe [fFlags=0x0]
159dcc.e28: '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
160dcc.e28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe)
161dcc.e28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
162dcc.e28: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ff8a4e48eb0 pvNtTerminateThread=00007ff8a4ec16f0
1631364.1888: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 62 ms.
164dcc.e28: \SystemRoot\System32\ntdll.dll:
165dcc.e28: CreationTime: 2015-04-15T12:54:24.332363000Z
166dcc.e28: LastWriteTime: 2015-03-23T21:59:25.551884100Z
167dcc.e28: ChangeTime: 2015-05-06T14:01:01.710325500Z
168dcc.e28: FileAttributes: 0x20
169dcc.e28: Size: 0x1a7540
170dcc.e28: NT Headers: 0xd8
171dcc.e28: Timestamp: 0x550f4336
172dcc.e28: Machine: 0x8664 - amd64
173dcc.e28: Timestamp: 0x550f4336
174dcc.e28: Image Version: 6.3
175dcc.e28: SizeOfImage: 0x1ac000 (1753088)
176dcc.e28: Resource Dir: 0x148000 LB 0x62450
177dcc.e28: ProductName: Microsoft® Windows® Operating System
178dcc.e28: ProductVersion: 6.3.9600.17736
179dcc.e28: FileVersion: 6.3.9600.17736 (winblue_r9.150322-1500)
180dcc.e28: FileDescription: NT Layer DLL
181dcc.e28: \SystemRoot\System32\kernel32.dll:
182dcc.e28: CreationTime: 2015-03-28T18:43:10.880167300Z
183dcc.e28: LastWriteTime: 2014-10-29T04:09:24.572407200Z
184dcc.e28: ChangeTime: 2015-03-30T13:34:43.087928400Z
185dcc.e28: FileAttributes: 0x20
186dcc.e28: Size: 0x13fc30
187dcc.e28: NT Headers: 0xf8
188dcc.e28: Timestamp: 0x545054ca
189dcc.e28: Machine: 0x8664 - amd64
190dcc.e28: Timestamp: 0x545054ca
191dcc.e28: Image Version: 6.3
192dcc.e28: SizeOfImage: 0x13e000 (1302528)
193dcc.e28: Resource Dir: 0x12e000 LB 0x518
194dcc.e28: ProductName: Microsoft® Windows® Operating System
195dcc.e28: ProductVersion: 6.3.9600.17415
196dcc.e28: FileVersion: 6.3.9600.17415 (winblue_r4.141028-1500)
197dcc.e28: FileDescription: Windows NT BASE API Client DLL
198dcc.e28: \SystemRoot\System32\KernelBase.dll:
199dcc.e28: CreationTime: 2015-03-28T18:43:59.209819500Z
200dcc.e28: LastWriteTime: 2014-10-29T03:55:08.402989600Z
201dcc.e28: ChangeTime: 2015-03-30T13:33:05.602192500Z
202dcc.e28: FileAttributes: 0x20
203dcc.e28: Size: 0x114a90
204dcc.e28: NT Headers: 0xf0
205dcc.e28: Timestamp: 0x54505737
206dcc.e28: Machine: 0x8664 - amd64
207dcc.e28: Timestamp: 0x54505737
208dcc.e28: Image Version: 6.3
209dcc.e28: SizeOfImage: 0x115000 (1134592)
210dcc.e28: Resource Dir: 0x110000 LB 0x3528
211dcc.e28: ProductName: Microsoft® Windows® Operating System
212dcc.e28: ProductVersion: 6.3.9600.17415
213dcc.e28: FileVersion: 6.3.9600.17415 (winblue_r4.141028-1500)
214dcc.e28: FileDescription: Windows NT BASE API Client DLL
215dcc.e28: \SystemRoot\System32\apisetschema.dll:
216dcc.e28: CreationTime: 2013-08-22T12:13:09.745625900Z
217dcc.e28: LastWriteTime: 2013-08-22T12:35:12.091034400Z
218dcc.e28: ChangeTime: 2014-05-10T19:29:38.590798500Z
219dcc.e28: FileAttributes: 0x20
220dcc.e28: Size: 0x11360
221dcc.e28: NT Headers: 0xd0
222dcc.e28: Timestamp: 0x52160049
223dcc.e28: Machine: 0x8664 - amd64
224dcc.e28: Timestamp: 0x52160049
225dcc.e28: Image Version: 6.3
226dcc.e28: SizeOfImage: 0x13000 (77824)
227dcc.e28: Resource Dir: 0x11000 LB 0x3f8
228dcc.e28: ProductName: Microsoft® Windows® Operating System
229dcc.e28: ProductVersion: 6.3.9600.16384
230dcc.e28: FileVersion: 6.3.9600.16384 (winblue_rtm.130821-1623)
231dcc.e28: FileDescription: ApiSet Schema DLL
232dcc.e28: NtOpenDirectoryObject failed on \Driver: 0xc0000022
233dcc.e28: supR3HardenedWinFindAdversaries: 0x0
234dcc.e28: Calling main()
235dcc.e28: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
236dcc.e28: '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
237dcc.e28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe)
238dcc.e28: SUPR3HardenedMain: Respawn #2
239dcc.e28: supR3HardNtEnableThreadCreation:
240dcc.e28: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ff8a4e48eb0 pvNtTerminateThread=00007ff8a4ec16f0
241dcc.e28: supR3HardenedWinDoReSpawn(2): New child ecc.e58 [kernel32].
242dcc.e28: supR3HardenedWinReSpawn: NtSetInformationThread/ThreadHideFromDebugger failed: 0xc0000022 (harmless)
243dcc.e28: supR3HardNtChildGatherData: PebBaseAddress=00007ff6d0dbf000 cbPeb=0x388
244dcc.e28: supR3HardNtPuChFindNtdll: uNtDllParentAddr=00007ff8a4e30000 uNtDllChildAddr=00007ff8a4e30000
245dcc.e28: supR3HardenedWinSetupChildInit: uLdrInitThunk=00007ff8a4e48eb0
246dcc.e28: supR3HardenedWinSetupChildInit: Start child.
247dcc.e28: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
248dcc.e28: supR3HardNtChildPurify: Startup delay kludge #1/0: 265 ms, 17 sleeps
249dcc.e28: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
250dcc.e28: *0000000000000000-ffffffffff65ffff 0x0001/0x0000 0x0000000
251dcc.e28: *00000000009a0000-000000000097ffff 0x0004/0x0004 0x0020000
252dcc.e28: *00000000009c0000-00000000009b0fff 0x0002/0x0002 0x0040000
253dcc.e28: 00000000009cf000-00000000009cdfff 0x0001/0x0000 0x0000000
254dcc.e28: *00000000009d0000-00000000008d3fff 0x0000/0x0004 0x0020000
255dcc.e28: 0000000000acc000-0000000000ac8fff 0x0104/0x0004 0x0020000
256dcc.e28: 0000000000acf000-0000000000acdfff 0x0004/0x0004 0x0020000
257dcc.e28: *0000000000ad0000-0000000000acbfff 0x0002/0x0002 0x0040000
258dcc.e28: 0000000000ad4000-0000000000ac7fff 0x0001/0x0000 0x0000000
259dcc.e28: *0000000000ae0000-0000000000addfff 0x0004/0x0004 0x0020000
260dcc.e28: 0000000000ae2000-ffffffff815e3fff 0x0001/0x0000 0x0000000
261dcc.e28: *000000007ffe0000-000000007ffdefff 0x0002/0x0002 0x0020000
262dcc.e28: 000000007ffe1000-000000007ffd1fff 0x0000/0x0002 0x0020000
263dcc.e28: 000000007fff0000-ffff800a2f24ffff 0x0001/0x0000 0x0000000
264dcc.e28: *00007ff6d0d90000-00007ff6d0d6cfff 0x0002/0x0002 0x0040000
265dcc.e28: 00007ff6d0db3000-00007ff6d0da8fff 0x0001/0x0000 0x0000000
266dcc.e28: *00007ff6d0dbd000-00007ff6d0dbafff 0x0004/0x0004 0x0020000
267dcc.e28: *00007ff6d0dbf000-00007ff6d0dbdfff 0x0004/0x0004 0x0020000
268dcc.e28: 00007ff6d0dc0000-00007ff6d062ffff 0x0001/0x0000 0x0000000
269dcc.e28: *00007ff6d1550000-00007ff6d1550fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
270dcc.e28: 00007ff6d1551000-00007ff6d15d5fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
271dcc.e28: 00007ff6d15d6000-00007ff6d15d6fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
272dcc.e28: 00007ff6d15d7000-00007ff6d1614fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
273dcc.e28: 00007ff6d1615000-00007ff6d1615fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
274dcc.e28: 00007ff6d1616000-00007ff6d1616fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
275dcc.e28: 00007ff6d1617000-00007ff6d1618fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
276dcc.e28: 00007ff6d1619000-00007ff6d1619fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
277dcc.e28: 00007ff6d161a000-00007ff6d161afff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
278dcc.e28: 00007ff6d161b000-00007ff6d161efff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
279dcc.e28: 00007ff6d161f000-00007ff6d1657fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
280dcc.e28: 00007ff6d1658000-00007ff4fde7ffff 0x0001/0x0000 0x0000000
281dcc.e28: *00007ff8a4e30000-00007ff8a4e30fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
282dcc.e28: 00007ff8a4e31000-00007ff8a4f5cfff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
283dcc.e28: 00007ff8a4f5d000-00007ff8a4f62fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
284dcc.e28: 00007ff8a4f63000-00007ff8a4f6ffff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
285dcc.e28: 00007ff8a4f70000-00007ff8a4f70fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
286dcc.e28: 00007ff8a4f71000-00007ff8a4f73fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
287dcc.e28: 00007ff8a4f74000-00007ff8a4f74fff 0x0010/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
288dcc.e28: 00007ff8a4f75000-00007ff8a4fdbfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
289dcc.e28: 00007ff8a4fdc000-00007ff149fd7fff 0x0001/0x0000 0x0000000
290dcc.e28: *00007ffffffe0000-00007ffffffcffff 0x0001/0x0002 0x0020000
291dcc.e28: VirtualBox.exe: timestamp 0x555369a5 (rc=VINF_SUCCESS)
292dcc.e28: '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
293dcc.e28: '\Device\HarddiskVolume4\Windows\System32\ntdll.dll' has no imports
294dcc.e28: supR3HardNtChildPurify: Done after 312 ms and 0 fixes (loop #0).
295ecc.e58: Log file opened: 4.3.28r100309 g_hStartupLog=0000000000000004 g_uNtVerCombined=0x63258000
296ecc.e58: supR3HardenedVmProcessInit: uNtDllAddr=00007ff8a4e30000
297ecc.e58: ntdll.dll: timestamp 0x550f4336 (rc=VINF_SUCCESS)
298ecc.e58: New simple heap: #1 0000000000bf0000 LB 0x400000 (for 1753088 allocation)
299dcc.e28: supR3HardenedEarlyCompact: Removed heap 1 (0x000000009f0000 LB 0x400000)
300dcc.e28: supR3HardNtEnableThreadCreation:
301ecc.e58: System32: \Device\HarddiskVolume4\Windows\System32
302ecc.e58: WinSxS: \Device\HarddiskVolume4\Windows\WinSxS
303ecc.e58: KnownDllPath: C:\Windows\system32
304ecc.e58: supR3HardenedVmProcessInit: Opening vboxdrv...
305ecc.e58: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
306ecc.e58: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
307ecc.e58: Registered Dll notification callback with NTDLL.
308ecc.e58: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\kernel32.dll)
309ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\kernel32.dll
310ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\KERNEL32.DLL (Input=KERNEL32.DLL, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000801:<flags> [calling]
311ecc.e58: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
312ecc.e58: supR3HardenedDllNotificationCallback: load 00007ff8a22e0000 LB 0x00115000 C:\Windows\system32\KERNELBASE.dll [fFlags=0x0]
313ecc.e58: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\KernelBase.dll)
314ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\KernelBase.dll
315ecc.e58: supR3HardenedDllNotificationCallback: load 00007ff8a4b10000 LB 0x0013e000 C:\Windows\system32\KERNEL32.DLL [fFlags=0x0]
316ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
317ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a4b10000 'C:\Windows\system32\KERNEL32.DLL'
318ecc.e58: supR3HardenedDllNotificationCallback: load 00007ff6d1550000 LB 0x00108000 C:\Program Files\Oracle\VirtualBox\VirtualBox.exe [fFlags=0x0]
319ecc.e58: '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
320ecc.e58: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe)
321ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
322ecc.e58: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ff8a4e48eb0 pvNtTerminateThread=00007ff8a4ec16f0
323dcc.e28: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 63 ms.
324ecc.e58: \SystemRoot\System32\ntdll.dll:
325ecc.e58: CreationTime: 2015-04-15T12:54:24.332363000Z
326ecc.e58: LastWriteTime: 2015-03-23T21:59:25.551884100Z
327ecc.e58: ChangeTime: 2015-05-06T14:01:01.710325500Z
328ecc.e58: FileAttributes: 0x20
329ecc.e58: Size: 0x1a7540
330ecc.e58: NT Headers: 0xd8
331ecc.e58: Timestamp: 0x550f4336
332ecc.e58: Machine: 0x8664 - amd64
333ecc.e58: Timestamp: 0x550f4336
334ecc.e58: Image Version: 6.3
335ecc.e58: SizeOfImage: 0x1ac000 (1753088)
336ecc.e58: Resource Dir: 0x148000 LB 0x62450
337ecc.e58: ProductName: Microsoft® Windows® Operating System
338ecc.e58: ProductVersion: 6.3.9600.17736
339ecc.e58: FileVersion: 6.3.9600.17736 (winblue_r9.150322-1500)
340ecc.e58: FileDescription: NT Layer DLL
341ecc.e58: \SystemRoot\System32\kernel32.dll:
342ecc.e58: CreationTime: 2015-03-28T18:43:10.880167300Z
343ecc.e58: LastWriteTime: 2014-10-29T04:09:24.572407200Z
344ecc.e58: ChangeTime: 2015-03-30T13:34:43.087928400Z
345ecc.e58: FileAttributes: 0x20
346ecc.e58: Size: 0x13fc30
347ecc.e58: NT Headers: 0xf8
348ecc.e58: Timestamp: 0x545054ca
349ecc.e58: Machine: 0x8664 - amd64
350ecc.e58: Timestamp: 0x545054ca
351ecc.e58: Image Version: 6.3
352ecc.e58: SizeOfImage: 0x13e000 (1302528)
353ecc.e58: Resource Dir: 0x12e000 LB 0x518
354ecc.e58: ProductName: Microsoft® Windows® Operating System
355ecc.e58: ProductVersion: 6.3.9600.17415
356ecc.e58: FileVersion: 6.3.9600.17415 (winblue_r4.141028-1500)
357ecc.e58: FileDescription: Windows NT BASE API Client DLL
358ecc.e58: \SystemRoot\System32\KernelBase.dll:
359ecc.e58: CreationTime: 2015-03-28T18:43:59.209819500Z
360ecc.e58: LastWriteTime: 2014-10-29T03:55:08.402989600Z
361ecc.e58: ChangeTime: 2015-03-30T13:33:05.602192500Z
362ecc.e58: FileAttributes: 0x20
363ecc.e58: Size: 0x114a90
364ecc.e58: NT Headers: 0xf0
365ecc.e58: Timestamp: 0x54505737
366ecc.e58: Machine: 0x8664 - amd64
367ecc.e58: Timestamp: 0x54505737
368ecc.e58: Image Version: 6.3
369ecc.e58: SizeOfImage: 0x115000 (1134592)
370ecc.e58: Resource Dir: 0x110000 LB 0x3528
371ecc.e58: ProductName: Microsoft® Windows® Operating System
372ecc.e58: ProductVersion: 6.3.9600.17415
373ecc.e58: FileVersion: 6.3.9600.17415 (winblue_r4.141028-1500)
374ecc.e58: FileDescription: Windows NT BASE API Client DLL
375ecc.e58: \SystemRoot\System32\apisetschema.dll:
376ecc.e58: CreationTime: 2013-08-22T12:13:09.745625900Z
377ecc.e58: LastWriteTime: 2013-08-22T12:35:12.091034400Z
378ecc.e58: ChangeTime: 2014-05-10T19:29:38.590798500Z
379ecc.e58: FileAttributes: 0x20
380ecc.e58: Size: 0x11360
381ecc.e58: NT Headers: 0xd0
382ecc.e58: Timestamp: 0x52160049
383ecc.e58: Machine: 0x8664 - amd64
384ecc.e58: Timestamp: 0x52160049
385ecc.e58: Image Version: 6.3
386ecc.e58: SizeOfImage: 0x13000 (77824)
387ecc.e58: Resource Dir: 0x11000 LB 0x3f8
388ecc.e58: ProductName: Microsoft® Windows® Operating System
389ecc.e58: ProductVersion: 6.3.9600.16384
390ecc.e58: FileVersion: 6.3.9600.16384 (winblue_rtm.130821-1623)
391ecc.e58: FileDescription: ApiSet Schema DLL
392ecc.e58: NtOpenDirectoryObject failed on \Driver: 0xc0000022
393ecc.e58: supR3HardenedWinFindAdversaries: 0x0
394ecc.e58: Calling main()
395ecc.e58: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
396ecc.e58: '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
397ecc.e58: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe)
398ecc.e58: SUPR3HardenedMain: Final process, opening VBoxDrv...
399ecc.e58: supR3HardenedEarlyCompact: Removed heap 1 (0x00000000bf0000 LB 0x400000)
400ecc.e58: supR3HardNtEnableThreadCreation:
401ecc.e58: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSupLib.dll)
402ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSupLib.dll
403ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
404ecc.e58: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
405ecc.e58: supR3HardenedDllNotificationCallback: load 00007ff8969d0000 LB 0x00005000 C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL [fFlags=0x0]
406ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
407ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
408ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
409ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8969d0000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
410ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
411ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
412ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8969d0000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
413ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8969d0000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
414ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
415ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'crypt32.dll'.
416ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #19 'msasn1.dll'.
417ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #22 'rpcrt4.dll'.
418ecc.e58: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\wintrust.dll)
419ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\wintrust.dll
420ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
421ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
422ecc.e58: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll)
423ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll
424ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
425ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume4\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
426ecc.e58: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\msasn1.dll)
427ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\msasn1.dll
428ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
429ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume4\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
430ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
431ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #28 'msasn1.dll'.
432ecc.e58: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\crypt32.dll)
433ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\crypt32.dll
434ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
435ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
436ecc.e58: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\msvcrt.dll)
437ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\msvcrt.dll
438ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
439ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume4\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
440ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
441ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
442ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
443ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
444ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
445ecc.e58: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
446ecc.e58: supR3HardenedDllNotificationCallback: load 00007ff8a28b0000 LB 0x000aa000 C:\Windows\system32\msvcrt.dll [fFlags=0x0]
447ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
448ecc.e58: supR3HardenedDllNotificationCallback: load 00007ff8a2030000 LB 0x00011000 C:\Windows\system32\MSASN1.dll [fFlags=0x0]
449ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
450ecc.e58: supR3HardenedDllNotificationCallback: load 00007ff8a2100000 LB 0x001df000 C:\Windows\system32\CRYPT32.dll [fFlags=0x0]
451ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
452ecc.e58: supR3HardenedDllNotificationCallback: load 00007ff8a2b80000 LB 0x00141000 C:\Windows\system32\RPCRT4.dll [fFlags=0x0]
453ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
454ecc.e58: supR3HardenedDllNotificationCallback: load 00007ff8a2400000 LB 0x00051000 C:\Windows\system32\Wintrust.dll [fFlags=0x0]
455ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
456ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2400000 'C:\Windows\system32\Wintrust.dll'
457ecc.e58: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\bcrypt.dll)
458ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\bcrypt.dll
459ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcrypt.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
460ecc.e58: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
461ecc.e58: supR3HardenedDllNotificationCallback: load 00007ff8a1aa0000 LB 0x00026000 C:\Windows\system32\bcrypt.dll [fFlags=0x0]
462ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
463ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1aa0000 'C:\Windows\system32\bcrypt.dll'
464ecc.e58: bcrypt.dll loaded at 00007ff8a1aa0000, BCryptOpenAlgorithmProvider at 00007ff8a1aa34a0, preloading providers:
465ecc.e58: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\bcryptprimitives.dll)
466ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\bcryptprimitives.dll
467ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcryptprimitives.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
468ecc.e58: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
469ecc.e58: supR3HardenedDllNotificationCallback: load 00007ff8a1de0000 LB 0x00063000 C:\Windows\system32\bcryptprimitives.dll [fFlags=0x0]
470ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
471ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1de0000 'C:\Windows\system32\bcryptprimitives.dll'
472ecc.e58: BCryptOpenAlgorithmProvider(,'MD2',0,0) -> 0x0 (hAlgo=00000000010f90e0)
473ecc.e58: BCryptOpenAlgorithmProvider(,'MD4',0,0) -> 0x0 (hAlgo=00000000010f94d0)
474ecc.e58: BCryptOpenAlgorithmProvider(,'MD5',0,0) -> 0x0 (hAlgo=00000000010f95f0)
475ecc.e58: BCryptOpenAlgorithmProvider(,'SHA1',0,0) -> 0x0 (hAlgo=00000000010f9840)
476ecc.e58: BCryptOpenAlgorithmProvider(,'SHA256',0,0) -> 0x0 (hAlgo=00000000010f9960)
477ecc.e58: BCryptOpenAlgorithmProvider(,'SHA512',0,0) -> 0x0 (hAlgo=00000000010fa3d0)
478ecc.e58: BCryptOpenAlgorithmProvider(,'RSA',0,0) -> 0x0 (hAlgo=00000000010fa2b0)
479ecc.e58: BCryptOpenAlgorithmProvider(,'DSA',0,0) -> 0x0 (hAlgo=00000000010f9e30)
480ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
481ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
482ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2400000 'C:\Windows\System32\WINTRUST.DLL'
483ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
484ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
485ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2400000 'C:\Windows\System32\WINTRUST.DLL'
486ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
487ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
488ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2400000 'C:\Windows\System32\WINTRUST.DLL'
489ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
490ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
491ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2400000 'C:\Windows\System32\WINTRUST.DLL'
492ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
493ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
494ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2400000 'C:\Windows\System32\WINTRUST.DLL'
495ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
496ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
497ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2400000 'C:\Windows\System32\WINTRUST.DLL'
498ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
499ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2400000 'C:\Windows\System32\WINTRUST.DLL'
500ecc.e58: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\cryptsp.dll)
501ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\cryptsp.dll
502ecc.e58: supR3HardenedDllNotificationCallback: load 00007ff8a17f0000 LB 0x00020000 C:\Windows\SYSTEM32\CRYPTSP.dll [fFlags=0x0]
503ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
504ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'bcrypt.dll'.
505ecc.e58: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\rsaenh.dll)
506ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\rsaenh.dll
507ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
508ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume4\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
509ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
510ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
511ecc.e58: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
512ecc.e58: supR3HardenedDllNotificationCallback: load 00007ff8a1410000 LB 0x00036000 C:\Windows\system32\rsaenh.dll [fFlags=0x0]
513ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
514ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
515ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'bcryptprimitives.dll'.
516ecc.e58: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\cryptbase.dll)
517ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\cryptbase.dll
518ecc.e58: supR3HardenedDllNotificationCallback: load 00007ff8a1e50000 LB 0x0000b000 C:\Windows\SYSTEM32\CRYPTBASE.dll [fFlags=0x0]
519ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\cryptbase.dll [lacks WinVerifyTrust]
520ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
521ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcryptprimitives.dll'...
522ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcryptprimitives.dll' -> '\Device\HarddiskVolume4\Windows\System32\bcryptprimitives.dll' [rcNtRedir=0xc0150008]
523ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
524ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
525ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a4b10000 'C:\Windows\system32\kernel32.dll'
526ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
527ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2400000 'C:\Windows\System32\WINTRUST.DLL'
528ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
529ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPT32.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
530ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\CRYPT32.dll'
531ecc.e58: supR3HardenedDllNotificationCallback: load 00007ff8a4ae0000 LB 0x00016000 C:\Windows\system32\imagehlp.dll [fFlags=0x0]
532ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
533ecc.e58: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\imagehlp.dll)
534ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\imagehlp.dll
535ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
536ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
537ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
538ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
539ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
540ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
541ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'bcrypt.dll'.
542ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'ntasn1.dll'.
543ecc.e58: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\ncrypt.dll)
544ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\ncrypt.dll
545ecc.e58: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\ntasn1.dll)
546ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\ntasn1.dll
547ecc.e58: supR3HardenedDllNotificationCallback: load 00007ff8a1a30000 LB 0x00037000 C:\Windows\SYSTEM32\NTASN1.dll [fFlags=0x0]
548ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ntasn1.dll [lacks WinVerifyTrust]
549ecc.e58: supR3HardenedDllNotificationCallback: load 00007ff8a1a70000 LB 0x00025000 C:\Windows\SYSTEM32\ncrypt.dll [fFlags=0x0]
550ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ncrypt.dll [lacks WinVerifyTrust]
551ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'rpcrt4.dll'.
552ecc.e58: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\sechost.dll)
553ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\sechost.dll
554ecc.e58: supR3HardenedDllNotificationCallback: load 00007ff8a34a0000 LB 0x00059000 C:\Windows\SYSTEM32\sechost.dll [fFlags=0x0]
555ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\sechost.dll [lacks WinVerifyTrust]
556ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
557ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'rpcrt4.dll'.
558ecc.e58: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\gpapi.dll)
559ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\gpapi.dll
560ecc.e58: supR3HardenedDllNotificationCallback: load 00007ff8a1110000 LB 0x00024000 C:\Windows\SYSTEM32\gpapi.dll [fFlags=0x0]
561ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gpapi.dll [lacks WinVerifyTrust]
562ecc.e58: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\profapi.dll)
563ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\profapi.dll
564ecc.e58: supR3HardenedDllNotificationCallback: load 00007ff8a1f80000 LB 0x00015000 C:\Windows\SYSTEM32\profapi.dll [fFlags=0x0]
565ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\profapi.dll [lacks WinVerifyTrust]
566ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
567ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'crypt32.dll'.
568ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'wldap32.dll'.
569ecc.e58: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\System32\cryptnet.dll)
570ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\cryptnet.dll
571ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wldap32.dll'...
572ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'wldap32.dll' -> '\Device\HarddiskVolume4\Windows\System32\wldap32.dll' [rcNtRedir=0xc0150008]
573ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
574ecc.e58: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\System32\Wldap32.dll)
575ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\Wldap32.dll
576ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
577ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume4\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
578ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
579ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
580ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
581ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
582ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
583ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
584ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
585ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
586ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
587ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
588ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
589ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
590ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
591ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntasn1.dll'...
592ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntasn1.dll' -> '\Device\HarddiskVolume4\Windows\System32\ntasn1.dll' [rcNtRedir=0xc0150008]
593ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ntasn1.dll [lacks WinVerifyTrust]
594ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
595ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume4\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
596ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
597ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
598ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
599ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
600ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (Input=cryptnet.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
601ecc.e58: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
602ecc.e58: supR3HardenedDllNotificationCallback: load 00007ff8a3440000 LB 0x0005c000 C:\Windows\system32\WLDAP32.dll [fFlags=0x0]
603ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\Wldap32.dll [lacks WinVerifyTrust]
604ecc.e58: supR3HardenedDllNotificationCallback: load 00007ff888620000 LB 0x00039000 C:\Windows\system32\cryptnet.dll [fFlags=0x0]
605ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
606ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
607ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
608ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff888620000 'C:\Windows\system32\cryptnet.dll'
609ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
610ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
611ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff888620000 'C:\Windows\system32\cryptnet.dll'
612ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
613ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
614ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff888620000 'C:\Windows\system32\cryptnet.dll'
615ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
616ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
617ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff888620000 'C:\Windows\system32\cryptnet.dll'
618ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
619ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
620ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff888620000 'C:\Windows\system32\cryptnet.dll'
621ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
622ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
623ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff888620000 'C:\Windows\system32\cryptnet.dll'
624ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
625ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff888620000 'C:\Windows\system32\cryptnet.dll'
626ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
627ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff888620000 'C:\Windows\system32\cryptnet.dll'
628ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
629ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff888620000 'C:\Windows\system32\cryptnet.dll'
630ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
631ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff888620000 'C:\Windows\system32\cryptnet.dll'
632ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
633ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff888620000 'C:\Windows\system32\cryptnet.dll'
634ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff888620000 'C:\Windows\system32\cryptnet.dll'
635ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
636ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff888620000 'C:\Windows\System32\cryptnet.dll'
637ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
638ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'sechost.dll'.
639ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'rpcrt4.dll'.
640ecc.e58: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\advapi32.dll)
641ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\advapi32.dll
642ecc.e58: supR3HardenedDllNotificationCallback: load 00007ff8a3390000 LB 0x000aa000 C:\Windows\SYSTEM32\advapi32.dll [fFlags=0x0]
643ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
644ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
645ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
646ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
647ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
648ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'sechost.dll'...
649ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'sechost.dll' -> '\Device\HarddiskVolume4\Windows\System32\sechost.dll' [rcNtRedir=0xc0150008]
650ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\sechost.dll [lacks WinVerifyTrust]
651ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
652ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
653ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
654ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
655ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
656ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
657ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
658ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
659ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000000 pwszName=\SystemRoot\System32\ntdll.dll
660ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: New context 000000000112a710
661ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000112a710
662ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=0C388B9F1A03B08C9E0419963B4B8BEF1136190E
663ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
664ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rpcrt4.dll (Input=rpcrt4.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
665ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2b80000 'C:\Windows\system32\rpcrt4.dll'
666ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
667ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2400000 'C:\Windows\System32\WINTRUST.DLL'
668ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
669ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2400000 'C:\Windows\System32\WINTRUST.DLL'
670ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
671ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2400000 'C:\Windows\System32\WINTRUST.DLL'
672ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
673ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2400000 'C:\Windows\System32\WINTRUST.DLL'
674ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
675ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2400000 'C:\Windows\System32\WINTRUST.DLL'
676ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
677ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
678ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2400000 'C:\Windows\System32\WINTRUST.DLL'
679ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
680ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2400000 'C:\Windows\System32\WINTRUST.DLL'
681ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
682ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
683ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
684ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
685ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
686ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
687ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_31_for_KB3045999~31bf3856ad364e35~amd64~~6.3.1.3.cat'; file='\SystemRoot\System32\ntdll.dll'
688ecc.e58: g_pfnWinVerifyTrust=00007ff8a2401050
689ecc.e58: supR3HardenedScreenImage/preload: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll [redoing WinVerifyTrust]
690ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
691ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
692ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
693ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
694ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
695ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
696ecc.e58: supR3HardenedScreenImage/preload: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\crypt32.dll'
697ecc.e58: supR3HardenedScreenImage/preload: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [redoing WinVerifyTrust]
698ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
699ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
700ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
701ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll
702ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
703ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
704ecc.e58: supR3HardenedScreenImage/preload: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\wintrust.dll'
705ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
706ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
707ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
708ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
709ecc.e58: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\advapi32.dll'
710ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000378 pwszName=\Device\HarddiskVolume4\Windows\System32\Wldap32.dll
711ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000112a710
712ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000112a710
713ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=BBC3979054487C3D01C936AC44608445F3BDB24A
714ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
715ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
716ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
717ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_1991_for_KB3000850~31bf3856ad364e35~amd64~~6.3.1.8.cat'; file='\Device\HarddiskVolume4\Windows\System32\Wldap32.dll'
718ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
719ecc.e58: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\Wldap32.dll'
720ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000374 pwszName=\Device\HarddiskVolume4\Windows\System32\cryptnet.dll
721ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000112a710
722ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000112a710
723ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=CFA081F787F20E906CEFF5631F4EC1F5B874BBA5
724ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
725ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
726ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
727ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_1991_for_KB3000850~31bf3856ad364e35~amd64~~6.3.1.8.cat'; file='\Device\HarddiskVolume4\Windows\System32\cryptnet.dll'
728ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
729ecc.e58: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\cryptnet.dll'
730ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
731ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
732ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
733ecc.e58: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\profapi.dll'
734ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
735ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
736ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
737ecc.e58: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\gpapi.dll'
738ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
739ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
740ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
741ecc.e58: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\sechost.dll'
742ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
743ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
744ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
745ecc.e58: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\ntasn1.dll'
746ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
747ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
748ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll
749ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
750ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
751ecc.e58: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\ncrypt.dll'
752ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
753ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
754ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
755ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
756ecc.e58: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\imagehlp.dll'
757ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
758ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
759ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
760ecc.e58: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\cryptbase.dll'
761ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
762ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
763ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
764ecc.e58: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\rsaenh.dll'
765ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
766ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
767ecc.e58: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\cryptsp.dll'
768ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
769ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
770ecc.e58: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\bcryptprimitives.dll'
771ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
772ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
773ecc.e58: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\bcrypt.dll'
774ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
775ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
776ecc.e58: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll'
777ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
778ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
779ecc.e58: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\msasn1.dll'
780ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
781ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
782ecc.e58: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll'
783ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
784ecc.e58: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSupLib.dll'
785ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
786ecc.e58: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe'
787ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
788ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
789ecc.e58: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\KernelBase.dll'
790ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
791ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
792ecc.e58: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\kernel32.dll'
793ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
794ecc.e58: supR3HardenedWinIsDesiredRootCA: Adding 0xf4050763db1ec800 CN=keith-laptop
795ecc.e58: supR3HardenedWinIsDesiredRootCA: Adding 0x5ad46780fa5df300 DC=com, DC=microsoft, CN=Microsoft Root Certificate Authority
796ecc.e58: supR3HardenedWinIsDesiredRootCA: Adding 0xea5386456178582b C=ZA, ST=Western Cape, L=Durbanville, O=Thawte, OU=Thawte Certification, CN=Thawte Timestamping CA
797ecc.e58: supR3HardenedWinIsDesiredRootCA: Adding 0x3be670c1bd02a900 OU=Copyright (c) 1997 Microsoft Corp., OU=Microsoft Corporation, CN=Microsoft Root Authority
798ecc.e58: supR3HardenedWinIsDesiredRootCA: Adding 0x4d3835aa4180b200 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2011
799ecc.e58: supR3HardenedWinIsDesiredRootCA: Adding 0x646e3fe3ba08df00 C=US, O=MSFT, CN=Microsoft Authenticode(tm) Root Authority
800ecc.e58: supR3HardenedWinIsDesiredRootCA: Adding 0xece4e4289e08b900 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010
801ecc.e58: supR3HardenedWinIsDesiredRootCA: Adding 0x43a9cc371ff5385a O=Microsoft Trust Network, OU=Microsoft Corporation, OU=Microsoft Time Stamping Service Root, OU=Copyright (c) 1997 Microsoft Corp.
802ecc.e58: supR3HardenedWinIsDesiredRootCA: Adding 0x2e2d2c7c68f0202e O=VeriSign Trust Network, OU=VeriSign, Inc., OU=VeriSign Time Stamping Service Root, OU=NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.
803ecc.e58: supR3HardenedWinIsDesiredRootCA: Adding 0xd8dbfb2c27bfb200 C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2008 thawte, Inc. - For authorized use only, CN=thawte Primary Root CA - G3
804ecc.e58: supR3HardenedWinIsDesiredRootCA: Adding 0x61a3a33f81aace00 C=US, ST=UT, L=Salt Lake City, O=The USERTRUST Network, OU=http://www.usertrust.com, CN=UTN-USERFirst-Object
805ecc.e58: supR3HardenedWinIsDesiredRootCA: Adding 0xf4fd306318ccda00 C=US, O=GeoTrust Inc., CN=GeoTrust Global CA
806ecc.e58: supR3HardenedWinIsDesiredRootCA: Adding 0x780679907625cc00 OU=GlobalSign Root CA - R3, O=GlobalSign, CN=GlobalSign
807ecc.e58: supR3HardenedWinIsDesiredRootCA: Adding 0x3d98ab22bb04a300 C=IE, O=Baltimore, OU=CyberTrust, CN=Baltimore CyberTrust Root
808ecc.e58: supR3HardenedWinIsDesiredRootCA: Adding 0xa0ee62086758b15d C=US, O=Equifax, OU=Equifax Secure Certificate Authority
809ecc.e58: supR3HardenedWinIsDesiredRootCA: Adding 0x8ff6fc03c1edbd00 C=US, ST=Arizona, L=Scottsdale, O=Starfield Technologies, Inc., CN=Starfield Root Certificate Authority - G2
810ecc.e58: supR3HardenedWinIsDesiredRootCA: Adding 0xa3ce8d99e60eda00 C=BE, O=GlobalSign nv-sa, OU=Root CA, CN=GlobalSign Root CA
811ecc.e58: supR3HardenedWinIsDesiredRootCA: Adding 0xa671e9fec832b700 C=US, O=Starfield Technologies, Inc., OU=Starfield Class 2 Certification Authority
812ecc.e58: supR3HardenedWinIsDesiredRootCA: Adding 0xa8de7211e13be200 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root CA
813ecc.e58: supR3HardenedWinIsDesiredRootCA: Adding 0xff3891b54348328 C=US, O=Entrust.net, OU=www.entrust.net/CPS incorp. by ref. (limits liab.), OU=(c) 1999 Entrust.net Limited, CN=Entrust.net Secure Server Certification Authority
814ecc.e58: supR3HardenedWinIsDesiredRootCA: Adding 0x7ae89c50f0b6a00f C=US, O=GTE Corporation, OU=GTE CyberTrust Solutions, Inc., CN=GTE CyberTrust Global Root
815ecc.e58: supR3HardenedWinIsDesiredRootCA: Adding 0xd45980fbf0a0ac00 C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2006 thawte, Inc. - For authorized use only, CN=thawte Primary Root CA
816ecc.e58: supR3HardenedWinIsDesiredRootCA: Adding 0xf5cd95e581a4ab00 C=US, O=SecureTrust Corporation, CN=SecureTrust CA
817ecc.e58: supR3HardenedWinIsDesiredRootCA: Adding 0x14018a1bf29e595c C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority
818ecc.e58: supR3HardenedWinIsDesiredRootCA: Adding 0x35f812d09650dc00 C=FR, O=Certplus, CN=Class 2 Primary CA
819ecc.e58: supR3HardenedWinIsDesiredRootCA: Adding 0x9e5bc2d78b6a3636 C=ZA, ST=Western Cape, L=Cape Town, O=Thawte Consulting cc, OU=Certification Services Division, CN=Thawte Premium Server CA, [email protected]
820ecc.e58: supR3HardenedWinIsDesiredRootCA: Adding 0x7c4fd32ec1b1ce00 C=PL, O=Unizeto Sp. z o.o., CN=Certum CA
821ecc.e58: supR3HardenedWinIsDesiredRootCA: Adding 0xd4fbe673e5ccc600 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA
822ecc.e58: supR3HardenedWinIsDesiredRootCA: Adding 0x6e2ba21058eedf00 C=US, ST=UT, L=Salt Lake City, O=The USERTRUST Network, OU=http://www.usertrust.com, CN=UTN - DATACorp SGC
823ecc.e58: supR3HardenedWinIsDesiredRootCA: Adding 0xb28612a94b4dad00 O=Entrust.net, OU=www.entrust.net/CPS_2048 incorp. by ref. (limits liab.), OU=(c) 1999 Entrust.net Limited, CN=Entrust.net Certification Authority (2048)
824ecc.e58: supR3HardenedWinIsDesiredRootCA: Adding 0x357a29080824af00 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2006 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G5
825ecc.e58: supR3HardenedWinIsDesiredRootCA: Adding 0x59faf1086271bf00 C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com, Inc., CN=Go Daddy Root Certificate Authority - G2
826ecc.e58: supR3HardenedWinIsDesiredRootCA: Adding 0x466cbc09db88c100 C=IL, O=StartCom Ltd., OU=Secure Digital Certificate Signing, CN=StartCom Certification Authority
827ecc.e58: supR3HardenedWinIsDesiredRootCA: Adding 0x491857ead79dde00 C=US, O=The Go Daddy Group, Inc., OU=Go Daddy Class 2 Certification Authority
828ecc.e58: supR3HardenedWinIsDesiredRootCA: Adding 0x8043e4ce150ead00 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID Root CA
829ecc.e58: supR3HardenedWinIsDesiredRootCA: Adding 0xa8b43f38c3f7b100 C=US, ST=UT, L=Salt Lake City, O=The USERTRUST Network, OU=http://www.usertrust.com, CN=UTN-USERFirst-Hardware
830ecc.e58: supR3HardenedWinIsDesiredRootCA: Adding 0xf2e6331af7b700 C=SE, O=AddTrust AB, OU=AddTrust External TTP Network, CN=AddTrust External CA Root
831ecc.e58: supR3HardenedWinRetrieveTrustedRootCAs: cAdded=37
832ecc.e58: SUPR3HardenedMain: Load Runtime...
833ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
834ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
835ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
836ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ws2_32.dll'.
837ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'rpcrt4.dll'.
838ecc.e58: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll)WinVerifyTrust
839ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
840ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
841ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
842ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll
843ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
844ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
845ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
846ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
847ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #22 'nsi.dll'.
848ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #24 'rpcrt4.dll'.
849ecc.e58: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\ws2_32.dll)WinVerifyTrust
850ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\ws2_32.dll
851ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
852ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
853ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
854ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
855ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll
856ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
857ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume4\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
858ecc.e58: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\nsi.dll'.
859ecc.e58: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\nsi.dll)
860ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\nsi.dll
861ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
862ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
863ecc.e58: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll)WinVerifyTrust
864ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll
865ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
866ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
867ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll
868ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
869ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
870ecc.e58: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll'.
871ecc.e58: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll)
872ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll
873ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
874ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
875ecc.e58: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll)WinVerifyTrust
876ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000a01:<flags> [calling]
877ecc.e58: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
878ecc.e58: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll [avoiding WinVerifyTrust]
879ecc.e58: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll
880ecc.e58: supR3HardenedDllNotificationCallback: load 000000006b810000 LB 0x000d2000 C:\Program Files\Oracle\VirtualBox\MSVCR100.dll [fFlags=0x0]
881ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll [avoiding WinVerifyTrust]
882ecc.e58: supR3HardenedDllNotificationCallback: load 000000006b770000 LB 0x00098000 C:\Program Files\Oracle\VirtualBox\MSVCP100.dll [fFlags=0x0]
883ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll
884ecc.e58: supR3HardenedDllNotificationCallback: load 00007ff8a2570000 LB 0x00009000 C:\Windows\system32\NSI.dll [fFlags=0x0]
885ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\nsi.dll [avoiding WinVerifyTrust]
886ecc.e58: supR3HardenedDllNotificationCallback: load 00007ff8a3560000 LB 0x0005a000 C:\Windows\system32\WS2_32.dll [fFlags=0x0]
887ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ws2_32.dll
888ecc.e58: supR3HardenedDllNotificationCallback: load 00007ff87be00000 LB 0x00538000 C:\Program Files\Oracle\VirtualBox\VBoxRT.dll [fFlags=0x0]
889ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
890ecc.e58: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll'.
891ecc.e58: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
892ecc.e58: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\nsi.dll'.
893ecc.e58: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\nsi.dll' [rescheduled]
894ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
895ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
896ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff87be00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
897ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
898ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
899ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff87be00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
900ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
901ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
902ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff87be00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
903ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
904ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
905ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff87be00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
906ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
907ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
908ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff87be00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
909ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
910ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
911ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff87be00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
912ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff87be00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
913ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff87be00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
914ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff87be00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
915ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff87be00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
916ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff87be00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
917ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff87be00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
918ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff87be00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
919ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
920ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
921ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff87be00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
922ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff87be00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
923ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff87be00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
924ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff87be00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
925ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff87be00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
926ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff87be00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
927ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff87be00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
928ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff87be00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
929ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff87be00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
930ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff87be00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
931ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff87be00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
932ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff87be00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
933ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff87be00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
934ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff87be00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
935ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff87be00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
936ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff87be00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
937ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
938ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
939ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff87be00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
940ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff87be00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
941ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff87be00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
942ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff87be00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
943ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2400000 'C:\Windows\system32\Wintrust.dll'
944ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
945ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
946ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
947ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
948ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll
949ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\crypt32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
950ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
951ecc.e58: SUPR3HardenedMain: Load TrustedMain...
952ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
953ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'opengl32.dll'.
954ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
955ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcp100.dll'.
956ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcr100.dll'.
957ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qtcorevbox4.dll'.
958ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'qtguivbox4.dll'.
959ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'qtnetworkvbox4.dll'.
960ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'qtopenglvbox4.dll'.
961ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'user32.dll'.
962ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'gdi32.dll'.
963ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'advapi32.dll'.
964ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'shell32.dll'.
965ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'ole32.dll'.
966ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'oleaut32.dll'.
967ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #15 'comdlg32.dll'.
968ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'winmm.dll'.
969ecc.e58: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.dll)WinVerifyTrust
970ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.dll
971ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
972ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume4\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
973ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
974ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
975ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'winmmbase.dll'.
976ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcrt.dll'.
977ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'user32.dll'.
978ecc.e58: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\winmm.dll)WinVerifyTrust
979ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\winmm.dll
980ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comdlg32.dll'...
981ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'comdlg32.dll' -> '\Device\HarddiskVolume4\Windows\System32\comdlg32.dll' [rcNtRedir=0xc0150008]
982ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000454 pwszName=\Device\HarddiskVolume4\Windows\System32\comdlg32.dll
983ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000112a710
984ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000112a710
985ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=A8D428FD3A844AF383E2EA2C23013320CECD6296
986ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
987ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
988ecc.e58: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\user32.dll'.
989ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #29 'gdi32.dll'.
990ecc.e58: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\user32.dll)
991ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\user32.dll
992ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
993ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
994ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll
995ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmmbase.dll'...
996ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmmbase.dll' -> '\Device\HarddiskVolume4\Windows\System32\winmmbase.dll' [rcNtRedir=0xc0150008]
997ecc.e58: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\winmmbase.dll'.
998ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
999ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #22 'devobj.dll'.
1000ecc.e58: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\winmmbase.dll)
1001ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\winmmbase.dll
1002ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'devobj.dll'...
1003ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'devobj.dll' -> '\Device\HarddiskVolume4\Windows\System32\devobj.dll' [rcNtRedir=0xc0150008]
1004ecc.e58: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\devobj.dll'.
1005ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1006ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'cfgmgr32.dll'.
1007ecc.e58: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\devobj.dll)
1008ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\devobj.dll
1009ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1010ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1011ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1012ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1013ecc.e58: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\gdi32.dll'.
1014ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #21 'user32.dll'.
1015ecc.e58: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\gdi32.dll)
1016ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\gdi32.dll
1017ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1018ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1019ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll [lacks WinVerifyTrust]
1020ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
1021ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
1022ecc.e58: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll'.
1023ecc.e58: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll)
1024ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll
1025ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1026ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1027ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
1028ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
1029ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_1358_for_KB3000850~31bf3856ad364e35~amd64~~6.3.1.8.cat'; file='\Device\HarddiskVolume4\Windows\System32\comdlg32.dll'
1030ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1031ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1032ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'shlwapi.dll'.
1033ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
1034ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'gdi32.dll'.
1035ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'comctl32.dll'.
1036ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'shell32.dll'.
1037ecc.e58: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\comdlg32.dll)WinVerifyTrust
1038ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\comdlg32.dll
1039ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
1040ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume4\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
1041ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
1042ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume4\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
1043ecc.e58: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\shell32.dll'.
1044ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1045ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #55 'user32.dll'.
1046ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #57 'shlwapi.dll'.
1047ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #59 'gdi32.dll'.
1048ecc.e58: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\shell32.dll)
1049ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\shell32.dll
1050ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comctl32.dll'...
1051ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'comctl32.dll' -> '\Device\HarddiskVolume4\Windows\System32\comctl32.dll' [rcNtRedir=0x0]
1052ecc.e58: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume4\Windows\System32\comctl32.dll'.
1053ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'advapi32.dll'.
1054ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
1055ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
1056ecc.e58: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\System32\comctl32.dll)
1057ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\comctl32.dll
1058ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1059ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1060ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
1061ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1062ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1063ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll [lacks WinVerifyTrust]
1064ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
1065ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume4\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
1066ecc.e58: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\shlwapi.dll'.
1067ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
1068ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #37 'user32.dll'.
1069ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #38 'gdi32.dll'.
1070ecc.e58: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\shlwapi.dll)
1071ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\shlwapi.dll
1072ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1073ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1074ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1075ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1076ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
1077ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1078ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1079ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll [lacks WinVerifyTrust]
1080ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1081ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1082ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1083ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1084ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll [lacks WinVerifyTrust]
1085ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1086ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1087ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
1088ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
1089ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
1090ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\advapi32.dll
1091ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1092ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1093ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
1094ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
1095ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume4\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
1096ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\shlwapi.dll [lacks WinVerifyTrust]
1097ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1098ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1099ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll [lacks WinVerifyTrust]
1100ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1101ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1102ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
1103ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
1104ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1105ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'combase.dll'.
1106ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'rpcrt4.dll'.
1107ecc.e58: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\oleaut32.dll)WinVerifyTrust
1108ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\oleaut32.dll
1109ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
1110ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
1111ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
1112ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
1113ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll
1114ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
1115ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume4\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
1116ecc.e58: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\combase.dll'.
1117ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1118ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
1119ecc.e58: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\combase.dll)
1120ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\combase.dll
1121ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1122ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1123ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
1124ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
1125ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1126ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1127ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
1128ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
1129ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
1130ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'rpcrt4.dll'.
1131ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #36 'gdi32.dll'.
1132ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #37 'user32.dll'.
1133ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #38 'combase.dll'.
1134ecc.e58: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\ole32.dll)WinVerifyTrust
1135ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\ole32.dll
1136ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
1137ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume4\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
1138ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\shell32.dll [redoing WinVerifyTrust]
1139ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
1140ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume4\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
1141ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\combase.dll [lacks WinVerifyTrust]
1142ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1143ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1144ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll [lacks WinVerifyTrust]
1145ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1146ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1147ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
1148ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
1149ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
1150ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1151ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1152ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll
1153ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
1154ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
1155ecc.e58: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\shell32.dll'
1156ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
1157ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
1158ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\advapi32.dll
1159ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1160ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1161ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gdi32.dll [redoing WinVerifyTrust]
1162ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
1163ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
1164ecc.e58: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\gdi32.dll'
1165ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1166ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1167ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll [redoing WinVerifyTrust]
1168ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
1169ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
1170ecc.e58: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\user32.dll'
1171ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtopenglvbox4.dll'...
1172ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtopenglvbox4.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qtopenglvbox4.dll' [rcNtRedir=0xc0150008]
1173ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
1174ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'opengl32.dll'.
1175ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
1176ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
1177ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qtguivbox4.dll'.
1178ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qtcorevbox4.dll'.
1179ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcr100.dll'.
1180ecc.e58: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll)WinVerifyTrust
1181ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll
1182ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtnetworkvbox4.dll'...
1183ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtnetworkvbox4.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qtnetworkvbox4.dll' [rcNtRedir=0xc0150008]
1184ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
1185ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
1186ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
1187ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtcorevbox4.dll'...
1188ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtcorevbox4.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qtcorevbox4.dll' [rcNtRedir=0xc0150008]
1189ecc.e58: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll'.
1190ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
1191ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'ole32.dll'.
1192ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
1193ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ws2_32.dll'.
1194ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcp100.dll'.
1195ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcr100.dll'.
1196ecc.e58: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll)
1197ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll
1198ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtguivbox4.dll'...
1199ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtguivbox4.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qtguivbox4.dll' [rcNtRedir=0xc0150008]
1200ecc.e58: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll'.
1201ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
1202ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'comdlg32.dll'.
1203ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'oleaut32.dll'.
1204ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'imm32.dll'.
1205ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'winmm.dll'.
1206ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'winspool.drv'.
1207ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ole32.dll'.
1208ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'user32.dll'.
1209ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'advapi32.dll'.
1210ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'shell32.dll'.
1211ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'qtcorevbox4.dll'.
1212ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'msvcp100.dll'.
1213ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'msvcr100.dll'.
1214ecc.e58: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll)
1215ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll
1216ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1217ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1218ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll
1219ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1220ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1221ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gdi32.dll
1222ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
1223ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume4\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
1224ecc.e58: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume4\Windows\System32\opengl32.dll'.
1225ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1226ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
1227ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'gdi32.dll'.
1228ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'glu32.dll'.
1229ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ddraw.dll'.
1230ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'user32.dll'.
1231ecc.e58: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\System32\opengl32.dll)
1232ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\opengl32.dll
1233ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1234ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1235ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ddraw.dll'...
1236ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'ddraw.dll' -> '\Device\HarddiskVolume4\Windows\System32\ddraw.dll' [rcNtRedir=0xc0150008]
1237ecc.e58: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume4\Windows\System32\ddraw.dll'.
1238ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1239ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'user32.dll'.
1240ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'gdi32.dll'.
1241ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'dciman32.dll'.
1242ecc.e58: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\System32\ddraw.dll)
1243ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\ddraw.dll
1244ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'glu32.dll'...
1245ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'glu32.dll' -> '\Device\HarddiskVolume4\Windows\System32\glu32.dll' [rcNtRedir=0xc0150008]
1246ecc.e58: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume4\Windows\System32\glu32.dll'.
1247ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1248ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'opengl32.dll'.
1249ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
1250ecc.e58: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\System32\glu32.dll)
1251ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\glu32.dll
1252ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1253ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1254ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gdi32.dll
1255ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
1256ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
1257ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\advapi32.dll
1258ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1259ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1260ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
1261ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
1262ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
1263ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
1264ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
1265ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll
1266ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtcorevbox4.dll'...
1267ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtcorevbox4.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qtcorevbox4.dll' [rcNtRedir=0xc0150008]
1268ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll [lacks WinVerifyTrust]
1269ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
1270ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume4\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
1271ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\shell32.dll
1272ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
1273ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
1274ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\advapi32.dll
1275ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1276ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1277ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
1278ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
1279ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ole32.dll
1280ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winspool.drv'...
1281ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'winspool.drv' -> '\Device\HarddiskVolume4\Windows\System32\winspool.drv' [rcNtRedir=0xc0150008]
1282ecc.e58: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume4\Windows\System32\winspool.drv'.
1283ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1284ecc.e58: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\System32\winspool.drv)
1285ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\winspool.drv
1286ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
1287ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume4\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
1288ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmm.dll
1289ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
1290ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume4\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
1291ecc.e58: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\imm32.dll'.
1292ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'user32.dll'.
1293ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #21 'msctf.dll'.
1294ecc.e58: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\imm32.dll)
1295ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\imm32.dll
1296ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
1297ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume4\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
1298ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\oleaut32.dll
1299ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comdlg32.dll'...
1300ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'comdlg32.dll' -> '\Device\HarddiskVolume4\Windows\System32\comdlg32.dll' [rcNtRedir=0xc0150008]
1301ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\comdlg32.dll
1302ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1303ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1304ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
1305ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
1306ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
1307ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
1308ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
1309ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll
1310ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
1311ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
1312ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ws2_32.dll
1313ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
1314ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
1315ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\advapi32.dll
1316ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
1317ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
1318ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ole32.dll
1319ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1320ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1321ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msctf.dll'...
1322ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'msctf.dll' -> '\Device\HarddiskVolume4\Windows\System32\msctf.dll' [rcNtRedir=0xc0150008]
1323ecc.e58: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\msctf.dll'.
1324ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1325ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'user32.dll'.
1326ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #24 'gdi32.dll'.
1327ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'imm32.dll'.
1328ecc.e58: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\msctf.dll)
1329ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\msctf.dll
1330ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1331ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1332ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1333ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1334ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1335ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1336ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
1337ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume4\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
1338ecc.e58: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\opengl32.dll [lacks WinVerifyTrust]
1339ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1340ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1341ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dciman32.dll'...
1342ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'dciman32.dll' -> '\Device\HarddiskVolume4\Windows\System32\dciman32.dll' [rcNtRedir=0xc0150008]
1343ecc.e58: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume4\Windows\System32\dciman32.dll'.
1344ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1345ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'gdi32.dll'.
1346ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
1347ecc.e58: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\System32\dciman32.dll)
1348ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\dciman32.dll
1349ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1350ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1351ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1352ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1353ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1354ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1355ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1356ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1357ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1358ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1359ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1360ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1361ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
1362ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume4\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
1363ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\imm32.dll [lacks WinVerifyTrust]
1364ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1365ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1366ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1367ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1368ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll
1369ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1370ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1371ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
1372ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ws2_32.dll'.
1373ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'qtcorevbox4.dll'.
1374ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcr100.dll'.
1375ecc.e58: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtNetworkVBox4.dll)WinVerifyTrust
1376ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtNetworkVBox4.dll
1377ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtguivbox4.dll'...
1378ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtguivbox4.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qtguivbox4.dll' [rcNtRedir=0xc0150008]
1379ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll [redoing WinVerifyTrust]
1380ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
1381ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
1382ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
1383ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtcorevbox4.dll'...
1384ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtcorevbox4.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qtcorevbox4.dll' [rcNtRedir=0xc0150008]
1385ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll [lacks WinVerifyTrust]
1386ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
1387ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
1388ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ws2_32.dll
1389ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
1390ecc.e58: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll'
1391ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtcorevbox4.dll'...
1392ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtcorevbox4.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qtcorevbox4.dll' [rcNtRedir=0xc0150008]
1393ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll [redoing WinVerifyTrust]
1394ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
1395ecc.e58: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll'
1396ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
1397ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
1398ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll [redoing WinVerifyTrust]
1399ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
1400ecc.e58: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll'
1401ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
1402ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
1403ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll
1404ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
1405ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
1406ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
1407ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume4\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
1408ecc.e58: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\opengl32.dll [redoing WinVerifyTrust]
1409ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000050c pwszName=\Device\HarddiskVolume4\Windows\System32\opengl32.dll
1410ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000112a710
1411ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000112a710
1412ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2C6D4490D969C3233E8843AD4B11DB3F390C0B16
1413ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
1414ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
1415ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_1537_for_KB3000850~31bf3856ad364e35~amd64~~6.3.1.8.cat'; file='\Device\HarddiskVolume4\Windows\System32\opengl32.dll'
1416ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1417ecc.e58: supR3HardenedScreenImage/Imports: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\opengl32.dll'
1418ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VirtualBox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000a01:<flags> [calling]
1419ecc.e58: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.dll
1420ecc.e58: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\opengl32.dll
1421ecc.e58: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll
1422ecc.e58: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll
1423ecc.e58: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtNetworkVBox4.dll
1424ecc.e58: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll
1425ecc.e58: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmm.dll
1426ecc.e58: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\glu32.dll [avoiding WinVerifyTrust]
1427ecc.e58: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\ddraw.dll [avoiding WinVerifyTrust]
1428ecc.e58: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\winspool.drv [avoiding WinVerifyTrust]
1429ecc.e58: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\combase.dll [avoiding WinVerifyTrust]
1430ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'advapi32.dll'.
1431ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
1432ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
1433ecc.e58: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.9600.17415_none_34aa3313958e7a52\comctl32.dll)
1434ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.9600.17415_none_34aa3313958e7a52\comctl32.dll
1435ecc.e58: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmmbase.dll [avoiding WinVerifyTrust]
1436ecc.e58: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\dciman32.dll [avoiding WinVerifyTrust]
1437ecc.e58: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll [avoiding WinVerifyTrust]
1438ecc.e58: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\devobj.dll [avoiding WinVerifyTrust]
1439ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1440ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #33 'combase.dll'.
1441ecc.e58: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\SHCore.dll)
1442ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\SHCore.dll
1443ecc.e58: supR3HardenedDllNotificationCallback: load 00007ff8a2720000 LB 0x00177000 C:\Windows\system32\USER32.dll [fFlags=0x0]
1444ecc.e58: supR3HardenedDllNotificationCallback: load 00007ff8a2a20000 LB 0x00151000 C:\Windows\system32\GDI32.dll [fFlags=0x0]
1445ecc.e58: supR3HardenedDllNotificationCallback: load 00007ff892470000 LB 0x00009000 C:\Windows\SYSTEM32\DCIMAN32.dll [fFlags=0x0]
1446ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\dciman32.dll [avoiding WinVerifyTrust]
1447ecc.e58: supR3HardenedDllNotificationCallback: load 00007ff8894f0000 LB 0x000f8000 C:\Windows\SYSTEM32\DDRAW.dll [fFlags=0x0]
1448ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\ddraw.dll [avoiding WinVerifyTrust]
1449ecc.e58: supR3HardenedDllNotificationCallback: load 00007ff891ce0000 LB 0x0002e000 C:\Windows\SYSTEM32\GLU32.dll [fFlags=0x0]
1450ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\glu32.dll [avoiding WinVerifyTrust]
1451ecc.e58: supR3HardenedDllNotificationCallback: load 00007ff8895f0000 LB 0x0012b000 C:\Windows\SYSTEM32\OPENGL32.dll [fFlags=0x0]
1452ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\opengl32.dll
1453ecc.e58: supR3HardenedDllNotificationCallback: load 00007ff8a2d10000 LB 0x00211000 C:\Windows\SYSTEM32\combase.dll [fFlags=0x0]
1454ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\combase.dll [avoiding WinVerifyTrust]
1455ecc.e58: supR3HardenedDllNotificationCallback: load 00007ff8a2580000 LB 0x00194000 C:\Windows\system32\ole32.dll [fFlags=0x0]
1456ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ole32.dll
1457ecc.e58: supR3HardenedDllNotificationCallback: load 000000006b490000 LB 0x002de000 C:\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll [fFlags=0x0]
1458ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll
1459ecc.e58: supR3HardenedDllNotificationCallback: load 00007ff8a3500000 LB 0x00054000 C:\Windows\system32\SHLWAPI.dll [fFlags=0x0]
1460ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\shlwapi.dll [avoiding WinVerifyTrust]
1461ecc.e58: supR3HardenedDllNotificationCallback: load 00007ff89f960000 LB 0x000a4000 C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.9600.17415_none_34aa3313958e7a52\COMCTL32.dll [fFlags=0x0]
1462ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.9600.17415_none_34aa3313958e7a52\comctl32.dll [avoiding WinVerifyTrust]
1463ecc.e58: supR3HardenedDllNotificationCallback: load 00007ff8a35c0000 LB 0x01518000 C:\Windows\system32\SHELL32.dll [fFlags=0x0]
1464ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\shell32.dll
1465ecc.e58: supR3HardenedDllNotificationCallback: load 00007ff8a0ad0000 LB 0x000b2000 C:\Windows\SYSTEM32\SHCORE.DLL [fFlags=0x0]
1466ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\SHCore.dll [avoiding WinVerifyTrust]
1467ecc.e58: supR3HardenedDllNotificationCallback: load 00007ff8a24b0000 LB 0x000b6000 C:\Windows\system32\COMDLG32.dll [fFlags=0x0]
1468ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\comdlg32.dll
1469ecc.e58: supR3HardenedDllNotificationCallback: load 00007ff8a3250000 LB 0x000c1000 C:\Windows\system32\OLEAUT32.dll [fFlags=0x0]
1470ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\oleaut32.dll
1471ecc.e58: supR3HardenedDllNotificationCallback: load 00007ff8a30f0000 LB 0x00151000 C:\Windows\system32\MSCTF.dll [fFlags=0x0]
1472ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msctf.dll [avoiding WinVerifyTrust]
1473ecc.e58: supR3HardenedDllNotificationCallback: load 00007ff8a2cd0000 LB 0x00036000 C:\Windows\system32\IMM32.dll [fFlags=0x0]
1474ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\imm32.dll [avoiding WinVerifyTrust]
1475ecc.e58: supR3HardenedDllNotificationCallback: load 00007ff8a2460000 LB 0x0004f000 C:\Windows\SYSTEM32\cfgmgr32.dll [fFlags=0x0]
1476ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll [avoiding WinVerifyTrust]
1477ecc.e58: supR3HardenedDllNotificationCallback: load 00007ff8a0d70000 LB 0x00028000 C:\Windows\SYSTEM32\DEVOBJ.dll [fFlags=0x0]
1478ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\devobj.dll [avoiding WinVerifyTrust]
1479ecc.e58: supR3HardenedDllNotificationCallback: load 00007ff89fbc0000 LB 0x0002a000 C:\Windows\SYSTEM32\WINMMBASE.dll [fFlags=0x0]
1480ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmmbase.dll [avoiding WinVerifyTrust]
1481ecc.e58: supR3HardenedDllNotificationCallback: load 00007ff89fe80000 LB 0x00022000 C:\Windows\SYSTEM32\WINMM.dll [fFlags=0x0]
1482ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmm.dll
1483ecc.e58: supR3HardenedDllNotificationCallback: load 00007ff89f8d0000 LB 0x00082000 C:\Windows\SYSTEM32\WINSPOOL.DRV [fFlags=0x0]
1484ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\winspool.drv [avoiding WinVerifyTrust]
1485ecc.e58: supR3HardenedDllNotificationCallback: load 000000006ab20000 LB 0x00969000 C:\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll [fFlags=0x0]
1486ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll
1487ecc.e58: supR3HardenedDllNotificationCallback: load 000000006aa10000 LB 0x00105000 C:\Program Files\Oracle\VirtualBox\QtNetworkVBox4.dll [fFlags=0x0]
1488ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtNetworkVBox4.dll
1489ecc.e58: supR3HardenedDllNotificationCallback: load 000000006a930000 LB 0x000dc000 C:\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll [fFlags=0x0]
1490ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll
1491ecc.e58: supR3HardenedDllNotificationCallback: load 00007ff87afa0000 LB 0x00875000 C:\Program Files\Oracle\VirtualBox\VirtualBox.dll [fFlags=0x0]
1492ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.dll
1493ecc.e58: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\SHCore.dll'.
1494ecc.e58: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\SHCore.dll' [rescheduled]
1495ecc.e58: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume4\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.9600.17415_none_34aa3313958e7a52\comctl32.dll'.
1496ecc.e58: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.9600.17415_none_34aa3313958e7a52\comctl32.dll' [rescheduled]
1497ecc.e58: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume4\Windows\System32\dciman32.dll'.
1498ecc.e58: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\dciman32.dll' [rescheduled]
1499ecc.e58: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\msctf.dll'.
1500ecc.e58: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\msctf.dll' [rescheduled]
1501ecc.e58: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\imm32.dll'.
1502ecc.e58: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\imm32.dll' [rescheduled]
1503ecc.e58: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume4\Windows\System32\winspool.drv'.
1504ecc.e58: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\winspool.drv' [rescheduled]
1505ecc.e58: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume4\Windows\System32\glu32.dll'.
1506ecc.e58: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\glu32.dll' [rescheduled]
1507ecc.e58: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume4\Windows\System32\ddraw.dll'.
1508ecc.e58: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\ddraw.dll' [rescheduled]
1509ecc.e58: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\combase.dll'.
1510ecc.e58: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\combase.dll' [rescheduled]
1511ecc.e58: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\shlwapi.dll'.
1512ecc.e58: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\shlwapi.dll' [rescheduled]
1513ecc.e58: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume4\Windows\System32\comctl32.dll'.
1514ecc.e58: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\comctl32.dll' [rescheduled]
1515ecc.e58: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll'.
1516ecc.e58: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll' [rescheduled]
1517ecc.e58: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\devobj.dll'.
1518ecc.e58: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\devobj.dll' [rescheduled]
1519ecc.e58: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\winmmbase.dll'.
1520ecc.e58: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\winmmbase.dll' [rescheduled]
1521ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\imm32.dll [redoing WinVerifyTrust]
1522ecc.e58: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\imm32.dll'.
1523ecc.e58: supR3HardenedScreenImage/LdrLoadDll: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume4\Windows\System32\imm32.dll
1524ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
1525ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume4\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
1526ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\combase.dll [redoing WinVerifyTrust]
1527ecc.e58: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\combase.dll'.
1528ecc.e58: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume4\Windows\System32\combase.dll
1529ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1530ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1531ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1532ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1533ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1534ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1535ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
1536ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
1537ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\advapi32.dll
1538ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\imm32.dll (Input=imm32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
1539ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2cd0000 'C:\Windows\system32\imm32.dll'
1540ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff87afa0000 'C:\Program Files\Oracle\VirtualBox\VirtualBox.dll'
1541ecc.e58: SUPR3HardenedMain: Calling TrustedMain (00007ff87afa1ca0)...
1542ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmm.dll
1543ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\winmm.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
1544ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff89fe80000 'C:\Windows\system32\winmm.dll'
1545ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000610 pwszName=\Device\HarddiskVolume4\Windows\System32\uxtheme.dll
1546ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000112a710
1547ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000112a710
1548ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=011C79DEF7FEEC81838000B9664073BAE4A7CB92
1549ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
1550ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
1551ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_1357_for_KB3000850~31bf3856ad364e35~amd64~~6.3.1.8.cat'; file='\Device\HarddiskVolume4\Windows\System32\uxtheme.dll'
1552ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1553ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1554ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'user32.dll'.
1555ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'gdi32.dll'.
1556ecc.e58: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\uxtheme.dll)WinVerifyTrust
1557ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\uxtheme.dll
1558ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1559ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1560ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1561ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1562ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1563ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1564ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
1565ecc.e58: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\uxtheme.dll
1566ecc.e58: supR3HardenedDllNotificationCallback: load 00007ff8a0bf0000 LB 0x00129000 C:\Windows\system32\uxtheme.dll [fFlags=0x0]
1567ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\uxtheme.dll
1568ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a0bf0000 'C:\Windows\system32\uxtheme.dll'
1569ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\uxtheme.dll
1570ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
1571ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a0bf0000 'C:\Windows\system32\uxtheme.dll'
1572ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\uxtheme.dll
1573ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
1574ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a0bf0000 'C:\Windows\system32\uxtheme.dll'
1575ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\uxtheme.dll
1576ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
1577ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a0bf0000 'C:\Windows\system32\uxtheme.dll'
1578ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1579ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'user32.dll'.
1580ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #15 'gdi32.dll'.
1581ecc.e58: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\dwmapi.dll)
1582ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\dwmapi.dll
1583ecc.e58: supR3HardenedDllNotificationCallback: load 00007ff89feb0000 LB 0x00021000 C:\Windows\system32\dwmapi.dll [fFlags=0x0]
1584ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\dwmapi.dll [avoiding WinVerifyTrust]
1585ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcrt.dll'.
1586ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'rpcrt4.dll'.
1587ecc.e58: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\kernel.appcore.dll)
1588ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\kernel.appcore.dll
1589ecc.e58: supR3HardenedDllNotificationCallback: load 00007ff8a0dc0000 LB 0x0000b000 C:\Windows\SYSTEM32\kernel.appcore.dll [fFlags=0x0]
1590ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\kernel.appcore.dll [avoiding WinVerifyTrust]
1591ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
1592ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
1593ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1594ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1595ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1596ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1597ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gdi32.dll
1598ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1599ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1600ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1601ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1602ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
1603ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
1604ecc.e58: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\kernel.appcore.dll'
1605ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
1606ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
1607ecc.e58: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\dwmapi.dll'
1608ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\shell32.dll
1609ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
1610ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a35c0000 'C:\Windows\system32\shell32.dll'
1611ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\kernel32.dll
1612ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
1613ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a4b10000 'C:\Windows\system32\kernel32.dll'
1614ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\uxtheme.dll
1615ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
1616ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a0bf0000 'C:\Windows\system32\uxtheme.dll'
1617ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\uxtheme.dll
1618ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
1619ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a0bf0000 'C:\Windows\system32\uxtheme.dll'
1620ecc.e58: supR3HardenedMonitor_LdrLoadDll: error opening 'C:\Windows\system32\wintab32.dll': 0 (NtPath=\??\C:\Windows\system32\wintab32.dll; Input=C:\Windows\system32\wintab32.dll; rcNtGetDll=0x0
1621ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wintab32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
1622ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000135 'C:\Windows\system32\wintab32.dll'
1623ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2720000 'C:\Windows\system32\user32.dll'
1624ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\uxtheme.dll
1625ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
1626ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a0bf0000 'C:\Windows\system32\uxtheme.dll'
1627ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2720000 'C:\Windows\system32\user32.dll'
1628ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\advapi32.dll
1629ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\advapi32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
1630ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a3390000 'C:\Windows\system32\advapi32.dll'
1631ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
1632ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
1633ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1634ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rpcrt4.dll'.
1635ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #21 'profapi.dll'.
1636ecc.e58: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\userenv.dll)WinVerifyTrust
1637ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\userenv.dll
1638ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'profapi.dll'...
1639ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'profapi.dll' -> '\Device\HarddiskVolume4\Windows\System32\profapi.dll' [rcNtRedir=0xc0150008]
1640ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\profapi.dll
1641ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
1642ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
1643ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1644ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1645ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\userenv.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
1646ecc.e58: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\userenv.dll
1647ecc.e58: supR3HardenedDllNotificationCallback: load 00007ff8a1520000 LB 0x00021000 C:\Windows\system32\userenv.dll [fFlags=0x0]
1648ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\userenv.dll
1649ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1520000 'C:\Windows\system32\userenv.dll'
1650ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\kernel32.dll
1651ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
1652ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a4b10000 'C:\Windows\system32\kernel32.dll'
1653ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1654ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'rpcrt4.dll'.
1655ecc.e58: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\clbcatq.dll)
1656ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\clbcatq.dll
1657ecc.e58: supR3HardenedDllNotificationCallback: load 00007ff8a2960000 LB 0x000b6000 C:\Windows\SYSTEM32\clbcatq.dll [fFlags=0x0]
1658ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\clbcatq.dll [avoiding WinVerifyTrust]
1659ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
1660ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
1661ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1662ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1663ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
1664ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
1665ecc.e58: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\clbcatq.dll'
1666ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
1667ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\oleaut32.dll
1668ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\oleaut32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
1669ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a3250000 'C:\Windows\System32\oleaut32.dll'
1670ecc.e58: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\System32\sxs.dll)
1671ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\sxs.dll
1672ecc.e58: supR3HardenedDllNotificationCallback: load 00007ff8a1e60000 LB 0x00099000 C:\Windows\SYSTEM32\sxs.dll [fFlags=0x0]
1673ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\sxs.dll [avoiding WinVerifyTrust]
1674ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000718 pwszName=\Device\HarddiskVolume4\Windows\System32\sxs.dll
1675ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000112a710
1676ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000112a710
1677ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=CE9E354C30F5B2A6EDC3DE9416DF14533BE89816
1678ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
1679ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
1680ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_846_for_KB3000850~31bf3856ad364e35~amd64~~6.3.1.8.cat'; file='\Device\HarddiskVolume4\Windows\System32\sxs.dll'
1681ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1682ecc.e58: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\sxs.dll'
1683ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\oleaut32.dll
1684ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\OLEAUT32.dll (Input=OLEAUT32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
1685ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a3250000 'C:\Windows\system32\OLEAUT32.dll'
1686ecc.e58: supR3HardenedMonitor_LdrLoadDll: error opening 'C:\Windows\system32\wintab32.dll': 0 (NtPath=\??\C:\Windows\system32\wintab32.dll; Input=C:\Windows\system32\wintab32.dll; rcNtGetDll=0x0
1687ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wintab32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
1688ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000135 'C:\Windows\system32\wintab32.dll'
1689ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2a20000 'C:\Windows\system32\gdi32.dll'
1690ecc.1700: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
1691ecc.1700: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
1692ecc.1700: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
1693ecc.1700: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
1694ecc.1700: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
1695ecc.1700: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ws2_32.dll'.
1696ecc.1700: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ole32.dll'.
1697ecc.1700: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'oleaut32.dll'.
1698ecc.1700: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxC.dll)WinVerifyTrust
1699ecc.1700: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxC.dll
1700ecc.1700: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
1701ecc.1700: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume4\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
1702ecc.1700: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\oleaut32.dll
1703ecc.1700: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
1704ecc.1700: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
1705ecc.1700: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ole32.dll
1706ecc.1700: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
1707ecc.1700: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
1708ecc.1700: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ws2_32.dll
1709ecc.1700: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
1710ecc.1700: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
1711ecc.1700: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
1712ecc.1700: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
1713ecc.1700: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
1714ecc.1700: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
1715ecc.1700: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll
1716ecc.1700: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
1717ecc.1700: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
1718ecc.1700: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll
1719ecc.1700: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxC.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
1720ecc.1700: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxC.dll
1721ecc.1700: supR3HardenedDllNotificationCallback: load 00007ff87aaa0000 LB 0x004f9000 C:\Program Files\Oracle\VirtualBox\VBoxC.dll [fFlags=0x0]
1722ecc.1700: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxC.dll
1723ecc.1700: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff87aaa0000 'C:\Program Files\Oracle\VirtualBox\VBoxC.dll'
1724ecc.c14: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
1725ecc.c14: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
1726ecc.c14: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
1727ecc.c14: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
1728ecc.c14: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
1729ecc.c14: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMain.dll)WinVerifyTrust
1730ecc.c14: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMain.dll
1731ecc.c14: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
1732ecc.c14: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
1733ecc.c14: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
1734ecc.c14: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
1735ecc.c14: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.amd64/VBoxPuelMain.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
1736ecc.c14: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMain.dll
1737ecc.c14: supR3HardenedDllNotificationCallback: load 00007ff8969c0000 LB 0x0000c000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMain.DLL [fFlags=0x0]
1738ecc.c14: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMain.dll
1739ecc.c14: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8969c0000 'C:\Program Files\Oracle\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.amd64/VBoxPuelMain.DLL'
1740ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2720000 'C:\Windows\system32\user32.dll'
1741ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\shell32.dll
1742ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
1743ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a35c0000 'C:\Windows\system32\shell32.dll'
1744ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ole32.dll
1745ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ole32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
1746ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2580000 'C:\Windows\system32\ole32.dll'
1747ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ole32.dll
1748ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ole32.dll (Input=ole32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
1749ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2580000 'C:\Windows\system32\ole32.dll'
1750ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\oleaut32.dll
1751ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\OLEAUT32.dll (Input=OLEAUT32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
1752ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a3250000 'C:\Windows\system32\OLEAUT32.dll'
1753ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000a7c pwszName=\Device\HarddiskVolume4\Windows\System32\wbem\wbemprox.dll
1754ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000112a710
1755ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000112a710
1756ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=423F3447A3399AF560C707709A03AE5E23FA1CAD
1757ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
1758ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
1759ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_746_for_KB3000850~31bf3856ad364e35~amd64~~6.3.1.8.cat'; file='\Device\HarddiskVolume4\Windows\System32\wbem\wbemprox.dll'
1760ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1761ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1762ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ws2_32.dll'.
1763ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'wbemcomn.dll'.
1764ecc.e58: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\wbem\wbemprox.dll)WinVerifyTrust
1765ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\wbem\wbemprox.dll
1766ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wbemcomn.dll'...
1767ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'wbemcomn.dll' -> '\Device\HarddiskVolume4\Windows\System32\wbemcomn.dll' [rcNtRedir=0xc0150008]
1768ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000a98 pwszName=\Device\HarddiskVolume4\Windows\System32\wbemcomn.dll
1769ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000112a710
1770ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000112a710
1771ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=3E264B83DD0BC4A26011E964C5856C40BC4FD6A4
1772ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
1773ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
1774ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_746_for_KB3000850~31bf3856ad364e35~amd64~~6.3.1.8.cat'; file='\Device\HarddiskVolume4\Windows\System32\wbemcomn.dll'
1775ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1776ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1777ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #15 'ws2_32.dll'.
1778ecc.e58: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\wbemcomn.dll)WinVerifyTrust
1779ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\wbemcomn.dll
1780ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
1781ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
1782ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ws2_32.dll
1783ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1784ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1785ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
1786ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
1787ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ws2_32.dll
1788ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1789ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1790ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wbem\wbemprox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
1791ecc.e58: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wbem\wbemprox.dll
1792ecc.e58: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wbemcomn.dll
1793ecc.e58: supR3HardenedDllNotificationCallback: load 00007ff897680000 LB 0x00082000 C:\Windows\SYSTEM32\wbemcomn.dll [fFlags=0x0]
1794ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wbemcomn.dll
1795ecc.e58: supR3HardenedDllNotificationCallback: load 00007ff896600000 LB 0x00011000 C:\Windows\system32\wbem\wbemprox.dll [fFlags=0x0]
1796ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wbem\wbemprox.dll
1797ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Core-LocalRegistry-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
1798ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a22e0000 'API-MS-Win-Core-LocalRegistry-L1-1-0.dll'
1799ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff896600000 'C:\Windows\system32\wbem\wbemprox.dll'
1800ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000a60 pwszName=\Device\HarddiskVolume4\Windows\System32\wbem\wbemsvc.dll
1801ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000112a710
1802ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000112a710
1803ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=34CAAFAC191912291EB7000AE3D54335A7FD4C18
1804ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
1805ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
1806ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_746_for_KB3000850~31bf3856ad364e35~amd64~~6.3.1.8.cat'; file='\Device\HarddiskVolume4\Windows\System32\wbem\wbemsvc.dll'
1807ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1808ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1809ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'rpcrt4.dll'.
1810ecc.e58: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\wbem\wbemsvc.dll)WinVerifyTrust
1811ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\wbem\wbemsvc.dll
1812ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
1813ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
1814ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1815ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1816ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wbem\wbemsvc.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
1817ecc.e58: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wbem\wbemsvc.dll
1818ecc.e58: supR3HardenedDllNotificationCallback: load 00007ff896c40000 LB 0x00015000 C:\Windows\system32\wbem\wbemsvc.dll [fFlags=0x0]
1819ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wbem\wbemsvc.dll
1820ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff896c40000 'C:\Windows\system32\wbem\wbemsvc.dll'
1821ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-l1-2-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
1822ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a22e0000 'api-ms-win-core-localization-l1-2-0.dll'
1823ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-obsolete-l1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
1824ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a22e0000 'api-ms-win-core-localization-obsolete-l1-1-0.dll'
1825ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000a44 pwszName=\Device\HarddiskVolume4\Windows\System32\wbem\fastprox.dll
1826ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000112a710
1827ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000112a710
1828ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=92F5EA7DEF5292B930D85382B83309F563FFA69F
1829ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
1830ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
1831ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_746_for_KB3000850~31bf3856ad364e35~amd64~~6.3.1.8.cat'; file='\Device\HarddiskVolume4\Windows\System32\wbem\fastprox.dll'
1832ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1833ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1834ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'wbemcomn.dll'.
1835ecc.e58: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\wbem\fastprox.dll)WinVerifyTrust
1836ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\wbem\fastprox.dll
1837ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wbemcomn.dll'...
1838ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'wbemcomn.dll' -> '\Device\HarddiskVolume4\Windows\System32\wbemcomn.dll' [rcNtRedir=0xc0150008]
1839ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wbemcomn.dll
1840ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1841ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1842ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll
1843ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wbem\fastprox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
1844ecc.e58: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wbem\fastprox.dll
1845ecc.e58: supR3HardenedDllNotificationCallback: load 00007ff896c60000 LB 0x000fb000 C:\Windows\system32\wbem\fastprox.dll [fFlags=0x0]
1846ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wbem\fastprox.dll
1847ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff896c60000 'C:\Windows\system32\wbem\fastprox.dll'
1848ecc.e58: supR3HardenedMonitor_LdrLoadDll: 'C:\Windows\system32\comctl32.dll' -> 'C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.9600.17415_none_34aa3313958e7a52\comctl32.dll' [redir]
1849ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.9600.17415_none_34aa3313958e7a52\comctl32.dll [redoing WinVerifyTrust]
1850ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004bc pwszName=\Device\HarddiskVolume4\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.9600.17415_none_34aa3313958e7a52\comctl32.dll
1851ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000112a710
1852ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000112a710
1853ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=D2439957F4F4E64F3771B4CC408D22259C95DE82
1854ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll
1855ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
1856ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
1857ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
1858ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_1358_for_KB3000850~31bf3856ad364e35~amd64~~6.3.1.8.cat'; file='\Device\HarddiskVolume4\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.9600.17415_none_34aa3313958e7a52\comctl32.dll'
1859ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1860ecc.e58: supR3HardenedScreenImage/LdrLoadDll: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.9600.17415_none_34aa3313958e7a52\comctl32.dll'
1861ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.9600.17415_none_34aa3313958e7a52\comctl32.dll (Input=C:\Windows\system32\comctl32.dll, rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
1862ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff89f960000 'C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.9600.17415_none_34aa3313958e7a52\comctl32.dll'
1863ecc.b5c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
1864ecc.b5c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
1865ecc.b5c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrem.dll'.
1866ecc.b5c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
1867ecc.b5c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxVMM.dll)WinVerifyTrust
1868ecc.b5c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxVMM.dll
1869ecc.b5c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
1870ecc.b5c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
1871ecc.b5c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrem.dll'...
1872ecc.b5c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrem.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrem.dll' [rcNtRedir=0xc0150008]
1873ecc.b5c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
1874ecc.b5c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'vboxrt.dll'.
1875ecc.b5c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
1876ecc.b5c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcrt.dll'.
1877ecc.b5c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxREM.dll)WinVerifyTrust
1878ecc.b5c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxREM.dll
1879ecc.b5c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
1880ecc.b5c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
1881ecc.b5c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1882ecc.b5c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1883ecc.b5c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
1884ecc.b5c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
1885ecc.b5c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxVMM.dll
1886ecc.b5c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
1887ecc.b5c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
1888ecc.b5c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
1889ecc.b5c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxVMM.dll
1890ecc.b5c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxREM.dll
1891ecc.b5c: supR3HardenedDllNotificationCallback: load 000000006a820000 LB 0x0010a000 C:\Program Files\Oracle\VirtualBox\VBoxREM.dll [fFlags=0x0]
1892ecc.b5c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxREM.dll
1893ecc.b5c: supR3HardenedDllNotificationCallback: load 00007ff87cff0000 LB 0x00262000 C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL [fFlags=0x0]
1894ecc.b5c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxVMM.dll
1895ecc.b5c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff87cff0000 'C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL'
1896ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
1897ecc.1840: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
1898ecc.1840: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
1899ecc.1840: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
1900ecc.1840: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
1901ecc.1840: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
1902ecc.1840: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll)WinVerifyTrust
1903ecc.1840: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll
1904ecc.1840: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1905ecc.1840: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1906ecc.1840: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
1907ecc.1840: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
1908ecc.1840: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
1909ecc.1840: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
1910ecc.1840: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxVMM.dll
1911ecc.1840: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
1912ecc.1840: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
1913ecc.1840: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
1914ecc.1840: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll
1915ecc.1840: supR3HardenedDllNotificationCallback: load 00007ff894620000 LB 0x0000a000 C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL [fFlags=0x0]
1916ecc.1840: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll
1917ecc.1840: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff894620000 'C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL'
1918ecc.19b8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
1919ecc.19b8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
1920ecc.19b8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
1921ecc.19b8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll)WinVerifyTrust
1922ecc.19b8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll
1923ecc.19b8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
1924ecc.19b8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
1925ecc.19b8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
1926ecc.19b8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
1927ecc.19b8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
1928ecc.19b8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll
1929ecc.19b8: supR3HardenedDllNotificationCallback: load 00007ff893a80000 LB 0x0000e000 C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL [fFlags=0x0]
1930ecc.19b8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll
1931ecc.19b8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff893a80000 'C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL'
1932ecc.10cc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
1933ecc.10cc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
1934ecc.10cc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
1935ecc.10cc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
1936ecc.10cc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll)WinVerifyTrust
1937ecc.10cc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll
1938ecc.10cc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
1939ecc.10cc: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
1940ecc.10cc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
1941ecc.10cc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
1942ecc.10cc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll
1943ecc.10cc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
1944ecc.10cc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
1945ecc.10cc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
1946ecc.10cc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll
1947ecc.10cc: supR3HardenedDllNotificationCallback: load 00007ff8939a0000 LB 0x0000f000 C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL [fFlags=0x0]
1948ecc.10cc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll
1949ecc.10cc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8939a0000 'C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL'
1950ecc.1a90: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
1951ecc.1a90: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
1952ecc.1a90: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
1953ecc.1a90: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
1954ecc.1a90: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll)WinVerifyTrust
1955ecc.1a90: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll
1956ecc.1a90: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
1957ecc.1a90: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
1958ecc.1a90: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
1959ecc.1a90: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
1960ecc.1a90: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll
1961ecc.1a90: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
1962ecc.1a90: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
1963ecc.1a90: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
1964ecc.1a90: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll
1965ecc.1a90: supR3HardenedDllNotificationCallback: load 00007ff8934f0000 LB 0x0000e000 C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL [fFlags=0x0]
1966ecc.1a90: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll
1967ecc.1a90: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8934f0000 'C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL'
1968ecc.10ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\shell32.dll
1969ecc.10ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32/Shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
1970ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a35c0000 'C:\Windows\system32/Shell32.dll'
1971ecc.10ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxVMM.dll
1972ecc.10ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
1973ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff87cff0000 'C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL'
1974ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
1975ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
1976ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
1977ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
1978ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ole32.dll'.
1979ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
1980ecc.10ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll)WinVerifyTrust
1981ecc.10ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
1982ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
1983ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume4\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
1984ecc.10ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\oleaut32.dll
1985ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
1986ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
1987ecc.10ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ole32.dll
1988ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1989ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1990ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
1991ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
1992ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
1993ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
1994ecc.10ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.amd64/VBoxHostWebcam.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
1995ecc.10ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
1996ecc.10ac: supR3HardenedDllNotificationCallback: load 00007ff892ea0000 LB 0x00033000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL [fFlags=0x0]
1997ecc.10ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
1998ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff892ea0000 'C:\Program Files\Oracle\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.amd64/VBoxHostWebcam.DLL'
1999ecc.10ac: supR3HardenedDllNotificationCallback: Unload 00007ff892ea0000 LB 0x00033000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL [flags=0x0]
2000ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
2001ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
2002ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
2003ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
2004ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
2005ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vboxddu.dll'.
2006ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'vboxdd2.dll'.
2007ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
2008ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'setupapi.dll'.
2009ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'ws2_32.dll'.
2010ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'ole32.dll'.
2011ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'iphlpapi.dll'.
2012ecc.10ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDD.dll)WinVerifyTrust
2013ecc.10ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDD.dll
2014ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'iphlpapi.dll'...
2015ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'iphlpapi.dll' -> '\Device\HarddiskVolume4\Windows\System32\iphlpapi.dll' [rcNtRedir=0xc0150008]
2016ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
2017ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
2018ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'nsi.dll'.
2019ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'winnsi.dll'.
2020ecc.10ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\IPHLPAPI.DLL)WinVerifyTrust
2021ecc.10ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\IPHLPAPI.DLL
2022ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
2023ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
2024ecc.10ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ole32.dll
2025ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
2026ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
2027ecc.10ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ws2_32.dll
2028ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
2029ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume4\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
2030ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winnsi.dll'...
2031ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'winnsi.dll' -> '\Device\HarddiskVolume4\Windows\System32\winnsi.dll' [rcNtRedir=0xc0150008]
2032ecc.10ac: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\winnsi.dll'.
2033ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'rpcrt4.dll'.
2034ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'nsi.dll'.
2035ecc.10ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\winnsi.dll)
2036ecc.10ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\winnsi.dll
2037ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
2038ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume4\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
2039ecc.10ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\nsi.dll [lacks WinVerifyTrust]
2040ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
2041ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume4\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
2042ecc.10ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\nsi.dll [lacks WinVerifyTrust]
2043ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
2044ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
2045ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
2046ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
2047ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'cfgmgr32.dll'.
2048ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
2049ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #22 'rpcrt4.dll'.
2050ecc.10ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\setupapi.dll)WinVerifyTrust
2051ecc.10ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\setupapi.dll
2052ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
2053ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
2054ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxdd2.dll'...
2055ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxdd2.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxdd2.dll' [rcNtRedir=0xc0150008]
2056ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
2057ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
2058ecc.10ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll
2059ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
2060ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
2061ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
2062ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
2063ecc.10ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll [lacks WinVerifyTrust]
2064ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
2065ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
2066ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
2067ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
2068ecc.10ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDD2.dll)WinVerifyTrust
2069ecc.10ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDD2.dll
2070ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxddu.dll'...
2071ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxddu.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxddu.dll' [rcNtRedir=0xc0150008]
2072ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
2073ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
2074ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
2075ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
2076ecc.10ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxVMM.dll
2077ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
2078ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
2079ecc.10ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll
2080ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
2081ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
2082ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
2083ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
2084ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'setupapi.dll'.
2085ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'newdev.dll'.
2086ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'advapi32.dll'.
2087ecc.10ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDDU.dll)WinVerifyTrust
2088ecc.10ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDDU.dll
2089ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
2090ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
2091ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
2092ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
2093ecc.10ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxVMM.dll
2094ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
2095ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
2096ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
2097ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
2098ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'newdev.dll'...
2099ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'newdev.dll' -> '\Device\HarddiskVolume4\Windows\System32\newdev.dll' [rcNtRedir=0xc0150008]
2100ecc.10ac: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000c80 pwszName=\Device\HarddiskVolume4\Windows\System32\newdev.dll
2101ecc.10ac: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000112a710
2102ecc.10ac: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000112a710
2103ecc.10ac: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=9B90F53BC1E04734936A6993D9005F5A7C816F8F
2104ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
2105ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
2106ecc.10ac: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_868_for_KB3000850~31bf3856ad364e35~amd64~~6.3.1.8.cat'; file='\Device\HarddiskVolume4\Windows\System32\newdev.dll'
2107ecc.10ac: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2108ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
2109ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
2110ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
2111ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
2112ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'uxtheme.dll'.
2113ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'cfgmgr32.dll'.
2114ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'setupapi.dll'.
2115ecc.10ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\newdev.dll)WinVerifyTrust
2116ecc.10ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\newdev.dll
2117ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
2118ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume4\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
2119ecc.10ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\setupapi.dll
2120ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
2121ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
2122ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
2123ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
2124ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
2125ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
2126ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
2127ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume4\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
2128ecc.10ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\setupapi.dll
2129ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
2130ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
2131ecc.10ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll [redoing WinVerifyTrust]
2132ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
2133ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
2134ecc.10ac: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll'
2135ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'uxtheme.dll'...
2136ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'uxtheme.dll' -> '\Device\HarddiskVolume4\Windows\System32\uxtheme.dll' [rcNtRedir=0xc0150008]
2137ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
2138ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
2139ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
2140ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
2141ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
2142ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
2143ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
2144ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
2145ecc.10ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox/VBoxDD.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
2146ecc.10ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDD.dll
2147ecc.10ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDDU.dll
2148ecc.10ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDD2.dll
2149ecc.10ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\IPHLPAPI.DLL
2150ecc.10ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\newdev.dll
2151ecc.10ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winnsi.dll [avoiding WinVerifyTrust]
2152ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
2153ecc.10ac: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\System32\devrtl.dll)
2154ecc.10ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\devrtl.dll
2155ecc.10ac: supR3HardenedDllNotificationCallback: load 00007ff8a4c50000 LB 0x001da000 C:\Windows\system32\SETUPAPI.dll [fFlags=0x0]
2156ecc.10ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\setupapi.dll
2157ecc.10ac: supR3HardenedDllNotificationCallback: load 00007ff899790000 LB 0x00016000 C:\Windows\SYSTEM32\devrtl.DLL [fFlags=0x0]
2158ecc.10ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\devrtl.dll [avoiding WinVerifyTrust]
2159ecc.10ac: supR3HardenedDllNotificationCallback: load 00007ff893df0000 LB 0x00056000 C:\Windows\SYSTEM32\newdev.dll [fFlags=0x0]
2160ecc.10ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\newdev.dll
2161ecc.10ac: supR3HardenedDllNotificationCallback: load 00007ff893bc0000 LB 0x00061000 C:\Program Files\Oracle\VirtualBox\VBoxDDU.dll [fFlags=0x0]
2162ecc.10ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDDU.dll
2163ecc.10ac: supR3HardenedDllNotificationCallback: load 00007ff892ea0000 LB 0x00035000 C:\Program Files\Oracle\VirtualBox\VBoxDD2.dll [fFlags=0x0]
2164ecc.10ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDD2.dll
2165ecc.10ac: supR3HardenedDllNotificationCallback: load 00007ff89ec70000 LB 0x0000a000 C:\Windows\SYSTEM32\WINNSI.DLL [fFlags=0x0]
2166ecc.10ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winnsi.dll [avoiding WinVerifyTrust]
2167ecc.10ac: supR3HardenedDllNotificationCallback: load 00007ff89e8d0000 LB 0x0002a000 C:\Windows\SYSTEM32\IPHLPAPI.DLL [fFlags=0x0]
2168ecc.10ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\IPHLPAPI.DLL
2169ecc.10ac: supR3HardenedDllNotificationCallback: load 00007ff87c710000 LB 0x008d2000 C:\Program Files\Oracle\VirtualBox\VBoxDD.DLL [fFlags=0x0]
2170ecc.10ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDD.dll
2171ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff87c710000 'C:\Program Files\Oracle\VirtualBox/VBoxDD.DLL'
2172ecc.10ac: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000c8c pwszName=\Device\HarddiskVolume4\Windows\System32\devrtl.dll
2173ecc.10ac: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000112a710
2174ecc.10ac: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000112a710
2175ecc.10ac: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=1BD420FD87C527DD7764DD8C12C3F1C9F0448C71
2176ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
2177ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
2178ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
2179ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
2180ecc.10ac: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_1966_for_KB3000850~31bf3856ad364e35~amd64~~6.3.1.8.cat'; file='\Device\HarddiskVolume4\Windows\System32\devrtl.dll'
2181ecc.10ac: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2182ecc.10ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\devrtl.dll'
2183ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
2184ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
2185ecc.10ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\winnsi.dll'
2186ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
2187ecc.10ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
2188ecc.10ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.amd64/VBoxHostWebcam.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
2189ecc.10ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
2190ecc.10ac: supR3HardenedDllNotificationCallback: load 00007ff8925d0000 LB 0x00033000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL [fFlags=0x0]
2191ecc.10ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
2192ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8925d0000 'C:\Program Files\Oracle\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.amd64/VBoxHostWebcam.DLL'
2193ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
2194ecc.10ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxC.dll
2195ecc.10ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox/VBoxC.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
2196ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff87aaa0000 'C:\Program Files\Oracle\VirtualBox/VBoxC.DLL'
2197ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
2198ecc.10ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDD2.dll
2199ecc.10ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox/VBoxDD2.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
2200ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff892ea0000 'C:\Program Files\Oracle\VirtualBox/VBoxDD2.DLL'
2201ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
2202ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
2203ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
2204ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
2205ecc.10ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.dll)WinVerifyTrust
2206ecc.10ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.dll
2207ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
2208ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
2209ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
2210ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
2211ecc.10ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.amd64/VBoxEhciR3.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
2212ecc.10ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.dll
2213ecc.10ac: supR3HardenedDllNotificationCallback: load 00007ff892300000 LB 0x00013000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.DLL [fFlags=0x0]
2214ecc.10ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.dll
2215ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff892300000 'C:\Program Files\Oracle\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.amd64/VBoxEhciR3.DLL'
2216ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
2217ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
2218ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
2219ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
2220ecc.10ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.dll)WinVerifyTrust
2221ecc.10ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.dll
2222ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
2223ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
2224ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
2225ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
2226ecc.10ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.amd64/VBoxUsbCardReaderR3.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
2227ecc.10ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.dll
2228ecc.10ac: supR3HardenedDllNotificationCallback: load 00007ff8922e0000 LB 0x00017000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.DLL [fFlags=0x0]
2229ecc.10ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.dll
2230ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8922e0000 'C:\Program Files\Oracle\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.amd64/VBoxUsbCardReaderR3.DLL'
2231ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
2232ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
2233ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
2234ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
2235ecc.10ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.dll)WinVerifyTrust
2236ecc.10ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.dll
2237ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
2238ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
2239ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
2240ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
2241ecc.10ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.amd64/VBoxUsbWebcamR3.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
2242ecc.10ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.dll
2243ecc.10ac: supR3HardenedDllNotificationCallback: load 00007ff8922c0000 LB 0x00019000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.DLL [fFlags=0x0]
2244ecc.10ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.dll
2245ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8922c0000 'C:\Program Files\Oracle\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.amd64/VBoxUsbWebcamR3.DLL'
2246ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
2247ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
2248ecc.1ae4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
2249ecc.1ae4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
2250ecc.1ae4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
2251ecc.1ae4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
2252ecc.1ae4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll)WinVerifyTrust
2253ecc.1ae4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll
2254ecc.1ae4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
2255ecc.1ae4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
2256ecc.1ae4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
2257ecc.1ae4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
2258ecc.1ae4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxVMM.dll
2259ecc.1ae4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
2260ecc.1ae4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
2261ecc.1ae4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
2262ecc.1ae4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll
2263ecc.1ae4: supR3HardenedDllNotificationCallback: load 00007ff8932d0000 LB 0x0000d000 C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL [fFlags=0x0]
2264ecc.1ae4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll
2265ecc.1ae4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8932d0000 'C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL'
2266ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
2267ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
2268ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
2269ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
2270ecc.10ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.dll)WinVerifyTrust
2271ecc.10ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.dll
2272ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
2273ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
2274ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
2275ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
2276ecc.10ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.amd64/VDPluginCrypt.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
2277ecc.10ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.dll
2278ecc.10ac: supR3HardenedDllNotificationCallback: load 00007ff896980000 LB 0x00009000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.DLL [fFlags=0x0]
2279ecc.10ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.dll
2280ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff896980000 'C:\Program Files\Oracle\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.amd64/VDPluginCrypt.DLL'
2281ecc.10ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\IPHLPAPI.DLL
2282ecc.10ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32/Iphlpapi.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
2283ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff89e8d0000 'C:\Windows\system32/Iphlpapi.dll'
2284ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'rpcrt4.dll'.
2285ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ws2_32.dll'.
2286ecc.10ac: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\System32\dhcpcsvc6.dll)
2287ecc.10ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\dhcpcsvc6.dll
2288ecc.10ac: supR3HardenedDllNotificationCallback: load 00007ff89a4f0000 LB 0x00016000 C:\Windows\SYSTEM32\dhcpcsvc6.DLL [fFlags=0x0]
2289ecc.10ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\dhcpcsvc6.dll [avoiding WinVerifyTrust]
2290ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rpcrt4.dll'.
2291ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ws2_32.dll'.
2292ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'nsi.dll'.
2293ecc.10ac: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\System32\dhcpcsvc.dll)
2294ecc.10ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\dhcpcsvc.dll
2295ecc.10ac: supR3HardenedDllNotificationCallback: load 00007ff89a5d0000 LB 0x0001a000 C:\Windows\SYSTEM32\dhcpcsvc.DLL [fFlags=0x0]
2296ecc.10ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\dhcpcsvc.dll [avoiding WinVerifyTrust]
2297ecc.10ac: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000e20 pwszName=\Device\HarddiskVolume4\Windows\System32\dhcpcsvc.dll
2298ecc.10ac: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000112a710
2299ecc.10ac: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000112a710
2300ecc.10ac: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=BA7A32ED884F605C3353300D1165178C01A252E7
2301ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
2302ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume4\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
2303ecc.10ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\nsi.dll [lacks WinVerifyTrust]
2304ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
2305ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
2306ecc.10ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ws2_32.dll
2307ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
2308ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
2309ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
2310ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
2311ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
2312ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
2313ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
2314ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
2315ecc.10ac: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_1995_for_KB3000850~31bf3856ad364e35~amd64~~6.3.1.8.cat'; file='\Device\HarddiskVolume4\Windows\System32\dhcpcsvc.dll'
2316ecc.10ac: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2317ecc.10ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\dhcpcsvc.dll'
2318ecc.10ac: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000e14 pwszName=\Device\HarddiskVolume4\Windows\System32\dhcpcsvc6.dll
2319ecc.10ac: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000112a710
2320ecc.10ac: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000112a710
2321ecc.10ac: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=852EBF87DB04C5286E131027705696EE75673482
2322ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
2323ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
2324ecc.10ac: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_1995_for_KB3000850~31bf3856ad364e35~amd64~~6.3.1.8.cat'; file='\Device\HarddiskVolume4\Windows\System32\dhcpcsvc6.dll'
2325ecc.10ac: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2326ecc.10ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\dhcpcsvc6.dll'
2327ecc.10ac: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000eb8 pwszName=\Device\HarddiskVolume4\Windows\System32\dsound.dll
2328ecc.10ac: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000112a710
2329ecc.10ac: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000112a710
2330ecc.10ac: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=DF2CE4B6EA46F5759902C86AAA15DD883AC6DD4E
2331ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
2332ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
2333ecc.10ac: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_779_for_KB3000850~31bf3856ad364e35~amd64~~6.3.1.8.cat'; file='\Device\HarddiskVolume4\Windows\System32\dsound.dll'
2334ecc.10ac: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2335ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
2336ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
2337ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
2338ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ole32.dll'.
2339ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'winmm.dll'.
2340ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'powrprof.dll'.
2341ecc.10ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\dsound.dll)WinVerifyTrust
2342ecc.10ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\dsound.dll
2343ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'powrprof.dll'...
2344ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'powrprof.dll' -> '\Device\HarddiskVolume4\Windows\System32\powrprof.dll' [rcNtRedir=0xc0150008]
2345ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
2346ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
2347ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
2348ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'rpcrt4.dll'.
2349ecc.10ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\powrprof.dll)WinVerifyTrust
2350ecc.10ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\powrprof.dll
2351ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
2352ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume4\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
2353ecc.10ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmm.dll
2354ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
2355ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
2356ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
2357ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
2358ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
2359ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
2360ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
2361ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
2362ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
2363ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
2364ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
2365ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
2366ecc.10ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
2367ecc.10ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\dsound.dll
2368ecc.10ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\powrprof.dll
2369ecc.10ac: supR3HardenedDllNotificationCallback: load 00007ff8a1f20000 LB 0x00046000 C:\Windows\System32\POWRPROF.dll [fFlags=0x0]
2370ecc.10ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\powrprof.dll
2371ecc.10ac: supR3HardenedDllNotificationCallback: load 00007ff883440000 LB 0x0009d000 C:\Windows\System32\dsound.dll [fFlags=0x0]
2372ecc.10ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\dsound.dll
2373ecc.10ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\dsound.dll
2374ecc.10ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
2375ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff883440000 'C:\Windows\System32\dsound.dll'
2376ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff883440000 'C:\Windows\System32\dsound.dll'
2377ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
2378ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
2379ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
2380ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'rpcrt4.dll'.
2381ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'devobj.dll'.
2382ecc.10ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\MMDevAPI.dll)WinVerifyTrust
2383ecc.10ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\MMDevAPI.dll
2384ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'devobj.dll'...
2385ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'devobj.dll' -> '\Device\HarddiskVolume4\Windows\System32\devobj.dll' [rcNtRedir=0xc0150008]
2386ecc.10ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\devobj.dll [redoing WinVerifyTrust]
2387ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
2388ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
2389ecc.10ac: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\devobj.dll'
2390ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
2391ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
2392ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
2393ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
2394ecc.10ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\MMDevApi.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
2395ecc.10ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\MMDevAPI.dll
2396ecc.10ac: supR3HardenedDllNotificationCallback: load 00007ff89f3b0000 LB 0x00070000 C:\Windows\System32\MMDevApi.dll [fFlags=0x0]
2397ecc.10ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\MMDevAPI.dll
2398ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff89f3b0000 'C:\Windows\System32\MMDevApi.dll'
2399ecc.10ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\MMDevAPI.dll
2400ecc.10ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\MMDEVAPI.DLL (Input=MMDEVAPI.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
2401ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff89f3b0000 'C:\Windows\system32\MMDEVAPI.DLL'
2402ecc.197c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
2403ecc.197c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll
2404ecc.197c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
2405ecc.197c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
2406ecc.197c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
2407ecc.197c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'rpcrt4.dll'.
2408ecc.197c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'oleaut32.dll'.
2409ecc.197c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #30 'mmdevapi.dll'.
2410ecc.197c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #31 'combase.dll'.
2411ecc.197c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\AudioSes.dll)WinVerifyTrust
2412ecc.197c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\AudioSes.dll
2413ecc.197c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
2414ecc.197c: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume4\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
2415ecc.197c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\combase.dll [redoing WinVerifyTrust]
2416ecc.197c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
2417ecc.197c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
2418ecc.197c: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\combase.dll'
2419ecc.197c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mmdevapi.dll'...
2420ecc.197c: supR3HardenedWinVerifyCacheProcessImportTodos: 'mmdevapi.dll' -> '\Device\HarddiskVolume4\Windows\System32\mmdevapi.dll' [rcNtRedir=0xc0150008]
2421ecc.197c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\MMDevAPI.dll
2422ecc.197c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
2423ecc.197c: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume4\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
2424ecc.197c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\oleaut32.dll
2425ecc.197c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
2426ecc.197c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
2427ecc.197c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
2428ecc.197c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
2429ecc.197c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\AUDIOSES.DLL (Input=AUDIOSES.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
2430ecc.197c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\AudioSes.dll
2431ecc.197c: supR3HardenedDllNotificationCallback: load 00007ff894e10000 LB 0x0007e000 C:\Windows\system32\AUDIOSES.DLL [fFlags=0x0]
2432ecc.197c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\AudioSes.dll
2433ecc.197c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff894e10000 'C:\Windows\system32\AUDIOSES.DLL'
2434ecc.10ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmm.dll
2435ecc.10ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\winmm.dll (Input=winmm.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
2436ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff89fe80000 'C:\Windows\system32\winmm.dll'
2437ecc.10ac: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000f24 pwszName=\Device\HarddiskVolume4\Windows\System32\wdmaud.drv
2438ecc.10ac: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000112a710
2439ecc.10ac: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000112a710
2440ecc.10ac: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=39D0975C289FEE943955B8CE81B02A0395FAA747
2441ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
2442ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
2443ecc.10ac: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_779_for_KB3000850~31bf3856ad364e35~amd64~~6.3.1.8.cat'; file='\Device\HarddiskVolume4\Windows\System32\wdmaud.drv'
2444ecc.10ac: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2445ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
2446ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'mmdevapi.dll'.
2447ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #19 'user32.dll'.
2448ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #20 'winmm.dll'.
2449ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #21 'ksuser.dll'.
2450ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #22 'avrt.dll'.
2451ecc.10ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\wdmaud.drv)WinVerifyTrust
2452ecc.10ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\wdmaud.drv
2453ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'avrt.dll'...
2454ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'avrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\avrt.dll' [rcNtRedir=0xc0150008]
2455ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
2456ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
2457ecc.10ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\avrt.dll)WinVerifyTrust
2458ecc.10ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\avrt.dll
2459ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ksuser.dll'...
2460ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'ksuser.dll' -> '\Device\HarddiskVolume4\Windows\System32\ksuser.dll' [rcNtRedir=0xc0150008]
2461ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
2462ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
2463ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
2464ecc.10ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\ksuser.dll)WinVerifyTrust
2465ecc.10ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\ksuser.dll
2466ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
2467ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume4\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
2468ecc.10ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmm.dll
2469ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
2470ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
2471ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mmdevapi.dll'...
2472ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'mmdevapi.dll' -> '\Device\HarddiskVolume4\Windows\System32\mmdevapi.dll' [rcNtRedir=0xc0150008]
2473ecc.10ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\MMDevAPI.dll
2474ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
2475ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
2476ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
2477ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
2478ecc.10ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
2479ecc.10ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wdmaud.drv
2480ecc.10ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ksuser.dll
2481ecc.10ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\avrt.dll
2482ecc.10ac: supR3HardenedDllNotificationCallback: load 00007ff89eca0000 LB 0x00008000 C:\Windows\SYSTEM32\ksuser.dll [fFlags=0x0]
2483ecc.10ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ksuser.dll
2484ecc.10ac: supR3HardenedDllNotificationCallback: load 00007ff89ec80000 LB 0x0000c000 C:\Windows\SYSTEM32\AVRT.dll [fFlags=0x0]
2485ecc.10ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\avrt.dll
2486ecc.10ac: supR3HardenedDllNotificationCallback: load 00007ff895770000 LB 0x0003e000 C:\Windows\system32\wdmaud.drv [fFlags=0x0]
2487ecc.10ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wdmaud.drv
2488ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff895770000 'C:\Windows\system32\wdmaud.drv'
2489ecc.10ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wdmaud.drv
2490ecc.10ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
2491ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff895770000 'C:\Windows\system32\wdmaud.drv'
2492ecc.10ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wdmaud.drv
2493ecc.10ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
2494ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff895770000 'C:\Windows\system32\wdmaud.drv'
2495ecc.10ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wdmaud.drv
2496ecc.10ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
2497ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff895770000 'C:\Windows\system32\wdmaud.drv'
2498ecc.10ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wdmaud.drv
2499ecc.10ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
2500ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff895770000 'C:\Windows\system32\wdmaud.drv'
2501ecc.10ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wdmaud.drv
2502ecc.10ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
2503ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff895770000 'C:\Windows\system32\wdmaud.drv'
2504ecc.10ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wdmaud.drv
2505ecc.10ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
2506ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff895770000 'C:\Windows\system32\wdmaud.drv'
2507ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff895770000 'C:\Windows\system32\wdmaud.drv'
2508ecc.10ac: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000f50 pwszName=\Device\HarddiskVolume4\Windows\System32\msacm32.drv
2509ecc.10ac: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000112a710
2510ecc.10ac: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000112a710
2511ecc.10ac: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=FC41C5E1A841A83249581F1B29E14A708B8981A9
2512ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
2513ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
2514ecc.10ac: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_779_for_KB3000850~31bf3856ad364e35~amd64~~6.3.1.8.cat'; file='\Device\HarddiskVolume4\Windows\System32\msacm32.drv'
2515ecc.10ac: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2516ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
2517ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
2518ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'winmm.dll'.
2519ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msacm32.dll'.
2520ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'mmdevapi.dll'.
2521ecc.10ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\msacm32.drv)WinVerifyTrust
2522ecc.10ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\msacm32.drv
2523ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mmdevapi.dll'...
2524ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'mmdevapi.dll' -> '\Device\HarddiskVolume4\Windows\System32\mmdevapi.dll' [rcNtRedir=0xc0150008]
2525ecc.10ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\MMDevAPI.dll
2526ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msacm32.dll'...
2527ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msacm32.dll' -> '\Device\HarddiskVolume4\Windows\System32\msacm32.dll' [rcNtRedir=0xc0150008]
2528ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
2529ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
2530ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
2531ecc.10ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\msacm32.dll)WinVerifyTrust
2532ecc.10ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\msacm32.dll
2533ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
2534ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume4\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
2535ecc.10ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmm.dll
2536ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
2537ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
2538ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
2539ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
2540ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
2541ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
2542ecc.10ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
2543ecc.10ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msacm32.drv
2544ecc.10ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msacm32.dll
2545ecc.10ac: supR3HardenedDllNotificationCallback: load 00007ff896780000 LB 0x0001c000 C:\Windows\SYSTEM32\MSACM32.dll [fFlags=0x0]
2546ecc.10ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msacm32.dll
2547ecc.10ac: supR3HardenedDllNotificationCallback: load 00007ff89b2b0000 LB 0x0000b000 C:\Windows\system32\msacm32.drv [fFlags=0x0]
2548ecc.10ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msacm32.drv
2549ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff89b2b0000 'C:\Windows\system32\msacm32.drv'
2550ecc.10ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msacm32.drv
2551ecc.10ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
2552ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff89b2b0000 'C:\Windows\system32\msacm32.drv'
2553ecc.10ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msacm32.drv
2554ecc.10ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
2555ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff89b2b0000 'C:\Windows\system32\msacm32.drv'
2556ecc.10ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msacm32.drv
2557ecc.10ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
2558ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff89b2b0000 'C:\Windows\system32\msacm32.drv'
2559ecc.10ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msacm32.drv
2560ecc.10ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
2561ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff89b2b0000 'C:\Windows\system32\msacm32.drv'
2562ecc.10ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msacm32.drv
2563ecc.10ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
2564ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff89b2b0000 'C:\Windows\system32\msacm32.drv'
2565ecc.10ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msacm32.drv
2566ecc.10ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
2567ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff89b2b0000 'C:\Windows\system32\msacm32.drv'
2568ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff89b2b0000 'C:\Windows\system32\msacm32.drv'
2569ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff89b2b0000 'C:\Windows\system32\msacm32.drv'
2570ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff89b2b0000 'C:\Windows\system32\msacm32.drv'
2571ecc.10ac: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000f54 pwszName=\Device\HarddiskVolume4\Windows\System32\midimap.dll
2572ecc.10ac: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000112a710
2573ecc.10ac: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000112a710
2574ecc.10ac: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=A0F2984C30BFC77017EA7B9BF6F656853E29D991
2575ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
2576ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
2577ecc.10ac: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_779_for_KB3000850~31bf3856ad364e35~amd64~~6.3.1.8.cat'; file='\Device\HarddiskVolume4\Windows\System32\midimap.dll'
2578ecc.10ac: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2579ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
2580ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
2581ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'winmm.dll'.
2582ecc.10ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\midimap.dll)WinVerifyTrust
2583ecc.10ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\midimap.dll
2584ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
2585ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume4\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
2586ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
2587ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
2588ecc.10ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll
2589ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
2590ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
2591ecc.10ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
2592ecc.10ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\midimap.dll
2593ecc.10ac: supR3HardenedDllNotificationCallback: load 00007ff8990d0000 LB 0x0000a000 C:\Windows\system32\midimap.dll [fFlags=0x0]
2594ecc.10ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\midimap.dll
2595ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8990d0000 'C:\Windows\system32\midimap.dll'
2596ecc.10ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\midimap.dll
2597ecc.10ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
2598ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8990d0000 'C:\Windows\system32\midimap.dll'
2599ecc.10ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\midimap.dll
2600ecc.10ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
2601ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8990d0000 'C:\Windows\system32\midimap.dll'
2602ecc.10ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\midimap.dll
2603ecc.10ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
2604ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8990d0000 'C:\Windows\system32\midimap.dll'
2605ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff89fe80000 'C:\Windows\system32\winmm.dll'
2606ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff89fe80000 'C:\Windows\system32\winmm.dll'
2607ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff89fe80000 'C:\Windows\system32\winmm.dll'
2608ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff89fe80000 'C:\Windows\system32\winmm.dll'
2609ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff89fe80000 'C:\Windows\system32\winmm.dll'
2610ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff89fe80000 'C:\Windows\system32\winmm.dll'
2611ecc.10ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmm.dll
2612ecc.10ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\winmm.dll (Input=winmm.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
2613ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff89fe80000 'C:\Windows\system32\winmm.dll'
2614ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff89fe80000 'C:\Windows\system32\winmm.dll'
2615ecc.10ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\kernel32.dll
2616ecc.10ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32/kernel32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
2617ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a4b10000 'C:\Windows\system32/kernel32.dll'
2618ecc.10ac: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000001030 pwszName=\Device\HarddiskVolume4\Windows\System32\mswsock.dll
2619ecc.10ac: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000112a710
2620ecc.10ac: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000112a710
2621ecc.10ac: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F5D0CFD7C59A53ECEE5E548E409683E758757285
2622ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
2623ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
2624ecc.10ac: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_1995_for_KB3000850~31bf3856ad364e35~amd64~~6.3.1.8.cat'; file='\Device\HarddiskVolume4\Windows\System32\mswsock.dll'
2625ecc.10ac: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2626ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rpcrt4.dll'.
2627ecc.10ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ws2_32.dll'.
2628ecc.10ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\mswsock.dll)WinVerifyTrust
2629ecc.10ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\mswsock.dll
2630ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
2631ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
2632ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
2633ecc.10ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
2634ecc.10ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\mswsock.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
2635ecc.10ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\mswsock.dll
2636ecc.10ac: supR3HardenedDllNotificationCallback: load 00007ff8a1790000 LB 0x00059000 C:\Windows\system32\mswsock.dll [fFlags=0x0]
2637ecc.10ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\mswsock.dll
2638ecc.10ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1790000 'C:\Windows\system32\mswsock.dll'
2639ecc.1978: '\Device\HarddiskVolume4\Windows\System32\tzres.dll' has no imports
2640ecc.1978: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\System32\tzres.dll)
2641ecc.1978: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\tzres.dll
2642ecc.1978: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\tzres.dll [avoiding WinVerifyTrust]
2643ecc.1074: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000ad0 pwszName=\Device\HarddiskVolume4\Windows\System32\tzres.dll
2644ecc.1074: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000112a710
2645ecc.1074: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000112a710
2646ecc.1074: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2C2912B1AF73A6796732D1488D75007F742A3299
2647ecc.1074: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
2648ecc.1074: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
2649ecc.1074: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_1966_for_KB3000850~31bf3856ad364e35~amd64~~6.3.1.8.cat'; file='\Device\HarddiskVolume4\Windows\System32\tzres.dll'
2650ecc.1074: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2651ecc.1074: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\tzres.dll'
2652ecc.1074: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\avrt.dll
2653ecc.1074: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\avrt.dll (Input=avrt.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
2654ecc.1074: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff89ec80000 'C:\Windows\system32\avrt.dll'
2655ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000770 pwszName=\Device\HarddiskVolume4\Windows\System32\mscms.dll
2656ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000112a710
2657ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000112a710
2658ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=C01A2E8CE3347A322BF0830A5BC147EBA8BAD06F
2659ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
2660ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
2661ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_1529_for_KB3000850~31bf3856ad364e35~amd64~~6.3.1.8.cat'; file='\Device\HarddiskVolume4\Windows\System32\mscms.dll'
2662ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2663ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
2664ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'userenv.dll'.
2665ecc.e58: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\mscms.dll)WinVerifyTrust
2666ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\mscms.dll
2667ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'userenv.dll'...
2668ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'userenv.dll' -> '\Device\HarddiskVolume4\Windows\System32\userenv.dll' [rcNtRedir=0xc0150008]
2669ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\userenv.dll
2670ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
2671ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
2672ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\mscms.dll (Input=mscms.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
2673ecc.e58: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\mscms.dll
2674ecc.e58: supR3HardenedDllNotificationCallback: load 00007ff8a00c0000 LB 0x00092000 C:\Windows\system32\mscms.dll [fFlags=0x0]
2675ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\mscms.dll
2676ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a00c0000 'C:\Windows\system32\mscms.dll'
2677ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000010a4 pwszName=\Device\HarddiskVolume4\Windows\System32\icm32.dll
2678ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000112a710
2679ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000112a710
2680ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=47D46A3D26A83E75181F440594F6DC145125C84E
2681ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a1410000 'C:\Windows\system32\rsaenh.dll'
2682ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff8a2100000 'C:\Windows\system32\crypt32.dll'
2683ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_1529_for_KB3000850~31bf3856ad364e35~amd64~~6.3.1.8.cat'; file='\Device\HarddiskVolume4\Windows\System32\icm32.dll'
2684ecc.e58: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2685ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
2686ecc.e58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'mscms.dll'.
2687ecc.e58: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\icm32.dll)WinVerifyTrust
2688ecc.e58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\icm32.dll
2689ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mscms.dll'...
2690ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'mscms.dll' -> '\Device\HarddiskVolume4\Windows\System32\mscms.dll' [rcNtRedir=0xc0150008]
2691ecc.e58: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\mscms.dll
2692ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
2693ecc.e58: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
2694ecc.e58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\icm32.dll (Input=icm32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
2695ecc.e58: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\icm32.dll
2696ecc.e58: supR3HardenedDllNotificationCallback: load 00007ff87d970000 LB 0x00041000 C:\Windows\system32\icm32.dll [fFlags=0x0]
2697ecc.e58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\icm32.dll
2698ecc.e58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff87d970000 'C:\Windows\system32\icm32.dll'

© 2025 Oracle Support Privacy / Do Not Sell My Info Terms of Use Trademark Policy Automated Access Etiquette