VirtualBox

Ticket #14774: VBoxHardening.2.log

File VBoxHardening.2.log, 330.3 KB (added by GoodGodd, 9 years ago)
Line 
1d88.d8c: Log file opened: 5.0.10r104061 g_hStartupLog=0000000000000014 g_uNtVerCombined=0x611db110
2d88.d8c: \SystemRoot\System32\ntdll.dll:
3d88.d8c: CreationTime: 2015-06-30T18:24:53.606504900Z
4d88.d8c: LastWriteTime: 2015-05-25T18:21:21.289963400Z
5d88.d8c: ChangeTime: 2015-06-30T22:16:12.090281900Z
6d88.d8c: FileAttributes: 0x20
7d88.d8c: Size: 0x1a61c0
8d88.d8c: NT Headers: 0xe0
9d88.d8c: Timestamp: 0x556366f2
10d88.d8c: Machine: 0x8664 - amd64
11d88.d8c: Timestamp: 0x556366f2
12d88.d8c: Image Version: 6.1
13d88.d8c: SizeOfImage: 0x1a9000 (1740800)
14d88.d8c: Resource Dir: 0x14d000 LB 0x5a028
15d88.d8c: ProductName: Microsoft® Windows® Operating System
16d88.d8c: ProductVersion: 6.1.7601.18869
17d88.d8c: FileVersion: 6.1.7601.18869 (win7sp1_gdr.150525-0603)
18d88.d8c: FileDescription: NT Layer DLL
19d88.d8c: \SystemRoot\System32\kernel32.dll:
20d88.d8c: CreationTime: 2015-06-30T18:24:53.107304100Z
21d88.d8c: LastWriteTime: 2015-05-25T18:19:02.585000000Z
22d88.d8c: ChangeTime: 2015-06-30T22:16:12.324282300Z
23d88.d8c: FileAttributes: 0x20
24d88.d8c: Size: 0x11be00
25d88.d8c: NT Headers: 0xe8
26d88.d8c: Timestamp: 0x556366fc
27d88.d8c: Machine: 0x8664 - amd64
28d88.d8c: Timestamp: 0x556366fc
29d88.d8c: Image Version: 6.1
30d88.d8c: SizeOfImage: 0x11f000 (1175552)
31d88.d8c: Resource Dir: 0x116000 LB 0x528
32d88.d8c: ProductName: Microsoft® Windows® Operating System
33d88.d8c: ProductVersion: 6.1.7601.18869
34d88.d8c: FileVersion: 6.1.7601.18869 (win7sp1_gdr.150525-0603)
35d88.d8c: FileDescription: Windows NT BASE API Client DLL
36d88.d8c: \SystemRoot\System32\KernelBase.dll:
37d88.d8c: CreationTime: 2015-06-30T18:24:53.060504000Z
38d88.d8c: LastWriteTime: 2015-05-25T18:19:02.585000000Z
39d88.d8c: ChangeTime: 2015-06-30T22:16:12.324282300Z
40d88.d8c: FileAttributes: 0x20
41d88.d8c: Size: 0x67c00
42d88.d8c: NT Headers: 0xe8
43d88.d8c: Timestamp: 0x556366fd
44d88.d8c: Machine: 0x8664 - amd64
45d88.d8c: Timestamp: 0x556366fd
46d88.d8c: Image Version: 6.1
47d88.d8c: SizeOfImage: 0x6c000 (442368)
48d88.d8c: Resource Dir: 0x6a000 LB 0x530
49d88.d8c: ProductName: Microsoft® Windows® Operating System
50d88.d8c: ProductVersion: 6.1.7601.18869
51d88.d8c: FileVersion: 6.1.7601.18869 (win7sp1_gdr.150525-0603)
52d88.d8c: FileDescription: Windows NT BASE API Client DLL
53d88.d8c: \SystemRoot\System32\apisetschema.dll:
54d88.d8c: CreationTime: 2015-06-30T18:24:52.124502300Z
55d88.d8c: LastWriteTime: 2015-05-25T18:11:40.254000000Z
56d88.d8c: ChangeTime: 2015-06-30T22:16:12.074681900Z
57d88.d8c: FileAttributes: 0x20
58d88.d8c: Size: 0x1a00
59d88.d8c: NT Headers: 0xc0
60d88.d8c: Timestamp: 0x55636622
61d88.d8c: Machine: 0x8664 - amd64
62d88.d8c: Timestamp: 0x55636622
63d88.d8c: Image Version: 6.1
64d88.d8c: SizeOfImage: 0x50000 (327680)
65d88.d8c: Resource Dir: 0x30000 LB 0x3f8
66d88.d8c: ProductName: Microsoft® Windows® Operating System
67d88.d8c: ProductVersion: 6.1.7601.18869
68d88.d8c: FileVersion: 6.1.7601.18869 (win7sp1_gdr.150525-0603)
69d88.d8c: FileDescription: ApiSet Schema DLL
70d88.d8c: supR3HardenedWinFindAdversaries: 0x80
71d88.d8c: \SystemRoot\System32\drivers\MBAMSwissArmy.sys:
72d88.d8c: CreationTime: 2015-07-18T23:42:46.446818300Z
73d88.d8c: LastWriteTime: 2015-07-27T17:41:10.541992700Z
74d88.d8c: ChangeTime: 2015-07-27T17:41:10.541992700Z
75d88.d8c: FileAttributes: 0x20
76d88.d8c: Size: 0x1bcd8
77d88.d8c: NT Headers: 0xe8
78d88.d8c: Timestamp: 0x552c190f
79d88.d8c: Machine: 0x8664 - amd64
80d88.d8c: Timestamp: 0x552c190f
81d88.d8c: Image Version: 6.1
82d88.d8c: SizeOfImage: 0x21000 (135168)
83d88.d8c: Resource Dir: 0x1f000 LB 0x3f0
84d88.d8c: ProductName: Malwarebytes Anti-Malware
85d88.d8c: ProductVersion: 0.2.22.0
86d88.d8c: FileVersion: 0.2.22.0
87d88.d8c: FileDescription: Malwarebytes Anti-Malware
88d88.d8c: \SystemRoot\System32\drivers\mwac.sys:
89d88.d8c: CreationTime: 2015-07-18T23:42:36.308030900Z
90d88.d8c: LastWriteTime: 2015-06-18T08:48:04.000000000Z
91d88.d8c: ChangeTime: 2015-07-18T23:43:21.166227100Z
92d88.d8c: FileAttributes: 0x20
93d88.d8c: Size: 0xf8d8
94d88.d8c: NT Headers: 0xf8
95d88.d8c: Timestamp: 0x53a0f42a
96d88.d8c: Machine: 0x8664 - amd64
97d88.d8c: Timestamp: 0x53a0f42a
98d88.d8c: Image Version: 6.2
99d88.d8c: SizeOfImage: 0x12000 (73728)
100d88.d8c: Resource Dir: 0x10000 LB 0x3e0
101d88.d8c: ProductName: Malwarebytes Web Access Control
102d88.d8c: ProductVersion: 1.0.6.0
103d88.d8c: FileVersion: 1.0.6.0
104d88.d8c: FileDescription: Malwarebytes Web Access Control
105d88.d8c: \SystemRoot\System32\drivers\mbamchameleon.sys:
106d88.d8c: CreationTime: 2015-07-18T23:42:36.315031800Z
107d88.d8c: LastWriteTime: 2015-06-18T08:47:54.000000000Z
108d88.d8c: ChangeTime: 2015-07-18T23:43:21.178228700Z
109d88.d8c: FileAttributes: 0x20
110d88.d8c: Size: 0x1aad8
111d88.d8c: NT Headers: 0xd8
112d88.d8c: Timestamp: 0x554cf757
113d88.d8c: Machine: 0x8664 - amd64
114d88.d8c: Timestamp: 0x554cf757
115d88.d8c: Image Version: 6.1
116d88.d8c: SizeOfImage: 0x1e000 (122880)
117d88.d8c: Resource Dir: 0x1c000 LB 0xbd8
118d88.d8c: ProductName: Malwarebytes Chameleon
119d88.d8c: ProductVersion: 1.1.20.0
120d88.d8c: FileVersion: 1.1.20.0
121d88.d8c: FileDescription: Malwarebytes Chameleon Protection Driver
122d88.d8c: \SystemRoot\System32\drivers\mbam.sys:
123d88.d8c: CreationTime: 2015-07-18T23:42:36.304030400Z
124d88.d8c: LastWriteTime: 2015-06-18T08:47:50.000000000Z
125d88.d8c: ChangeTime: 2015-07-18T23:43:21.159226300Z
126d88.d8c: FileAttributes: 0x20
127d88.d8c: Size: 0x64d8
128d88.d8c: NT Headers: 0xd8
129d88.d8c: Timestamp: 0x540754e1
130d88.d8c: Machine: 0x8664 - amd64
131d88.d8c: Timestamp: 0x540754e1
132d88.d8c: Image Version: 6.1
133d88.d8c: SizeOfImage: 0xa000 (40960)
134d88.d8c: Resource Dir: 0x8000 LB 0x3d0
135d88.d8c: ProductName: Malwarebytes Anti-Malware
136d88.d8c: ProductVersion: 0.1.15.0
137d88.d8c: FileVersion: 0.1.15.0
138d88.d8c: FileDescription: Malwarebytes Anti-Malware
139d88.d8c: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
140d88.d8c: Calling main()
141d88.d8c: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
142d88.d8c: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
143d88.d8c: SUPR3HardenedMain: Respawn #1
144d88.d8c: System32: \Device\HarddiskVolume2\Windows\System32
145d88.d8c: WinSxS: \Device\HarddiskVolume2\Windows\winsxs
146d88.d8c: KnownDllPath: C:\Windows\system32
147d88.d8c: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
148d88.d8c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe)
149d88.d8c: supR3HardNtEnableThreadCreation:
150d88.d8c: supR3HardNtDisableThreadCreation: pvLdrInitThunk=000000007784b780 pvNtTerminateThread=000000007786e0e0
151d88.d8c: supR3HardenedWinDoReSpawn(1): New child d90.d94 [kernel32].
152d88.d8c: supR3HardNtChildGatherData: PebBaseAddress=000007fffffd4000 cbPeb=0x380
153d88.d8c: supR3HardNtPuChFindNtdll: uNtDllParentAddr=0000000077820000 uNtDllChildAddr=0000000077820000
154d88.d8c: supR3HardenedWinSetupChildInit: uLdrInitThunk=000000007784b780
155d88.d8c: supR3HardenedWinSetupChildInit: Start child.
156d88.d8c: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
157d88.d8c: supR3HardNtChildPurify: Startup delay kludge #1/0: 515 ms, 33 sleeps
158d88.d8c: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
159d88.d8c: *0000000000000000-fffffffffffeffff 0x0001/0x0000 0x0000000
160d88.d8c: *0000000000010000-fffffffffffeffff 0x0004/0x0004 0x0020000
161d88.d8c: *0000000000030000-000000000002bfff 0x0002/0x0002 0x0040000
162d88.d8c: 0000000000034000-0000000000027fff 0x0001/0x0000 0x0000000
163d88.d8c: *0000000000040000-000000000003efff 0x0004/0x0004 0x0020000
164d88.d8c: 0000000000041000-0000000000001fff 0x0001/0x0000 0x0000000
165d88.d8c: *0000000000080000-fffffffffff83fff 0x0000/0x0004 0x0020000
166d88.d8c: 000000000017c000-0000000000178fff 0x0104/0x0004 0x0020000
167d88.d8c: 000000000017f000-000000000017dfff 0x0004/0x0004 0x0020000
168d88.d8c: 0000000000180000-ffffffff88adffff 0x0001/0x0000 0x0000000
169d88.d8c: *0000000077820000-0000000077820fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
170d88.d8c: 0000000077821000-000000007791efff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
171d88.d8c: 000000007791f000-000000007794dfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
172d88.d8c: 000000007794e000-0000000077955fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
173d88.d8c: 0000000077956000-0000000077956fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
174d88.d8c: 0000000077957000-0000000077959fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
175d88.d8c: 000000007795a000-00000000779c8fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
176d88.d8c: 00000000779c9000-00000000703b1fff 0x0001/0x0000 0x0000000
177d88.d8c: *000000007efe0000-000000007dfdffff 0x0000/0x0002 0x0020000
178d88.d8c: *000000007ffe0000-000000007ffdefff 0x0002/0x0002 0x0020000
179d88.d8c: 000000007ffe1000-000000007ffd1fff 0x0000/0x0002 0x0020000
180d88.d8c: 000000007fff0000-ffffffffc045ffff 0x0001/0x0000 0x0000000
181d88.d8c: *000000013fb80000-000000013fb80fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
182d88.d8c: 000000013fb81000-000000013fc07fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
183d88.d8c: 000000013fc08000-000000013fc08fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
184d88.d8c: 000000013fc09000-000000013fc53fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
185d88.d8c: 000000013fc54000-000000013fc54fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
186d88.d8c: 000000013fc55000-000000013fc55fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
187d88.d8c: 000000013fc56000-000000013fc5afff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
188d88.d8c: 000000013fc5b000-000000013fc5bfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
189d88.d8c: 000000013fc5c000-000000013fc5cfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
190d88.d8c: 000000013fc5d000-000000013fc60fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
191d88.d8c: 000000013fc61000-000000013fcabfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
192d88.d8c: 000000013fcac000-fffff8037fe17fff 0x0001/0x0000 0x0000000
193d88.d8c: *000007feffb40000-000007feffb40fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\apisetschema.dll
194d88.d8c: 000007feffb41000-000007fdff6d1fff 0x0001/0x0000 0x0000000
195d88.d8c: *000007fffffb0000-000007fffff8cfff 0x0002/0x0002 0x0040000
196d88.d8c: 000007fffffd3000-000007fffffd1fff 0x0001/0x0000 0x0000000
197d88.d8c: *000007fffffd4000-000007fffffd2fff 0x0004/0x0004 0x0020000
198d88.d8c: 000007fffffd5000-000007fffffcbfff 0x0001/0x0000 0x0000000
199d88.d8c: *000007fffffde000-000007fffffdbfff 0x0004/0x0004 0x0020000
200d88.d8c: *000007fffffe0000-000007fffffcffff 0x0001/0x0002 0x0020000
201d88.d8c: apisetschema.dll: timestamp 0x55636622 (rc=VINF_SUCCESS)
202d88.d8c: VirtualBox.exe: timestamp 0x564221d3 (rc=VINF_SUCCESS)
203d88.d8c: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
204d88.d8c: '\Device\HarddiskVolume2\Windows\System32\apisetschema.dll' has no imports
205d88.d8c: '\Device\HarddiskVolume2\Windows\System32\ntdll.dll' has no imports
206d88.d8c: supR3HardNtChildPurify: Done after 546 ms and 0 fixes (loop #0).
207d90.d94: Log file opened: 5.0.10r104061 g_hStartupLog=0000000000000004 g_uNtVerCombined=0x611db110
208d90.d94: supR3HardenedVmProcessInit: uNtDllAddr=0000000077820000
209d90.d94: ntdll.dll: timestamp 0x556366f2 (rc=VINF_SUCCESS)
210d90.d94: New simple heap: #1 0000000000280000 LB 0x400000 (for 1740800 allocation)
211d88.d8c: supR3HardNtEnableThreadCreation:
212d90.d94: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
213d90.d94: System32: \Device\HarddiskVolume2\Windows\System32
214d90.d94: WinSxS: \Device\HarddiskVolume2\Windows\winsxs
215d90.d94: KnownDllPath: C:\Windows\system32
216d90.d94: supR3HardenedVmProcessInit: Opening vboxdrv stub...
217d90.d94: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
218d90.d94: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
219d90.d94: Registered Dll notification callback with NTDLL.
220d90.d94: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\kernel32.dll)
221d90.d94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\kernel32.dll
222d90.d94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
223d90.d94: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
224d90.d94: supR3HardenedDllNotificationCallback: load 0000000077700000 LB 0x0011f000 C:\Windows\system32\kernel32.dll [fFlags=0x0]
225d90.d94: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
226d90.d94: supR3HardenedDllNotificationCallback: load 000007fefd630000 LB 0x0006c000 C:\Windows\system32\KERNELBASE.dll [fFlags=0x0]
227d90.d94: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\KernelBase.dll)
228d90.d94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\KernelBase.dll
229d90.d94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077700000 'C:\Windows\system32\kernel32.dll'
230d90.d94: supR3HardNtDisableThreadCreation: pvLdrInitThunk=000000007784b780 pvNtTerminateThread=000000007786e0e0
231d88.d8c: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 16 ms.
232d90.d94: \SystemRoot\System32\ntdll.dll:
233d90.d94: CreationTime: 2015-06-30T18:24:53.606504900Z
234d90.d94: LastWriteTime: 2015-05-25T18:21:21.289963400Z
235d90.d94: ChangeTime: 2015-06-30T22:16:12.090281900Z
236d90.d94: FileAttributes: 0x20
237d90.d94: Size: 0x1a61c0
238d90.d94: NT Headers: 0xe0
239d90.d94: Timestamp: 0x556366f2
240d90.d94: Machine: 0x8664 - amd64
241d90.d94: Timestamp: 0x556366f2
242d90.d94: Image Version: 6.1
243d90.d94: SizeOfImage: 0x1a9000 (1740800)
244d90.d94: Resource Dir: 0x14d000 LB 0x5a028
245d90.d94: ProductName: Microsoft® Windows® Operating System
246d90.d94: ProductVersion: 6.1.7601.18869
247d90.d94: FileVersion: 6.1.7601.18869 (win7sp1_gdr.150525-0603)
248d90.d94: FileDescription: NT Layer DLL
249d90.d94: \SystemRoot\System32\kernel32.dll:
250d90.d94: CreationTime: 2015-06-30T18:24:53.107304100Z
251d90.d94: LastWriteTime: 2015-05-25T18:19:02.585000000Z
252d90.d94: ChangeTime: 2015-06-30T22:16:12.324282300Z
253d90.d94: FileAttributes: 0x20
254d90.d94: Size: 0x11be00
255d90.d94: NT Headers: 0xe8
256d90.d94: Timestamp: 0x556366fc
257d90.d94: Machine: 0x8664 - amd64
258d90.d94: Timestamp: 0x556366fc
259d90.d94: Image Version: 6.1
260d90.d94: SizeOfImage: 0x11f000 (1175552)
261d90.d94: Resource Dir: 0x116000 LB 0x528
262d90.d94: ProductName: Microsoft® Windows® Operating System
263d90.d94: ProductVersion: 6.1.7601.18869
264d90.d94: FileVersion: 6.1.7601.18869 (win7sp1_gdr.150525-0603)
265d90.d94: FileDescription: Windows NT BASE API Client DLL
266d90.d94: \SystemRoot\System32\KernelBase.dll:
267d90.d94: CreationTime: 2015-06-30T18:24:53.060504000Z
268d90.d94: LastWriteTime: 2015-05-25T18:19:02.585000000Z
269d90.d94: ChangeTime: 2015-06-30T22:16:12.324282300Z
270d90.d94: FileAttributes: 0x20
271d90.d94: Size: 0x67c00
272d90.d94: NT Headers: 0xe8
273d90.d94: Timestamp: 0x556366fd
274d90.d94: Machine: 0x8664 - amd64
275d90.d94: Timestamp: 0x556366fd
276d90.d94: Image Version: 6.1
277d90.d94: SizeOfImage: 0x6c000 (442368)
278d90.d94: Resource Dir: 0x6a000 LB 0x530
279d90.d94: ProductName: Microsoft® Windows® Operating System
280d90.d94: ProductVersion: 6.1.7601.18869
281d90.d94: FileVersion: 6.1.7601.18869 (win7sp1_gdr.150525-0603)
282d90.d94: FileDescription: Windows NT BASE API Client DLL
283d90.d94: \SystemRoot\System32\apisetschema.dll:
284d90.d94: CreationTime: 2015-06-30T18:24:52.124502300Z
285d90.d94: LastWriteTime: 2015-05-25T18:11:40.254000000Z
286d90.d94: ChangeTime: 2015-06-30T22:16:12.074681900Z
287d90.d94: FileAttributes: 0x20
288d90.d94: Size: 0x1a00
289d90.d94: NT Headers: 0xc0
290d90.d94: Timestamp: 0x55636622
291d90.d94: Machine: 0x8664 - amd64
292d90.d94: Timestamp: 0x55636622
293d90.d94: Image Version: 6.1
294d90.d94: SizeOfImage: 0x50000 (327680)
295d90.d94: Resource Dir: 0x30000 LB 0x3f8
296d90.d94: ProductName: Microsoft® Windows® Operating System
297d90.d94: ProductVersion: 6.1.7601.18869
298d90.d94: FileVersion: 6.1.7601.18869 (win7sp1_gdr.150525-0603)
299d90.d94: FileDescription: ApiSet Schema DLL
300d90.d94: supR3HardenedWinFindAdversaries: 0x80
301d90.d94: \SystemRoot\System32\drivers\MBAMSwissArmy.sys:
302d90.d94: CreationTime: 2015-07-18T23:42:46.446818300Z
303d90.d94: LastWriteTime: 2015-07-27T17:41:10.541992700Z
304d90.d94: ChangeTime: 2015-07-27T17:41:10.541992700Z
305d90.d94: FileAttributes: 0x20
306d90.d94: Size: 0x1bcd8
307d90.d94: NT Headers: 0xe8
308d90.d94: Timestamp: 0x552c190f
309d90.d94: Machine: 0x8664 - amd64
310d90.d94: Timestamp: 0x552c190f
311d90.d94: Image Version: 6.1
312d90.d94: SizeOfImage: 0x21000 (135168)
313d90.d94: Resource Dir: 0x1f000 LB 0x3f0
314d90.d94: ProductName: Malwarebytes Anti-Malware
315d90.d94: ProductVersion: 0.2.22.0
316d90.d94: FileVersion: 0.2.22.0
317d90.d94: FileDescription: Malwarebytes Anti-Malware
318d90.d94: \SystemRoot\System32\drivers\mwac.sys:
319d90.d94: CreationTime: 2015-07-18T23:42:36.308030900Z
320d90.d94: LastWriteTime: 2015-06-18T08:48:04.000000000Z
321d90.d94: ChangeTime: 2015-07-18T23:43:21.166227100Z
322d90.d94: FileAttributes: 0x20
323d90.d94: Size: 0xf8d8
324d90.d94: NT Headers: 0xf8
325d90.d94: Timestamp: 0x53a0f42a
326d90.d94: Machine: 0x8664 - amd64
327d90.d94: Timestamp: 0x53a0f42a
328d90.d94: Image Version: 6.2
329d90.d94: SizeOfImage: 0x12000 (73728)
330d90.d94: Resource Dir: 0x10000 LB 0x3e0
331d90.d94: ProductName: Malwarebytes Web Access Control
332d90.d94: ProductVersion: 1.0.6.0
333d90.d94: FileVersion: 1.0.6.0
334d90.d94: FileDescription: Malwarebytes Web Access Control
335d90.d94: \SystemRoot\System32\drivers\mbamchameleon.sys:
336d90.d94: CreationTime: 2015-07-18T23:42:36.315031800Z
337d90.d94: LastWriteTime: 2015-06-18T08:47:54.000000000Z
338d90.d94: ChangeTime: 2015-07-18T23:43:21.178228700Z
339d90.d94: FileAttributes: 0x20
340d90.d94: Size: 0x1aad8
341d90.d94: NT Headers: 0xd8
342d90.d94: Timestamp: 0x554cf757
343d90.d94: Machine: 0x8664 - amd64
344d90.d94: Timestamp: 0x554cf757
345d90.d94: Image Version: 6.1
346d90.d94: SizeOfImage: 0x1e000 (122880)
347d90.d94: Resource Dir: 0x1c000 LB 0xbd8
348d90.d94: ProductName: Malwarebytes Chameleon
349d90.d94: ProductVersion: 1.1.20.0
350d90.d94: FileVersion: 1.1.20.0
351d90.d94: FileDescription: Malwarebytes Chameleon Protection Driver
352d90.d94: \SystemRoot\System32\drivers\mbam.sys:
353d90.d94: CreationTime: 2015-07-18T23:42:36.304030400Z
354d90.d94: LastWriteTime: 2015-06-18T08:47:50.000000000Z
355d90.d94: ChangeTime: 2015-07-18T23:43:21.159226300Z
356d90.d94: FileAttributes: 0x20
357d90.d94: Size: 0x64d8
358d90.d94: NT Headers: 0xd8
359d90.d94: Timestamp: 0x540754e1
360d90.d94: Machine: 0x8664 - amd64
361d90.d94: Timestamp: 0x540754e1
362d90.d94: Image Version: 6.1
363d90.d94: SizeOfImage: 0xa000 (40960)
364d90.d94: Resource Dir: 0x8000 LB 0x3d0
365d90.d94: ProductName: Malwarebytes Anti-Malware
366d90.d94: ProductVersion: 0.1.15.0
367d90.d94: FileVersion: 0.1.15.0
368d90.d94: FileDescription: Malwarebytes Anti-Malware
369d90.d94: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
370d90.d94: Calling main()
371d90.d94: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
372d90.d94: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
373d90.d94: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
374d90.d94: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe)
375d90.d94: SUPR3HardenedMain: Respawn #2
376d90.d94: supR3HardNtEnableThreadCreation:
377d90.d94: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\apphelp.dll)
378d90.d94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\apphelp.dll
379d90.d94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\apphelp.dll (rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
380d90.d94: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\apphelp.dll [lacks WinVerifyTrust]
381d90.d94: supR3HardenedDllNotificationCallback: load 000007fefd3d0000 LB 0x00057000 C:\Windows\system32\apphelp.dll [fFlags=0x0]
382d90.d94: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\apphelp.dll [lacks WinVerifyTrust]
383d90.d94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd3d0000 'C:\Windows\system32\apphelp.dll'
384d90.d94: supR3HardNtDisableThreadCreation: pvLdrInitThunk=000000007784b780 pvNtTerminateThread=000000007786e0e0
385d90.d94: supR3HardenedWinDoReSpawn(2): New child d98.d9c [kernel32].
386d90.d94: supR3HardNtChildGatherData: PebBaseAddress=000007fffffdf000 cbPeb=0x380
387d90.d94: supR3HardNtPuChFindNtdll: uNtDllParentAddr=0000000077820000 uNtDllChildAddr=0000000077820000
388d90.d94: supR3HardenedWinSetupChildInit: uLdrInitThunk=000000007784b780
389d90.d94: supR3HardenedWinSetupChildInit: Start child.
390d90.d94: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
391d90.d94: supR3HardNtChildPurify: Startup delay kludge #1/0: 515 ms, 33 sleeps
392d90.d94: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
393d90.d94: *0000000000000000-fffffffffffeffff 0x0001/0x0000 0x0000000
394d90.d94: *0000000000010000-fffffffffffeffff 0x0004/0x0004 0x0020000
395d90.d94: *0000000000030000-000000000002bfff 0x0002/0x0002 0x0040000
396d90.d94: 0000000000034000-0000000000027fff 0x0001/0x0000 0x0000000
397d90.d94: *0000000000040000-000000000003efff 0x0004/0x0004 0x0020000
398d90.d94: 0000000000041000-ffffffffffef1fff 0x0001/0x0000 0x0000000
399d90.d94: *0000000000190000-0000000000093fff 0x0000/0x0004 0x0020000
400d90.d94: 000000000028c000-0000000000288fff 0x0104/0x0004 0x0020000
401d90.d94: 000000000028f000-000000000028dfff 0x0004/0x0004 0x0020000
402d90.d94: 0000000000290000-ffffffff88cfffff 0x0001/0x0000 0x0000000
403d90.d94: *0000000077820000-0000000077820fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
404d90.d94: 0000000077821000-000000007791efff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
405d90.d94: 000000007791f000-000000007794dfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
406d90.d94: 000000007794e000-0000000077955fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
407d90.d94: 0000000077956000-0000000077956fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
408d90.d94: 0000000077957000-0000000077959fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
409d90.d94: 000000007795a000-00000000779c8fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
410d90.d94: 00000000779c9000-00000000703b1fff 0x0001/0x0000 0x0000000
411d90.d94: *000000007efe0000-000000007dfdffff 0x0000/0x0002 0x0020000
412d90.d94: *000000007ffe0000-000000007ffdefff 0x0002/0x0002 0x0020000
413d90.d94: 000000007ffe1000-000000007ffd1fff 0x0000/0x0002 0x0020000
414d90.d94: 000000007fff0000-ffffffffc045ffff 0x0001/0x0000 0x0000000
415d90.d94: *000000013fb80000-000000013fb80fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
416d90.d94: 000000013fb81000-000000013fc07fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
417d90.d94: 000000013fc08000-000000013fc08fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
418d90.d94: 000000013fc09000-000000013fc53fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
419d90.d94: 000000013fc54000-000000013fc54fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
420d90.d94: 000000013fc55000-000000013fc55fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
421d90.d94: 000000013fc56000-000000013fc5afff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
422d90.d94: 000000013fc5b000-000000013fc5bfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
423d90.d94: 000000013fc5c000-000000013fc5cfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
424d90.d94: 000000013fc5d000-000000013fc60fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
425d90.d94: 000000013fc61000-000000013fcabfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
426d90.d94: 000000013fcac000-fffff8037fe17fff 0x0001/0x0000 0x0000000
427d90.d94: *000007feffb40000-000007feffb40fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\apisetschema.dll
428d90.d94: 000007feffb41000-000007fdff6d1fff 0x0001/0x0000 0x0000000
429d90.d94: *000007fffffb0000-000007fffff8cfff 0x0002/0x0002 0x0040000
430d90.d94: 000007fffffd3000-000007fffffc8fff 0x0001/0x0000 0x0000000
431d90.d94: *000007fffffdd000-000007fffffdafff 0x0004/0x0004 0x0020000
432d90.d94: *000007fffffdf000-000007fffffddfff 0x0004/0x0004 0x0020000
433d90.d94: *000007fffffe0000-000007fffffcffff 0x0001/0x0002 0x0020000
434d90.d94: apisetschema.dll: timestamp 0x55636622 (rc=VINF_SUCCESS)
435d90.d94: VirtualBox.exe: timestamp 0x564221d3 (rc=VINF_SUCCESS)
436d90.d94: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
437d90.d94: '\Device\HarddiskVolume2\Windows\System32\apisetschema.dll' has no imports
438d90.d94: '\Device\HarddiskVolume2\Windows\System32\ntdll.dll' has no imports
439d90.d94: supR3HardNtChildPurify: Done after 546 ms and 0 fixes (loop #0).
440d98.d9c: Log file opened: 5.0.10r104061 g_hStartupLog=0000000000000004 g_uNtVerCombined=0x611db110
441d98.d9c: supR3HardenedVmProcessInit: uNtDllAddr=0000000077820000
442d98.d9c: ntdll.dll: timestamp 0x556366f2 (rc=VINF_SUCCESS)
443d98.d9c: New simple heap: #1 0000000000290000 LB 0x400000 (for 1740800 allocation)
444d90.d94: supR3HardenedEarlyCompact: Removed heap 1 (0x00000000280000 LB 0x400000)
445d90.d94: supR3HardNtEnableThreadCreation:
446d98.d9c: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
447d98.d9c: System32: \Device\HarddiskVolume2\Windows\System32
448d98.d9c: WinSxS: \Device\HarddiskVolume2\Windows\winsxs
449d98.d9c: KnownDllPath: C:\Windows\system32
450d98.d9c: supR3HardenedVmProcessInit: Opening vboxdrv...
451d98.d9c: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
452d98.d9c: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
453d98.d9c: Registered Dll notification callback with NTDLL.
454d98.d9c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\kernel32.dll)
455d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\kernel32.dll
456d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
457d98.d9c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
458d98.d9c: supR3HardenedDllNotificationCallback: load 0000000077700000 LB 0x0011f000 C:\Windows\system32\kernel32.dll [fFlags=0x0]
459d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
460d98.d9c: supR3HardenedDllNotificationCallback: load 000007fefd630000 LB 0x0006c000 C:\Windows\system32\KERNELBASE.dll [fFlags=0x0]
461d98.d9c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\KernelBase.dll)
462d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\KernelBase.dll
463d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077700000 'C:\Windows\system32\kernel32.dll'
464d98.d9c: supR3HardNtDisableThreadCreation: pvLdrInitThunk=000000007784b780 pvNtTerminateThread=000000007786e0e0
465d90.d94: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 32 ms.
466d98.d9c: \SystemRoot\System32\ntdll.dll:
467d98.d9c: CreationTime: 2015-06-30T18:24:53.606504900Z
468d98.d9c: LastWriteTime: 2015-05-25T18:21:21.289963400Z
469d98.d9c: ChangeTime: 2015-06-30T22:16:12.090281900Z
470d98.d9c: FileAttributes: 0x20
471d98.d9c: Size: 0x1a61c0
472d98.d9c: NT Headers: 0xe0
473d98.d9c: Timestamp: 0x556366f2
474d98.d9c: Machine: 0x8664 - amd64
475d98.d9c: Timestamp: 0x556366f2
476d98.d9c: Image Version: 6.1
477d98.d9c: SizeOfImage: 0x1a9000 (1740800)
478d98.d9c: Resource Dir: 0x14d000 LB 0x5a028
479d98.d9c: ProductName: Microsoft® Windows® Operating System
480d98.d9c: ProductVersion: 6.1.7601.18869
481d98.d9c: FileVersion: 6.1.7601.18869 (win7sp1_gdr.150525-0603)
482d98.d9c: FileDescription: NT Layer DLL
483d98.d9c: \SystemRoot\System32\kernel32.dll:
484d98.d9c: CreationTime: 2015-06-30T18:24:53.107304100Z
485d98.d9c: LastWriteTime: 2015-05-25T18:19:02.585000000Z
486d98.d9c: ChangeTime: 2015-06-30T22:16:12.324282300Z
487d98.d9c: FileAttributes: 0x20
488d98.d9c: Size: 0x11be00
489d98.d9c: NT Headers: 0xe8
490d98.d9c: Timestamp: 0x556366fc
491d98.d9c: Machine: 0x8664 - amd64
492d98.d9c: Timestamp: 0x556366fc
493d98.d9c: Image Version: 6.1
494d98.d9c: SizeOfImage: 0x11f000 (1175552)
495d98.d9c: Resource Dir: 0x116000 LB 0x528
496d98.d9c: ProductName: Microsoft® Windows® Operating System
497d98.d9c: ProductVersion: 6.1.7601.18869
498d98.d9c: FileVersion: 6.1.7601.18869 (win7sp1_gdr.150525-0603)
499d98.d9c: FileDescription: Windows NT BASE API Client DLL
500d98.d9c: \SystemRoot\System32\KernelBase.dll:
501d98.d9c: CreationTime: 2015-06-30T18:24:53.060504000Z
502d98.d9c: LastWriteTime: 2015-05-25T18:19:02.585000000Z
503d98.d9c: ChangeTime: 2015-06-30T22:16:12.324282300Z
504d98.d9c: FileAttributes: 0x20
505d98.d9c: Size: 0x67c00
506d98.d9c: NT Headers: 0xe8
507d98.d9c: Timestamp: 0x556366fd
508d98.d9c: Machine: 0x8664 - amd64
509d98.d9c: Timestamp: 0x556366fd
510d98.d9c: Image Version: 6.1
511d98.d9c: SizeOfImage: 0x6c000 (442368)
512d98.d9c: Resource Dir: 0x6a000 LB 0x530
513d98.d9c: ProductName: Microsoft® Windows® Operating System
514d98.d9c: ProductVersion: 6.1.7601.18869
515d98.d9c: FileVersion: 6.1.7601.18869 (win7sp1_gdr.150525-0603)
516d98.d9c: FileDescription: Windows NT BASE API Client DLL
517d98.d9c: \SystemRoot\System32\apisetschema.dll:
518d98.d9c: CreationTime: 2015-06-30T18:24:52.124502300Z
519d98.d9c: LastWriteTime: 2015-05-25T18:11:40.254000000Z
520d98.d9c: ChangeTime: 2015-06-30T22:16:12.074681900Z
521d98.d9c: FileAttributes: 0x20
522d98.d9c: Size: 0x1a00
523d98.d9c: NT Headers: 0xc0
524d98.d9c: Timestamp: 0x55636622
525d98.d9c: Machine: 0x8664 - amd64
526d98.d9c: Timestamp: 0x55636622
527d98.d9c: Image Version: 6.1
528d98.d9c: SizeOfImage: 0x50000 (327680)
529d98.d9c: Resource Dir: 0x30000 LB 0x3f8
530d98.d9c: ProductName: Microsoft® Windows® Operating System
531d98.d9c: ProductVersion: 6.1.7601.18869
532d98.d9c: FileVersion: 6.1.7601.18869 (win7sp1_gdr.150525-0603)
533d98.d9c: FileDescription: ApiSet Schema DLL
534d98.d9c: supR3HardenedWinFindAdversaries: 0x80
535d98.d9c: \SystemRoot\System32\drivers\MBAMSwissArmy.sys:
536d98.d9c: CreationTime: 2015-07-18T23:42:46.446818300Z
537d98.d9c: LastWriteTime: 2015-07-27T17:41:10.541992700Z
538d98.d9c: ChangeTime: 2015-07-27T17:41:10.541992700Z
539d98.d9c: FileAttributes: 0x20
540d98.d9c: Size: 0x1bcd8
541d98.d9c: NT Headers: 0xe8
542d98.d9c: Timestamp: 0x552c190f
543d98.d9c: Machine: 0x8664 - amd64
544d98.d9c: Timestamp: 0x552c190f
545d98.d9c: Image Version: 6.1
546d98.d9c: SizeOfImage: 0x21000 (135168)
547d98.d9c: Resource Dir: 0x1f000 LB 0x3f0
548d98.d9c: ProductName: Malwarebytes Anti-Malware
549d98.d9c: ProductVersion: 0.2.22.0
550d98.d9c: FileVersion: 0.2.22.0
551d98.d9c: FileDescription: Malwarebytes Anti-Malware
552d98.d9c: \SystemRoot\System32\drivers\mwac.sys:
553d98.d9c: CreationTime: 2015-07-18T23:42:36.308030900Z
554d98.d9c: LastWriteTime: 2015-06-18T08:48:04.000000000Z
555d98.d9c: ChangeTime: 2015-07-18T23:43:21.166227100Z
556d98.d9c: FileAttributes: 0x20
557d98.d9c: Size: 0xf8d8
558d98.d9c: NT Headers: 0xf8
559d98.d9c: Timestamp: 0x53a0f42a
560d98.d9c: Machine: 0x8664 - amd64
561d98.d9c: Timestamp: 0x53a0f42a
562d98.d9c: Image Version: 6.2
563d98.d9c: SizeOfImage: 0x12000 (73728)
564d98.d9c: Resource Dir: 0x10000 LB 0x3e0
565d98.d9c: ProductName: Malwarebytes Web Access Control
566d98.d9c: ProductVersion: 1.0.6.0
567d98.d9c: FileVersion: 1.0.6.0
568d98.d9c: FileDescription: Malwarebytes Web Access Control
569d98.d9c: \SystemRoot\System32\drivers\mbamchameleon.sys:
570d98.d9c: CreationTime: 2015-07-18T23:42:36.315031800Z
571d98.d9c: LastWriteTime: 2015-06-18T08:47:54.000000000Z
572d98.d9c: ChangeTime: 2015-07-18T23:43:21.178228700Z
573d98.d9c: FileAttributes: 0x20
574d98.d9c: Size: 0x1aad8
575d98.d9c: NT Headers: 0xd8
576d98.d9c: Timestamp: 0x554cf757
577d98.d9c: Machine: 0x8664 - amd64
578d98.d9c: Timestamp: 0x554cf757
579d98.d9c: Image Version: 6.1
580d98.d9c: SizeOfImage: 0x1e000 (122880)
581d98.d9c: Resource Dir: 0x1c000 LB 0xbd8
582d98.d9c: ProductName: Malwarebytes Chameleon
583d98.d9c: ProductVersion: 1.1.20.0
584d98.d9c: FileVersion: 1.1.20.0
585d98.d9c: FileDescription: Malwarebytes Chameleon Protection Driver
586d98.d9c: \SystemRoot\System32\drivers\mbam.sys:
587d98.d9c: CreationTime: 2015-07-18T23:42:36.304030400Z
588d98.d9c: LastWriteTime: 2015-06-18T08:47:50.000000000Z
589d98.d9c: ChangeTime: 2015-07-18T23:43:21.159226300Z
590d98.d9c: FileAttributes: 0x20
591d98.d9c: Size: 0x64d8
592d98.d9c: NT Headers: 0xd8
593d98.d9c: Timestamp: 0x540754e1
594d98.d9c: Machine: 0x8664 - amd64
595d98.d9c: Timestamp: 0x540754e1
596d98.d9c: Image Version: 6.1
597d98.d9c: SizeOfImage: 0xa000 (40960)
598d98.d9c: Resource Dir: 0x8000 LB 0x3d0
599d98.d9c: ProductName: Malwarebytes Anti-Malware
600d98.d9c: ProductVersion: 0.1.15.0
601d98.d9c: FileVersion: 0.1.15.0
602d98.d9c: FileDescription: Malwarebytes Anti-Malware
603d98.d9c: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
604d98.d9c: Calling main()
605d98.d9c: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
606d98.d9c: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
607d98.d9c: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
608d98.d9c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe)
609d98.d9c: SUPR3HardenedMain: Final process, opening VBoxDrv...
610d98.d9c: supR3HardenedEarlyCompact: Removed heap 1 (0x00000000290000 LB 0x400000)
611d98.d9c: supR3HardNtEnableThreadCreation:
612d98.d9c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll)
613d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll
614d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000693bf0:C:\Windows\system32 [calling]
615d98.d9c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
616d98.d9c: supR3HardenedDllNotificationCallback: load 000007fefaee0000 LB 0x00005000 C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL [fFlags=0x0]
617d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
618d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
619d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000694020:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
620d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefaee0000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
621d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
622d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000694020:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
623d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefaee0000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
624d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefaee0000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
625d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
626d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'crypt32.dll'.
627d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msasn1.dll'.
628d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
629d98.d9c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\wintrust.dll)
630d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wintrust.dll
631d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
632d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
633d98.d9c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll)
634d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
635d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
636d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume2\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
637d98.d9c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\msasn1.dll)
638d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msasn1.dll
639d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
640d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume2\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
641d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
642d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msasn1.dll'.
643d98.d9c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\crypt32.dll)
644d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\crypt32.dll
645d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
646d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
647d98.d9c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\msvcrt.dll)
648d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
649d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
650d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume2\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
651d98.d9c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
652d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
653d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
654d98.d9c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
655d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000693bf0:C:\Windows\system32 [calling]
656d98.d9c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
657d98.d9c: supR3HardenedDllNotificationCallback: load 000007fefd7b0000 LB 0x0003b000 C:\Windows\system32\Wintrust.dll [fFlags=0x0]
658d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
659d98.d9c: supR3HardenedDllNotificationCallback: load 000007fefe400000 LB 0x0009f000 C:\Windows\system32\msvcrt.dll [fFlags=0x0]
660d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
661d98.d9c: supR3HardenedDllNotificationCallback: load 000007fefd7f0000 LB 0x0016d000 C:\Windows\system32\CRYPT32.dll [fFlags=0x0]
662d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
663d98.d9c: supR3HardenedDllNotificationCallback: load 000007fefd5d0000 LB 0x0000f000 C:\Windows\system32\MSASN1.dll [fFlags=0x0]
664d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
665d98.d9c: supR3HardenedDllNotificationCallback: load 000007feff250000 LB 0x0012d000 C:\Windows\system32\RPCRT4.dll [fFlags=0x0]
666d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
667d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd7b0000 'C:\Windows\system32\Wintrust.dll'
668d98.d9c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\bcrypt.dll)
669d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\bcrypt.dll
670d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcrypt.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000006d8e20:C:\Windows\system32 [calling]
671d98.d9c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
672d98.d9c: supR3HardenedDllNotificationCallback: load 000007fefcf20000 LB 0x00022000 C:\Windows\system32\bcrypt.dll [fFlags=0x0]
673d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
674d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcf20000 'C:\Windows\system32\bcrypt.dll'
675d98.d9c: bcrypt.dll loaded at 000007fefcf20000, BCryptOpenAlgorithmProvider at 000007fefcf22640, preloading providers:
676d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
677d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'bcrypt.dll'.
678d98.d9c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll)
679d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll
680d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
681d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume2\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
682d98.d9c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
683d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
684d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
685d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
686d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'rpcrt4.dll'.
687d98.d9c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\advapi32.dll)
688d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\advapi32.dll
689d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
690d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
691d98.d9c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
692d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
693d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
694d98.d9c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
695d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcryptprimitives.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000694020:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
696d98.d9c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
697d98.d9c: supR3HardenedDllNotificationCallback: load 000007fefca10000 LB 0x0004c000 C:\Windows\system32\bcryptprimitives.dll [fFlags=0x0]
698d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
699d98.d9c: supR3HardenedDllNotificationCallback: load 000007fefe320000 LB 0x000db000 C:\Windows\system32\ADVAPI32.dll [fFlags=0x0]
700d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
701d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msvcrt.dll'.
702d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'rpcrt4.dll'.
703d98.d9c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\sechost.dll)
704d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\sechost.dll
705d98.d9c: supR3HardenedDllNotificationCallback: load 000007feff230000 LB 0x0001f000 C:\Windows\SYSTEM32\sechost.dll [fFlags=0x0]
706d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\sechost.dll [lacks WinVerifyTrust]
707d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefca10000 'C:\Windows\system32\bcryptprimitives.dll'
708d98.d9c: BCryptOpenAlgorithmProvider(,'MD2',0,0) -> 0x0 (hAlgo=00000000006da500)
709d98.d9c: BCryptOpenAlgorithmProvider(,'MD4',0,0) -> 0x0 (hAlgo=00000000006dd3c0)
710d98.d9c: BCryptOpenAlgorithmProvider(,'MD5',0,0) -> 0x0 (hAlgo=00000000006dd4e0)
711d98.d9c: BCryptOpenAlgorithmProvider(,'SHA1',0,0) -> 0x0 (hAlgo=00000000006dd6f0)
712d98.d9c: BCryptOpenAlgorithmProvider(,'SHA256',0,0) -> 0x0 (hAlgo=00000000006dd810)
713d98.d9c: BCryptOpenAlgorithmProvider(,'SHA512',0,0) -> 0x0 (hAlgo=00000000006dd930)
714d98.d9c: BCryptOpenAlgorithmProvider(,'RSA',0,0) -> 0x0 (hAlgo=00000000006ddb70)
715d98.d9c: BCryptOpenAlgorithmProvider(,'DSA',0,0) -> 0x0 (hAlgo=00000000006ddc90)
716d98.d9c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\cryptsp.dll)
717d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cryptsp.dll
718d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
719d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
720d98.d9c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
721d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
722d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
723d98.d9c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
724d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTSP.dll (Input=CRYPTSP.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000694020:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
725d98.d9c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
726d98.d9c: supR3HardenedDllNotificationCallback: load 000007fefcdd0000 LB 0x00018000 C:\Windows\system32\CRYPTSP.dll [fFlags=0x0]
727d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
728d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcdd0000 'C:\Windows\system32\CRYPTSP.dll'
729d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
730d98.d9c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\rsaenh.dll)
731d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\rsaenh.dll
732d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
733d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
734d98.d9c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
735d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000694020:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
736d98.d9c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
737d98.d9c: supR3HardenedDllNotificationCallback: load 000007fefcad0000 LB 0x00047000 C:\Windows\system32\rsaenh.dll [fFlags=0x0]
738d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
739d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcad0000 'C:\Windows\system32\rsaenh.dll'
740d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
741d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ADVAPI32.dll (Input=ADVAPI32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000694020:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
742d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe320000 'C:\Windows\system32\ADVAPI32.dll'
743d98.d9c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\cryptbase.dll)
744d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cryptbase.dll
745d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTBASE.dll (Input=CRYPTBASE.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000694020:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
746d98.d9c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptbase.dll [lacks WinVerifyTrust]
747d98.d9c: supR3HardenedDllNotificationCallback: load 000007fefd470000 LB 0x0000f000 C:\Windows\system32\CRYPTBASE.dll [fFlags=0x0]
748d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptbase.dll [lacks WinVerifyTrust]
749d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd470000 'C:\Windows\system32\CRYPTBASE.dll'
750d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
751d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000694020:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
752d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077700000 'C:\Windows\system32\kernel32.dll'
753d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
754d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\WINTRUST.DLL (Input=WINTRUST.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000694020:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
755d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd7b0000 'C:\Windows\system32\WINTRUST.DLL'
756d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
757d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPT32.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=0000000000694020:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
758d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd7f0000 'C:\Windows\system32\CRYPT32.dll'
759d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
760d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'advapi32.dll'.
761d98.d9c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\imagehlp.dll)
762d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\imagehlp.dll
763d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
764d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
765d98.d9c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
766d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
767d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
768d98.d9c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
769d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\imagehlp.dll (Input=imagehlp.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000694020:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
770d98.d9c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\imagehlp.dll [lacks WinVerifyTrust]
771d98.d9c: supR3HardenedDllNotificationCallback: load 000007fefda60000 LB 0x00019000 C:\Windows\system32\imagehlp.dll [fFlags=0x0]
772d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\imagehlp.dll [lacks WinVerifyTrust]
773d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefda60000 'C:\Windows\system32\imagehlp.dll'
774d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
775d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTSP.dll (Input=CRYPTSP.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000694020:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
776d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcdd0000 'C:\Windows\system32\CRYPTSP.dll'
777d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
778d98.d9c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\user32.dll)
779d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\user32.dll
780d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
781d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
782d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
783d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'lpk.dll'.
784d98.d9c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\gdi32.dll)
785d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\gdi32.dll
786d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'lpk.dll'...
787d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'lpk.dll' -> '\Device\HarddiskVolume2\Windows\System32\lpk.dll' [rcNtRedir=0xc0150008]
788d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'gdi32.dll'.
789d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'user32.dll'.
790d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'usp10.dll'.
791d98.d9c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\lpk.dll)
792d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\lpk.dll
793d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
794d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
795d98.d9c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
796d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'usp10.dll'...
797d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'usp10.dll' -> '\Device\HarddiskVolume2\Windows\System32\usp10.dll' [rcNtRedir=0xc0150008]
798d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
799d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
800d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'gdi32.dll'.
801d98.d9c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\usp10.dll)
802d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\usp10.dll
803d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
804d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
805d98.d9c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
806d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
807d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
808d98.d9c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
809d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
810d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
811d98.d9c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
812d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
813d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
814d98.d9c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
815d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
816d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
817d98.d9c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
818d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\USER32.dll (Input=USER32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000694020:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
819d98.d9c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
820d98.d9c: supR3HardenedDllNotificationCallback: load 0000000077600000 LB 0x000fa000 C:\Windows\system32\USER32.dll [fFlags=0x0]
821d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
822d98.d9c: supR3HardenedDllNotificationCallback: load 000007feffac0000 LB 0x00067000 C:\Windows\system32\GDI32.dll [fFlags=0x0]
823d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
824d98.d9c: supR3HardenedDllNotificationCallback: load 000007feff8d0000 LB 0x0000e000 C:\Windows\system32\LPK.dll [fFlags=0x0]
825d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\lpk.dll [lacks WinVerifyTrust]
826d98.d9c: supR3HardenedDllNotificationCallback: load 000007fefd990000 LB 0x000c9000 C:\Windows\system32\USP10.dll [fFlags=0x0]
827d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\usp10.dll [lacks WinVerifyTrust]
828d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
829d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\gdi32.dll (Input=gdi32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000694020:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
830d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feffac0000 'C:\Windows\system32\gdi32.dll'
831d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'user32.dll'.
832d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
833d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msctf.dll'.
834d98.d9c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\imm32.dll)
835d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\imm32.dll
836d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msctf.dll'...
837d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msctf.dll' -> '\Device\HarddiskVolume2\Windows\System32\msctf.dll' [rcNtRedir=0xc0150008]
838d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
839d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
840d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'gdi32.dll'.
841d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'imm32.dll'.
842d98.d9c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\msctf.dll)
843d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msctf.dll
844d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
845d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
846d98.d9c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
847d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
848d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
849d98.d9c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
850d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
851d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume2\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
852d98.d9c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\imm32.dll [lacks WinVerifyTrust]
853d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
854d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
855d98.d9c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
856d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
857d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
858d98.d9c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
859d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
860d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
861d98.d9c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
862d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\IMM32.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000694020:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
863d98.d9c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\imm32.dll [lacks WinVerifyTrust]
864d98.d9c: supR3HardenedDllNotificationCallback: load 000007feff380000 LB 0x0002e000 C:\Windows\system32\IMM32.DLL [fFlags=0x0]
865d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\imm32.dll [lacks WinVerifyTrust]
866d98.d9c: supR3HardenedDllNotificationCallback: load 000007fefda80000 LB 0x00109000 C:\Windows\system32\MSCTF.dll [fFlags=0x0]
867d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msctf.dll [lacks WinVerifyTrust]
868d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff380000 'C:\Windows\system32\IMM32.DLL'
869d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077600000 'C:\Windows\system32\USER32.dll'
870d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'bcrypt.dll'.
871d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
872d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msasn1.dll'.
873d98.d9c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\ncrypt.dll)
874d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ncrypt.dll
875d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
876d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume2\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
877d98.d9c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
878d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
879d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
880d98.d9c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
881d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
882d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume2\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
883d98.d9c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
884d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ncrypt.dll (Input=ncrypt.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000694020:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
885d98.d9c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\ncrypt.dll [lacks WinVerifyTrust]
886d98.d9c: supR3HardenedDllNotificationCallback: load 000007fefcf50000 LB 0x00050000 C:\Windows\system32\ncrypt.dll [fFlags=0x0]
887d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\ncrypt.dll [lacks WinVerifyTrust]
888d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcf50000 'C:\Windows\system32\ncrypt.dll'
889d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
890d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcrypt.dll (Input=bcrypt.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000694020:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
891d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcf20000 'C:\Windows\system32\bcrypt.dll'
892d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
893d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'rpcrt4.dll'.
894d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'profapi.dll'.
895d98.d9c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\userenv.dll)
896d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\userenv.dll
897d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'profapi.dll'...
898d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'profapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\profapi.dll' [rcNtRedir=0xc0150008]
899d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
900d98.d9c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\profapi.dll)
901d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\profapi.dll
902d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
903d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
904d98.d9c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
905d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
906d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
907d98.d9c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
908d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
909d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
910d98.d9c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
911d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\USERENV.dll (Input=USERENV.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000694020:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
912d98.d9c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\userenv.dll [lacks WinVerifyTrust]
913d98.d9c: supR3HardenedDllNotificationCallback: load 000007fefd970000 LB 0x0001e000 C:\Windows\system32\USERENV.dll [fFlags=0x0]
914d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\userenv.dll [lacks WinVerifyTrust]
915d98.d9c: supR3HardenedDllNotificationCallback: load 000007fefd5e0000 LB 0x0000f000 C:\Windows\system32\profapi.dll [fFlags=0x0]
916d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\profapi.dll [lacks WinVerifyTrust]
917d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd970000 'C:\Windows\system32\USERENV.dll'
918d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000694020:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
919d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff230000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
920d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000694020:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
921d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff230000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
922d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
923d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'rpcrt4.dll'.
924d98.d9c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\gpapi.dll)
925d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\gpapi.dll
926d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
927d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
928d98.d9c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
929d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
930d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
931d98.d9c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
932d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\GPAPI.dll (Input=GPAPI.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000694020:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
933d98.d9c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gpapi.dll [lacks WinVerifyTrust]
934d98.d9c: supR3HardenedDllNotificationCallback: load 000007fefc890000 LB 0x0001b000 C:\Windows\system32\GPAPI.dll [fFlags=0x0]
935d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gpapi.dll [lacks WinVerifyTrust]
936d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc890000 'C:\Windows\system32\GPAPI.dll'
937d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-Management-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000694020:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
938d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff230000 'API-MS-WIN-Service-Management-L1-1-0.dll'
939d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
940d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rpcrt4.dll (Input=rpcrt4.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000694020:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
941d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff250000 'C:\Windows\system32\rpcrt4.dll'
942d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-Management-L2-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000694020:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
943d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff230000 'API-MS-WIN-Service-Management-L2-1-0.dll'
944d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000694020:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
945d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff230000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
946d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
947d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'advapi32.dll'.
948d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'crypt32.dll'.
949d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'wldap32.dll'.
950d98.d9c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\cryptnet.dll)
951d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cryptnet.dll
952d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wldap32.dll'...
953d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'wldap32.dll' -> '\Device\HarddiskVolume2\Windows\System32\wldap32.dll' [rcNtRedir=0xc0150008]
954d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
955d98.d9c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\Wldap32.dll)
956d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\Wldap32.dll
957d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
958d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume2\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
959d98.d9c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
960d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
961d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
962d98.d9c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
963d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
964d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
965d98.d9c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
966d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
967d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
968d98.d9c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
969d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (Input=cryptnet.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000694020:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
970d98.d9c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
971d98.d9c: supR3HardenedDllNotificationCallback: load 000007fefa110000 LB 0x00027000 C:\Windows\system32\cryptnet.dll [fFlags=0x0]
972d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
973d98.d9c: supR3HardenedDllNotificationCallback: load 000007feff4e0000 LB 0x00052000 C:\Windows\system32\WLDAP32.dll [fFlags=0x0]
974d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\Wldap32.dll [lacks WinVerifyTrust]
975d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
976d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=0000000000694020:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
977d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa110000 'C:\Windows\system32\cryptnet.dll'
978d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
979d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=0000000000694020:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
980d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa110000 'C:\Windows\system32\cryptnet.dll'
981d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
982d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=0000000000694020:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
983d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa110000 'C:\Windows\system32\cryptnet.dll'
984d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
985d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=0000000000694020:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
986d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa110000 'C:\Windows\system32\cryptnet.dll'
987d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
988d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=0000000000694020:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
989d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa110000 'C:\Windows\system32\cryptnet.dll'
990d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
991d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=0000000000694020:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
992d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa110000 'C:\Windows\system32\cryptnet.dll'
993d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
994d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa110000 'C:\Windows\system32\cryptnet.dll'
995d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
996d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa110000 'C:\Windows\system32\cryptnet.dll'
997d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
998d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa110000 'C:\Windows\system32\cryptnet.dll'
999d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
1000d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa110000 'C:\Windows\system32\cryptnet.dll'
1001d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
1002d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa110000 'C:\Windows\system32\cryptnet.dll'
1003d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa110000 'C:\Windows\system32\cryptnet.dll'
1004d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
1005d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa110000 'C:\Windows\system32\cryptnet.dll'
1006d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000694020:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
1007d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff230000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
1008d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\profapi.dll [lacks WinVerifyTrust]
1009d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\profapi.dll (Input=profapi.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000694020:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
1010d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd5e0000 'C:\Windows\system32\profapi.dll'
1011d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
1012d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
1013d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msvcrt.dll'.
1014d98.d9c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\shlwapi.dll)
1015d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\shlwapi.dll
1016d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1017d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1018d98.d9c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
1019d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1020d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1021d98.d9c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
1022d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1023d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1024d98.d9c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
1025d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\SHLWAPI.dll (Input=SHLWAPI.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000694020:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
1026d98.d9c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll [lacks WinVerifyTrust]
1027d98.d9c: supR3HardenedDllNotificationCallback: load 000007feff3b0000 LB 0x00071000 C:\Windows\system32\SHLWAPI.dll [fFlags=0x0]
1028d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll [lacks WinVerifyTrust]
1029d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff3b0000 'C:\Windows\system32\SHLWAPI.dll'
1030d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000000 pwszName=\SystemRoot\System32\ntdll.dll
1031d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: New context 00000000006de810
1032d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
1033d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=EDC3F71C5551972E1510D1BCC6D436D5B6B426E8
1034d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000694020:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
1035d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff230000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
1036d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-Management-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000694020:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
1037d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff230000 'API-MS-WIN-Service-Management-L1-1-0.dll'
1038d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-winsvc-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000694020:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
1039d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff230000 'API-MS-WIN-Service-winsvc-L1-1-0.dll'
1040d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
1041d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ADVAPI32.dll (Input=ADVAPI32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000694020:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
1042d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe320000 'C:\Windows\system32\ADVAPI32.dll'
1043d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-LSALookup-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000694020:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
1044d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff230000 'API-MS-Win-Security-LSALookup-L1-1-0.dll'
1045d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-LSALookup-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000694020:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
1046d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff230000 'API-MS-Win-Security-LSALookup-L1-1-0.dll'
1047d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_85_for_KB3068708~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\SystemRoot\System32\ntdll.dll'
1048d98.d9c: g_pfnWinVerifyTrust=000007fefd7b1010
1049d98.d9c: supR3HardenedScreenImage/preload: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [redoing WinVerifyTrust]
1050d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000e0 pwszName=\Device\HarddiskVolume2\Windows\System32\crypt32.dll
1051d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006de810
1052d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
1053d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=BFD41401EDEBD4D914977D62B588ECABEE60CFD3
1054d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_112_for_KB3040272~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\crypt32.dll'
1055d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1056d98.d9c: supR3HardenedScreenImage/preload: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\crypt32.dll'
1057d98.d9c: supR3HardenedScreenImage/preload: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [redoing WinVerifyTrust]
1058d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000d4 pwszName=\Device\HarddiskVolume2\Windows\System32\wintrust.dll
1059d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006de810
1060d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
1061d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=E1BBE4EB6D114F50142F24E2E2749EFD81021486
1062d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_75_for_KB3040272~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\wintrust.dll'
1063d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1064d98.d9c: supR3HardenedScreenImage/preload: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\wintrust.dll'
1065d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000038c pwszName=\Device\HarddiskVolume2\Windows\System32\shlwapi.dll
1066d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006de810
1067d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
1068d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=0AB8D9C9D3E1FC95D01F9A984B16ED031BB40CD8
1069d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\shlwapi.dll'
1070d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1071d98.d9c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll'
1072d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000380 pwszName=\Device\HarddiskVolume2\Windows\System32\Wldap32.dll
1073d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006de810
1074d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
1075d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=87E73086F2528CF31D3AD5F0D71E04F8B942D5D8
1076d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\Wldap32.dll'
1077d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1078d98.d9c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\Wldap32.dll'
1079d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000037c pwszName=\Device\HarddiskVolume2\Windows\System32\cryptnet.dll
1080d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006de810
1081d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
1082d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=756DC088EE40CF9369C990D71B200F3CB59FC35D
1083d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_75_for_KB3040272~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\cryptnet.dll'
1084d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1085d98.d9c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\cryptnet.dll'
1086d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000258 pwszName=\Device\HarddiskVolume2\Windows\System32\gpapi.dll
1087d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006de810
1088d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
1089d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=470795C189226F7BDB8E50F42104CC34488B9340
1090d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\gpapi.dll'
1091d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1092d98.d9c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\gpapi.dll'
1093d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000001c4 pwszName=\Device\HarddiskVolume2\Windows\System32\profapi.dll
1094d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006de810
1095d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
1096d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2449672745D9BA339420451D13FA0380AA768231
1097d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\profapi.dll'
1098d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1099d98.d9c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\profapi.dll'
1100d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000001c0 pwszName=\Device\HarddiskVolume2\Windows\System32\userenv.dll
1101d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006de810
1102d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
1103d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=D3E1A2CC7367F751C19EBF4E6EDF5E9A10E47313
1104d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\userenv.dll'
1105d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1106d98.d9c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\userenv.dll'
1107d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000001ac pwszName=\Device\HarddiskVolume2\Windows\System32\ncrypt.dll
1108d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006de810
1109d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
1110d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B24A74F7868A1824679A2006F7E6D98D206BCD0A
1111d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_85_for_KB3068708~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\Windows\System32\ncrypt.dll'
1112d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1113d98.d9c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\ncrypt.dll'
1114d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000194 pwszName=\Device\HarddiskVolume2\Windows\System32\msctf.dll
1115d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006de810
1116d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
1117d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=03916BC73EE5A0E312E3D3100D0ACE1B78E93BB1
1118d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3033889~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\Windows\System32\msctf.dll'
1119d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1120d98.d9c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\msctf.dll'
1121d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000190 pwszName=\Device\HarddiskVolume2\Windows\System32\imm32.dll
1122d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006de810
1123d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
1124d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=6EEE1AB3B6D79AFF857940FF5F51ED27698153EC
1125d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\imm32.dll'
1126d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1127d98.d9c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\imm32.dll'
1128d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000018c pwszName=\Device\HarddiskVolume2\Windows\System32\usp10.dll
1129d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006de810
1130d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
1131d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=1F1AA8340DE02FC1B6341EE2706E55D56EDF63B8
1132d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB2957509~31bf3856ad364e35~amd64~~6.1.1.2.cat'; file='\Device\HarddiskVolume2\Windows\System32\usp10.dll'
1133d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1134d98.d9c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\usp10.dll'
1135d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000188 pwszName=\Device\HarddiskVolume2\Windows\System32\lpk.dll
1136d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006de810
1137d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
1138d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=A9BD2F77F6F16827206A18B4C9CB5FCFA62A60CF
1139d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3032323~31bf3856ad364e35~amd64~~6.1.1.3.cat'; file='\Device\HarddiskVolume2\Windows\System32\lpk.dll'
1140d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1141d98.d9c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\lpk.dll'
1142d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000184 pwszName=\Device\HarddiskVolume2\Windows\System32\gdi32.dll
1143d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006de810
1144d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
1145d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=1707E74860DCBF0241835EF4A1E7C39B40ED3ACA
1146d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3046306~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\Windows\System32\gdi32.dll'
1147d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1148d98.d9c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\gdi32.dll'
1149d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000180 pwszName=\Device\HarddiskVolume2\Windows\System32\user32.dll
1150d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006de810
1151d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
1152d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B723D1B8AD72750B0CF5F6BEC66171B1254ED879
1153d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\user32.dll'
1154d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1155d98.d9c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\user32.dll'
1156d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000017c pwszName=\Device\HarddiskVolume2\Windows\System32\imagehlp.dll
1157d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006de810
1158d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
1159d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2702EE05F1B717B0F2CE0FBE32784A47B8419DCA
1160d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_2_for_KB2893294~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\imagehlp.dll'
1161d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1162d98.d9c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\imagehlp.dll'
1163d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000130 pwszName=\Device\HarddiskVolume2\Windows\System32\cryptbase.dll
1164d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006de810
1165d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
1166d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=A965CC5DB13A5FB23BBB1B6B5FA6D400DC49462F
1167d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\cryptbase.dll'
1168d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1169d98.d9c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\cryptbase.dll'
1170d98.d9c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\rsaenh.dll'
1171d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000012c pwszName=\Device\HarddiskVolume2\Windows\System32\cryptsp.dll
1172d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006de810
1173d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
1174d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=BA7AC4A7E8ADDFEA90AC951ECB6D6546E4873613
1175d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_115_for_KB3033929~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\cryptsp.dll'
1176d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1177d98.d9c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\cryptsp.dll'
1178d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000120 pwszName=\Device\HarddiskVolume2\Windows\System32\sechost.dll
1179d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006de810
1180d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
1181d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=CB669FA8DB80F8E50A29D055BB8D558E10E5E6B4
1182d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_85_for_KB3068708~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\Windows\System32\sechost.dll'
1183d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1184d98.d9c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\sechost.dll'
1185d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000011c pwszName=\Device\HarddiskVolume2\Windows\System32\advapi32.dll
1186d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006de810
1187d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
1188d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=9BBB1FC4DED54F17702B287B63F8FE24EE5D7844
1189d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_85_for_KB3068708~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\Windows\System32\advapi32.dll'
1190d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1191d98.d9c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\advapi32.dll'
1192d98.d9c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll'
1193d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000104 pwszName=\Device\HarddiskVolume2\Windows\System32\bcrypt.dll
1194d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006de810
1195d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
1196d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=62E377A1F0AD0C2EDC0A73CB3EFF841FF18D00D2
1197d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\bcrypt.dll'
1198d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1199d98.d9c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\bcrypt.dll'
1200d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000e4 pwszName=\Device\HarddiskVolume2\Windows\System32\msvcrt.dll
1201d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006de810
1202d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
1203d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2CA2FD632B264C063162F71474266E3615B6420C
1204d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB2654428~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\Windows\System32\msvcrt.dll'
1205d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1206d98.d9c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll'
1207d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000dc pwszName=\Device\HarddiskVolume2\Windows\System32\msasn1.dll
1208d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006de810
1209d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
1210d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F2FF57DC30D774F93061607060DAA0DD15E39CCE
1211d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\msasn1.dll'
1212d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1213d98.d9c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\msasn1.dll'
1214d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000d8 pwszName=\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
1215d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006de810
1216d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
1217d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=03E871CFC4A3E7194619AFC99CEEA1EC75982D12
1218d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB2978668~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll'
1219d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1220d98.d9c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll'
1221d98.d9c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll'
1222d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000028 pwszName=\Device\HarddiskVolume2\Windows\System32\KernelBase.dll
1223d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006de810
1224d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
1225d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=FD34F960ED54F1FB26E76A32FB91273E3093869E
1226d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_85_for_KB3068708~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\Windows\System32\KernelBase.dll'
1227d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1228d98.d9c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\KernelBase.dll'
1229d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000020 pwszName=\Device\HarddiskVolume2\Windows\System32\kernel32.dll
1230d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006de810
1231d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
1232d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=1C47BBB61CB0D4D781B3BEC602422D40A0784762
1233d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_85_for_KB3068708~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\Windows\System32\kernel32.dll'
1234d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1235d98.d9c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\kernel32.dll'
1236d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll
1237d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\crypt32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000749540:C:\Windows\system32 [calling]
1238d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd7f0000 'C:\Windows\system32\crypt32.dll'
1239d98.d9c: supR3HardenedWinIsDesiredRootCA: Adding 0x5ad46780fa5df300 DC=com, DC=microsoft, CN=Microsoft Root Certificate Authority
1240d98.d9c: supR3HardenedWinIsDesiredRootCA: Adding 0xea5386456178582b C=ZA, ST=Western Cape, L=Durbanville, O=Thawte, OU=Thawte Certification, CN=Thawte Timestamping CA
1241d98.d9c: supR3HardenedWinIsDesiredRootCA: Adding 0x3be670c1bd02a900 OU=Copyright (c) 1997 Microsoft Corp., OU=Microsoft Corporation, CN=Microsoft Root Authority
1242d98.d9c: supR3HardenedWinIsDesiredRootCA: Adding 0x4d3835aa4180b200 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2011
1243d98.d9c: supR3HardenedWinIsDesiredRootCA: Adding 0x646e3fe3ba08df00 C=US, O=MSFT, CN=Microsoft Authenticode(tm) Root Authority
1244d98.d9c: supR3HardenedWinIsDesiredRootCA: Adding 0xece4e4289e08b900 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010
1245d98.d9c: supR3HardenedWinIsDesiredRootCA: Adding 0x43a9cc371ff5385a O=Microsoft Trust Network, OU=Microsoft Corporation, OU=Microsoft Time Stamping Service Root, OU=Copyright (c) 1997 Microsoft Corp.
1246d98.d9c: supR3HardenedWinIsDesiredRootCA: Adding 0x2e2d2c7c68f0202e O=VeriSign Trust Network, OU=VeriSign, Inc., OU=VeriSign Time Stamping Service Root, OU=NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.
1247d98.d9c: supR3HardenedWinIsDesiredRootCA: Adding 0xf4fd306318ccda00 C=US, O=GeoTrust Inc., CN=GeoTrust Global CA
1248d98.d9c: supR3HardenedWinIsDesiredRootCA: Adding 0x3d98ab22bb04a300 C=IE, O=Baltimore, OU=CyberTrust, CN=Baltimore CyberTrust Root
1249d98.d9c: supR3HardenedWinIsDesiredRootCA: Adding 0xa0ee62086758b15d C=US, O=Equifax, OU=Equifax Secure Certificate Authority
1250d98.d9c: supR3HardenedWinIsDesiredRootCA: Adding 0xa3ce8d99e60eda00 C=BE, O=GlobalSign nv-sa, OU=Root CA, CN=GlobalSign Root CA
1251d98.d9c: supR3HardenedWinIsDesiredRootCA: Adding 0xa8de7211e13be200 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root CA
1252d98.d9c: supR3HardenedWinIsDesiredRootCA: Adding 0x7ae89c50f0b6a00f C=US, O=GTE Corporation, OU=GTE CyberTrust Solutions, Inc., CN=GTE CyberTrust Global Root
1253d98.d9c: supR3HardenedWinIsDesiredRootCA: Adding 0x4d3835aa4180b200 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2011
1254d98.d9c: supR3HardenedWinIsDesiredRootCA: Adding 0x14018a1bf29e595c C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority
1255d98.d9c: supR3HardenedWinIsDesiredRootCA: Adding 0x9e5bc2d78b6a3636 C=ZA, ST=Western Cape, L=Cape Town, O=Thawte Consulting cc, OU=Certification Services Division, CN=Thawte Premium Server CA, [email protected]
1256d98.d9c: supR3HardenedWinIsDesiredRootCA: Adding 0xd4fbe673e5ccc600 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA
1257d98.d9c: supR3HardenedWinIsDesiredRootCA: Adding 0x357a29080824af00 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2006 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G5
1258d98.d9c: supR3HardenedWinIsDesiredRootCA: Adding 0x8043e4ce150ead00 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID Root CA
1259d98.d9c: supR3HardenedWinRetrieveTrustedRootCAs: cAdded=20
1260d98.d9c: SUPR3HardenedMain: Load Runtime...
1261d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
1262d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
1263d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ws2_32.dll'.
1264d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'rpcrt4.dll'.
1265d98.d9c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll) WinVerifyTrust
1266d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
1267d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
1268d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
1269d98.d9c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
1270d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
1271d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
1272d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000040c pwszName=\Device\HarddiskVolume2\Windows\System32\ws2_32.dll
1273d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006de810
1274d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
1275d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=3EF3BDC1E84DFA17EA056313214EE88EC3E66F79
1276d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\ws2_32.dll'
1277d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1278d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1279d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'rpcrt4.dll'.
1280d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'nsi.dll'.
1281d98.d9c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ws2_32.dll) WinVerifyTrust
1282d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
1283d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
1284d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
1285d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
1286d98.d9c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll) WinVerifyTrust
1287d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
1288d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
1289d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
1290d98.d9c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll) WinVerifyTrust
1291d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
1292d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
1293d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
1294d98.d9c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
1295d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
1296d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume2\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
1297d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000438 pwszName=\Device\HarddiskVolume2\Windows\System32\nsi.dll
1298d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006de810
1299d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
1300d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=7AFD8538945F2D05BC1AF949B9B19B7D2D9FBBF8
1301d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\nsi.dll'
1302d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1303d98.d9c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\nsi.dll) WinVerifyTrust
1304d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\nsi.dll
1305d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
1306d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
1307d98.d9c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
1308d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1309d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1310d98.d9c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
1311d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000704870:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
1312d98.d9c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
1313d98.d9c: supR3HardenedDllNotificationCallback: load 000007fef40b0000 LB 0x0055f000 C:\Program Files\Oracle\VirtualBox\VBoxRT.dll [fFlags=0x0]
1314d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
1315d98.d9c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
1316d98.d9c: supR3HardenedDllNotificationCallback: load 0000000075080000 LB 0x000d2000 C:\Program Files\Oracle\VirtualBox\MSVCR100.dll [fFlags=0x0]
1317d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
1318d98.d9c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
1319d98.d9c: supR3HardenedDllNotificationCallback: load 0000000074fe0000 LB 0x00098000 C:\Program Files\Oracle\VirtualBox\MSVCP100.dll [fFlags=0x0]
1320d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
1321d98.d9c: supR3HardenedDllNotificationCallback: load 000007fefe250000 LB 0x0004d000 C:\Windows\system32\WS2_32.dll [fFlags=0x0]
1322d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
1323d98.d9c: supR3HardenedDllNotificationCallback: load 000007feff4d0000 LB 0x00008000 C:\Windows\system32\NSI.dll [fFlags=0x0]
1324d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\nsi.dll
1325d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
1326d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000694020:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
1327d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef40b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1328d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
1329d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000694020:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
1330d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef40b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1331d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
1332d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000694020:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
1333d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef40b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1334d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
1335d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000694020:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
1336d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef40b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1337d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
1338d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000694020:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
1339d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef40b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1340d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
1341d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000694020:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
1342d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef40b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1343d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef40b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1344d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef40b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1345d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef40b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1346d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef40b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1347d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef40b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1348d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef40b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1349d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef40b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1350d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
1351d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000694020:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
1352d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef40b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1353d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef40b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1354d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef40b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1355d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef40b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1356d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef40b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1357d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef40b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1358d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef40b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1359d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef40b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1360d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef40b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1361d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef40b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1362d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef40b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1363d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef40b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1364d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef40b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1365d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef40b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1366d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef40b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1367d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef40b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1368d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
1369d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000694020:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
1370d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef40b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1371d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef40b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1372d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef40b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1373d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef40b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1374d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll
1375d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000749900:C:\Windows\system32 [calling]
1376d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd7b0000 'C:\Windows\system32\Wintrust.dll'
1377d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll
1378d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\crypt32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000749900:C:\Windows\system32 [calling]
1379d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd7f0000 'C:\Windows\system32\crypt32.dll'
1380d98.d9c: SUPR3HardenedMain: Load TrustedMain...
1381d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'opengl32.dll'.
1382d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
1383d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcp100.dll'.
1384d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcr100.dll'.
1385d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qtcorevbox4.dll'.
1386d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'qtguivbox4.dll'.
1387d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'qtopenglvbox4.dll'.
1388d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'user32.dll'.
1389d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'gdi32.dll'.
1390d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'advapi32.dll'.
1391d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'shell32.dll'.
1392d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'ole32.dll'.
1393d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'oleaut32.dll'.
1394d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'comdlg32.dll'.
1395d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #15 'winmm.dll'.
1396d98.d9c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.dll) WinVerifyTrust
1397d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.dll
1398d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
1399d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
1400d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000480 pwszName=\Device\HarddiskVolume2\Windows\System32\winmm.dll
1401d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006de810
1402d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
1403d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=82E2B2A7826F88BEB98FFF0540C9BDB0A12F001A
1404d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\winmm.dll'
1405d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1406d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
1407d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
1408d98.d9c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\winmm.dll) WinVerifyTrust
1409d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\winmm.dll
1410d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comdlg32.dll'...
1411d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'comdlg32.dll' -> '\Device\HarddiskVolume2\Windows\System32\comdlg32.dll' [rcNtRedir=0xc0150008]
1412d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000460 pwszName=\Device\HarddiskVolume2\Windows\System32\comdlg32.dll
1413d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006de810
1414d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
1415d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=66EE5BDFFA413AEA9E1FE7838A08646E94136DA5
1416d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\comdlg32.dll'
1417d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1418d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1419d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'shlwapi.dll'.
1420d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
1421d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'gdi32.dll'.
1422d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'comctl32.dll'.
1423d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'shell32.dll'.
1424d98.d9c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\comdlg32.dll) WinVerifyTrust
1425d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\comdlg32.dll
1426d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
1427d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
1428d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000474 pwszName=\Device\HarddiskVolume2\Windows\System32\oleaut32.dll
1429d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006de810
1430d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
1431d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=8A837B0D823EB506C6A4C447C1962174D27ED954
1432d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3020338~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\oleaut32.dll'
1433d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1434d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ole32.dll'.
1435d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
1436d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
1437d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'user32.dll'.
1438d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'gdi32.dll'.
1439d98.d9c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\oleaut32.dll) WinVerifyTrust
1440d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
1441d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
1442d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
1443d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000048c pwszName=\Device\HarddiskVolume2\Windows\System32\ole32.dll
1444d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006de810
1445d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
1446d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2E64AE329BD5124592BC8CB0B327AA3B95DC65B7
1447d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\ole32.dll'
1448d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1449d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1450d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
1451d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'user32.dll'.
1452d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'rpcrt4.dll'.
1453d98.d9c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ole32.dll) WinVerifyTrust
1454d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ole32.dll
1455d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
1456d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
1457d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000484 pwszName=\Device\HarddiskVolume2\Windows\System32\shell32.dll
1458d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006de810
1459d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
1460d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=0ED534A13973A0F8A98CD4EDC6CBC56E0448E994
1461d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_2_for_KB3039066~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\shell32.dll'
1462d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1463d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1464d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #21 'shlwapi.dll'.
1465d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'user32.dll'.
1466d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #24 'gdi32.dll'.
1467d98.d9c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\shell32.dll) WinVerifyTrust
1468d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\shell32.dll
1469d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
1470d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
1471d98.d9c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
1472d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1473d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1474d98.d9c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll
1475d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1476d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1477d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtopenglvbox4.dll'...
1478d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtopenglvbox4.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qtopenglvbox4.dll' [rcNtRedir=0xc0150008]
1479d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'opengl32.dll'.
1480d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
1481d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
1482d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qtguivbox4.dll'.
1483d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qtcorevbox4.dll'.
1484d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcr100.dll'.
1485d98.d9c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll) WinVerifyTrust
1486d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll
1487d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtguivbox4.dll'...
1488d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtguivbox4.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qtguivbox4.dll' [rcNtRedir=0xc0150008]
1489d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
1490d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'comdlg32.dll'.
1491d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'oleaut32.dll'.
1492d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'imm32.dll'.
1493d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'winmm.dll'.
1494d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'winspool.drv'.
1495d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ole32.dll'.
1496d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'user32.dll'.
1497d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'advapi32.dll'.
1498d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'shell32.dll'.
1499d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'qtcorevbox4.dll'.
1500d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'msvcp100.dll'.
1501d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'msvcr100.dll'.
1502d98.d9c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll) WinVerifyTrust
1503d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll
1504d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtcorevbox4.dll'...
1505d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtcorevbox4.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qtcorevbox4.dll' [rcNtRedir=0xc0150008]
1506d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
1507d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'ole32.dll'.
1508d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
1509d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ws2_32.dll'.
1510d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcp100.dll'.
1511d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcr100.dll'.
1512d98.d9c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll) WinVerifyTrust
1513d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll
1514d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
1515d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
1516d98.d9c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
1517d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
1518d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
1519d98.d9c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
1520d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
1521d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
1522d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
1523d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
1524d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004c0 pwszName=\Device\HarddiskVolume2\Windows\System32\opengl32.dll
1525d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006de810
1526d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
1527d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=608AC397FCC42B9FBAE25CB8C25EAF4C19AA384D
1528d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\opengl32.dll'
1529d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1530d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1531d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
1532d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'gdi32.dll'.
1533d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'glu32.dll'.
1534d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ddraw.dll'.
1535d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'user32.dll'.
1536d98.d9c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\opengl32.dll) WinVerifyTrust
1537d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\opengl32.dll
1538d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1539d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1540d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ddraw.dll'...
1541d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ddraw.dll' -> '\Device\HarddiskVolume2\Windows\System32\ddraw.dll' [rcNtRedir=0xc0150008]
1542d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004c8 pwszName=\Device\HarddiskVolume2\Windows\System32\ddraw.dll
1543d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006de810
1544d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
1545d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=24C763EA54CD792A0F1618411061DC356EE31FF6
1546d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\ddraw.dll'
1547d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1548d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1549d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
1550d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'dciman32.dll'.
1551d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
1552d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'setupapi.dll'.
1553d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'dwmapi.dll'.
1554d98.d9c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ddraw.dll) WinVerifyTrust
1555d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ddraw.dll
1556d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'glu32.dll'...
1557d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'glu32.dll' -> '\Device\HarddiskVolume2\Windows\System32\glu32.dll' [rcNtRedir=0xc0150008]
1558d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004b8 pwszName=\Device\HarddiskVolume2\Windows\System32\glu32.dll
1559d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006de810
1560d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
1561d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=60E45AB914E06A11F44EA76C6EF750AF892F9EA2
1562d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\glu32.dll'
1563d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1564d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1565d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'opengl32.dll'.
1566d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
1567d98.d9c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\glu32.dll) WinVerifyTrust
1568d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\glu32.dll
1569d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1570d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1571d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
1572d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
1573d98.d9c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
1574d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1575d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1576d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
1577d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
1578d98.d9c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
1579d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
1580d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
1581d98.d9c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
1582d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
1583d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
1584d98.d9c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
1585d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
1586d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
1587d98.d9c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
1588d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
1589d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
1590d98.d9c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
1591d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1592d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1593d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
1594d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
1595d98.d9c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
1596d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
1597d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
1598d98.d9c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
1599d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtcorevbox4.dll'...
1600d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtcorevbox4.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qtcorevbox4.dll' [rcNtRedir=0xc0150008]
1601d98.d9c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll
1602d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
1603d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
1604d98.d9c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
1605d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
1606d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
1607d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1608d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1609d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
1610d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
1611d98.d9c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
1612d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winspool.drv'...
1613d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'winspool.drv' -> '\Device\HarddiskVolume2\Windows\System32\winspool.drv' [rcNtRedir=0xc0150008]
1614d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004c4 pwszName=\Device\HarddiskVolume2\Windows\System32\winspool.drv
1615d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006de810
1616d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
1617d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=C89A2ED7B99A056D78CA6BAC9CCAB8B1FF119A14
1618d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\winspool.drv'
1619d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1620d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1621d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
1622d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
1623d98.d9c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\winspool.drv) WinVerifyTrust
1624d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\winspool.drv
1625d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
1626d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
1627d98.d9c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
1628d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
1629d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume2\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
1630d98.d9c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\imm32.dll
1631d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
1632d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
1633d98.d9c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
1634d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comdlg32.dll'...
1635d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'comdlg32.dll' -> '\Device\HarddiskVolume2\Windows\System32\comdlg32.dll' [rcNtRedir=0xc0150008]
1636d98.d9c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\comdlg32.dll
1637d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1638d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1639d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
1640d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
1641d98.d9c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
1642d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtcorevbox4.dll'...
1643d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtcorevbox4.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qtcorevbox4.dll' [rcNtRedir=0xc0150008]
1644d98.d9c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll
1645d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtguivbox4.dll'...
1646d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtguivbox4.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qtguivbox4.dll' [rcNtRedir=0xc0150008]
1647d98.d9c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll
1648d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1649d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1650d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1651d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1652d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
1653d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
1654d98.d9c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
1655d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1656d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1657d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1658d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1659d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
1660d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
1661d98.d9c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll
1662d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1663d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1664d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
1665d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
1666d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1667d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1668d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1669d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1670d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1671d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1672d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1673d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1674d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1675d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1676d98.d9c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll
1677d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
1678d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
1679d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1680d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1681d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
1682d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
1683d98.d9c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
1684d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
1685d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
1686d98.d9c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
1687d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comctl32.dll'...
1688d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'comctl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\comctl32.dll' [rcNtRedir=0x0]
1689d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004d4 pwszName=\Device\HarddiskVolume2\Windows\System32\comctl32.dll
1690d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006de810
1691d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
1692d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=761964761EE466757E306124E042F4C2ACBEA092
1693d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3059317~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\Windows\System32\comctl32.dll'
1694d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1695d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'advapi32.dll'.
1696d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
1697d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
1698d98.d9c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\comctl32.dll) WinVerifyTrust
1699d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\comctl32.dll
1700d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1701d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1702d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1703d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1704d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
1705d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
1706d98.d9c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll
1707d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1708d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1709d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1710d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1711d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1712d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1713d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1714d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1715d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1716d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1717d98.d9c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll
1718d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
1719d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
1720d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1721d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1722d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1723d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1724d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1725d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1726d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1727d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1728d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
1729d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
1730d98.d9c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
1731d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1732d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1733d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dwmapi.dll'...
1734d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'dwmapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\dwmapi.dll' [rcNtRedir=0xc0150008]
1735d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000498 pwszName=\Device\HarddiskVolume2\Windows\System32\dwmapi.dll
1736d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006de810
1737d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
1738d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=C408F88301F22BE596490B4A80BD2E09034763B4
1739d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3048761~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\Windows\System32\dwmapi.dll'
1740d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1741d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1742d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
1743d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
1744d98.d9c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\dwmapi.dll) WinVerifyTrust
1745d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\dwmapi.dll
1746d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
1747d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
1748d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004b0 pwszName=\Device\HarddiskVolume2\Windows\System32\setupapi.dll
1749d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006de810
1750d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
1751d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=1499C4FEA6E143F9BEC35B4FFA098917D3A6EBF2
1752d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\setupapi.dll'
1753d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1754d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'cfgmgr32.dll'.
1755d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcrt.dll'.
1756d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'gdi32.dll'.
1757d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
1758d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'user32.dll'.
1759d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'oleaut32.dll'.
1760d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'devobj.dll'.
1761d98.d9c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\setupapi.dll) WinVerifyTrust
1762d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\setupapi.dll
1763d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1764d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1765d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dciman32.dll'...
1766d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'dciman32.dll' -> '\Device\HarddiskVolume2\Windows\System32\dciman32.dll' [rcNtRedir=0xc0150008]
1767d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004e4 pwszName=\Device\HarddiskVolume2\Windows\System32\dciman32.dll
1768d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006de810
1769d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
1770d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=8C17410BD716DCF557221B982F7A015B5B6AC2B4
1771d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3032323~31bf3856ad364e35~amd64~~6.1.1.3.cat'; file='\Device\HarddiskVolume2\Windows\System32\dciman32.dll'
1772d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1773d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1774d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'gdi32.dll'.
1775d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
1776d98.d9c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\dciman32.dll) WinVerifyTrust
1777d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\dciman32.dll
1778d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1779d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1780d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1781d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1782d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1783d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1784d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1785d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1786d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1787d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1788d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'devobj.dll'...
1789d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'devobj.dll' -> '\Device\HarddiskVolume2\Windows\System32\devobj.dll' [rcNtRedir=0xc0150008]
1790d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004ec pwszName=\Device\HarddiskVolume2\Windows\System32\devobj.dll
1791d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006de810
1792d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
1793d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B410A095222E69F0ECE7D66E4AC27A7125D2EB5A
1794d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\devobj.dll'
1795d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1796d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1797d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'cfgmgr32.dll'.
1798d98.d9c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\devobj.dll) WinVerifyTrust
1799d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\devobj.dll
1800d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
1801d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
1802d98.d9c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
1803d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1804d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1805d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
1806d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
1807d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1808d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1809d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1810d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1811d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
1812d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
1813d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004e0 pwszName=\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll
1814d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006de810
1815d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
1816d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=8F731777EFC4BC982C1E1467FBF29A74CC14D93A
1817d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll'
1818d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1819d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1820d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'rpcrt4.dll'.
1821d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
1822d98.d9c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll) WinVerifyTrust
1823d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll
1824d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1825d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1826d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1827d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1828d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1829d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1830d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
1831d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
1832d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
1833d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
1834d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1835d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1836d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
1837d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
1838d98.d9c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll
1839d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1840d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1841d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VirtualBox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000704870:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
1842d98.d9c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.dll
1843d98.d9c: supR3HardenedDllNotificationCallback: load 000007fef2850000 LB 0x00abb000 C:\Program Files\Oracle\VirtualBox\VirtualBox.dll [fFlags=0x0]
1844d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.dll
1845d98.d9c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
1846d98.d9c: supR3HardenedDllNotificationCallback: load 000007fef3f90000 LB 0x0011d000 C:\Windows\system32\OPENGL32.dll [fFlags=0x0]
1847d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
1848d98.d9c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\glu32.dll
1849d98.d9c: supR3HardenedDllNotificationCallback: load 000007fef4680000 LB 0x0002d000 C:\Windows\system32\GLU32.dll [fFlags=0x0]
1850d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\glu32.dll
1851d98.d9c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ddraw.dll
1852d98.d9c: supR3HardenedDllNotificationCallback: load 000007fef3e90000 LB 0x000f1000 C:\Windows\system32\DDRAW.dll [fFlags=0x0]
1853d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ddraw.dll
1854d98.d9c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dciman32.dll
1855d98.d9c: supR3HardenedDllNotificationCallback: load 000007fef4e40000 LB 0x00008000 C:\Windows\system32\DCIMAN32.dll [fFlags=0x0]
1856d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dciman32.dll
1857d98.d9c: supR3HardenedDllNotificationCallback: load 000007feff8e0000 LB 0x001d7000 C:\Windows\system32\SETUPAPI.dll [fFlags=0x0]
1858d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\setupapi.dll
1859d98.d9c: supR3HardenedDllNotificationCallback: load 000007fefd6a0000 LB 0x00036000 C:\Windows\system32\CFGMGR32.dll [fFlags=0x0]
1860d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll
1861d98.d9c: supR3HardenedDllNotificationCallback: load 000007feff540000 LB 0x000d7000 C:\Windows\system32\OLEAUT32.dll [fFlags=0x0]
1862d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
1863d98.d9c: supR3HardenedDllNotificationCallback: load 000007feff6c0000 LB 0x00203000 C:\Windows\system32\ole32.dll [fFlags=0x0]
1864d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
1865d98.d9c: supR3HardenedDllNotificationCallback: load 000007fefd6e0000 LB 0x0001a000 C:\Windows\system32\DEVOBJ.dll [fFlags=0x0]
1866d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\devobj.dll
1867d98.d9c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dwmapi.dll
1868d98.d9c: supR3HardenedDllNotificationCallback: load 000007fefba20000 LB 0x00018000 C:\Windows\system32\dwmapi.dll [fFlags=0x0]
1869d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dwmapi.dll
1870d98.d9c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll
1871d98.d9c: supR3HardenedDllNotificationCallback: load 0000000074d00000 LB 0x002de000 C:\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll [fFlags=0x0]
1872d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll
1873d98.d9c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll
1874d98.d9c: supR3HardenedDllNotificationCallback: load 0000000074390000 LB 0x0096c000 C:\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll [fFlags=0x0]
1875d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll
1876d98.d9c: supR3HardenedDllNotificationCallback: load 000007feff620000 LB 0x00097000 C:\Windows\system32\COMDLG32.dll [fFlags=0x0]
1877d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\comdlg32.dll
1878d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'advapi32.dll'.
1879d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
1880d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
1881d98.d9c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll)
1882d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll
1883d98.d9c: supR3HardenedDllNotificationCallback: load 000007fef8140000 LB 0x000a0000 C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\COMCTL32.dll [fFlags=0x0]
1884d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll [avoiding WinVerifyTrust]
1885d98.d9c: supR3HardenedDllNotificationCallback: load 000007fefe4a0000 LB 0x00d89000 C:\Windows\system32\SHELL32.dll [fFlags=0x0]
1886d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
1887d98.d9c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
1888d98.d9c: supR3HardenedDllNotificationCallback: load 000007fefb6b0000 LB 0x0003b000 C:\Windows\system32\WINMM.dll [fFlags=0x0]
1889d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
1890d98.d9c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winspool.drv
1891d98.d9c: supR3HardenedDllNotificationCallback: load 000007fef8480000 LB 0x00071000 C:\Windows\system32\WINSPOOL.DRV [fFlags=0x0]
1892d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winspool.drv
1893d98.d9c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll
1894d98.d9c: supR3HardenedDllNotificationCallback: load 00000000742b0000 LB 0x000dc000 C:\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll [fFlags=0x0]
1895d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll
1896d98.d9c: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume2\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll'.
1897d98.d9c: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll' [rescheduled]
1898d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\imm32.dll
1899d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1900d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1901d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1902d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1903d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
1904d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
1905d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\imm32.dll (Input=imm32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000704b40:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
1906d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff380000 'C:\Windows\system32\imm32.dll'
1907d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef2850000 'C:\Program Files\Oracle\VirtualBox\VirtualBox.dll'
1908d98.d9c: SUPR3HardenedMain: Calling TrustedMain (000007fef28510d0)...
1909d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
1910d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\winmm.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000704870:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
1911d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefb6b0000 'C:\Windows\system32\winmm.dll'
1912d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000584 pwszName=\Device\HarddiskVolume2\Windows\System32\uxtheme.dll
1913d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006de810
1914d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
1915d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=936D45CC7026757A151F62882B557DD75D5FCB21
1916d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\uxtheme.dll'
1917d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1918d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1919d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
1920d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'gdi32.dll'.
1921d98.d9c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\uxtheme.dll) WinVerifyTrust
1922d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
1923d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1924d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1925d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1926d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1927d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1928d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1929d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000292c740:C:\Windows\system32;C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
1930d98.d9c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
1931d98.d9c: supR3HardenedDllNotificationCallback: load 000007fefbe50000 LB 0x00056000 C:\Windows\system32\uxtheme.dll [fFlags=0x0]
1932d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
1933d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbe50000 'C:\Windows\system32\uxtheme.dll'
1934d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
1935d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000292c740:C:\Windows\system32;C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
1936d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbe50000 'C:\Windows\system32\uxtheme.dll'
1937d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
1938d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000292d450:C:\Windows\system32;C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
1939d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbe50000 'C:\Windows\system32\uxtheme.dll'
1940d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
1941d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000292d450:C:\Windows\system32;C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
1942d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbe50000 'C:\Windows\system32\uxtheme.dll'
1943d98.d9c: \Device\HarddiskVolume2\Program Files (x86)\TeamViewer\tv_x64.dll: Owner is administrators group.
1944d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'version.dll'.
1945d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'comctl32.dll'.
1946d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
1947d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'gdi32.dll'.
1948d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'shell32.dll'.
1949d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ole32.dll'.
1950d98.d9c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files (x86)\TeamViewer\tv_x64.dll) WinVerifyTrust
1951d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files (x86)\TeamViewer\tv_x64.dll
1952d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
1953d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
1954d98.d9c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
1955d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
1956d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
1957d98.d9c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
1958d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1959d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1960d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1961d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1962d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comctl32.dll'...
1963d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'comctl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\comctl32.dll' [rcNtRedir=0x0]
1964d98.d9c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\comctl32.dll
1965d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'version.dll'...
1966d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'version.dll' -> '\Device\HarddiskVolume2\Windows\System32\version.dll' [rcNtRedir=0xc0150008]
1967d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000005a8 pwszName=\Device\HarddiskVolume2\Windows\System32\version.dll
1968d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006de810
1969d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
1970d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=A3AB94A028D0330A3DBCAE54C04C648532198DB9
1971d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\version.dll'
1972d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1973d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
1974d98.d9c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\version.dll) WinVerifyTrust
1975d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\version.dll
1976d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1977d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1978d98.d9c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
1979d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files (x86)\TeamViewer\tv_x64.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007275c0:C:\Program Files (x86)\TeamViewer;C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
1980d98.d9c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files (x86)\TeamViewer\tv_x64.dll
1981d98.d9c: supR3HardenedDllNotificationCallback: load 000007fef6ca0000 LB 0x00048000 C:\Program Files (x86)\TeamViewer\tv_x64.dll [fFlags=0x0]
1982d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files (x86)\TeamViewer\tv_x64.dll
1983d98.d9c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\version.dll
1984d98.d9c: supR3HardenedDllNotificationCallback: load 000007fefc6c0000 LB 0x0000c000 C:\Windows\system32\VERSION.dll [fFlags=0x0]
1985d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\version.dll
1986d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef6ca0000 'C:\Program Files (x86)\TeamViewer\tv_x64.dll'
1987d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe320000 'C:\Windows\system32\advapi32.dll'
1988d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dwmapi.dll
1989d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\dwmapi.dll (Input=dwmapi.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000704870:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
1990d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefba20000 'C:\Windows\system32\dwmapi.dll'
1991d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cryptbase.dll
1992d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTBASE.dll (Input=CRYPTBASE.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000704870:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
1993d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd470000 'C:\Windows\system32\CRYPTBASE.dll'
1994d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
1995d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000704870:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
1996d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe4a0000 'C:\Windows\system32\shell32.dll'
1997d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll
1998d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000704870:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
1999d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077700000 'C:\Windows\system32\kernel32.dll'
2000d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
2001d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000704870:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2002d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbe50000 'C:\Windows\system32\uxtheme.dll'
2003d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
2004d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000704870:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2005d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbe50000 'C:\Windows\system32\uxtheme.dll'
2006d98.d9c: supR3HardenedMonitor_LdrLoadDll: error opening 'C:\Windows\system32\wintab32.dll': 0 (NtPath=\??\C:\Windows\system32\wintab32.dll; Input=C:\Windows\system32\wintab32.dll; rcNtGetDll=0x0
2007d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wintab32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000704870:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2008d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000135 'C:\Windows\system32\wintab32.dll'
2009d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077600000 'C:\Windows\system32\user32.dll'
2010d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
2011d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000704870:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2012d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbe50000 'C:\Windows\system32\uxtheme.dll'
2013d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077600000 'C:\Windows\system32\user32.dll'
2014d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe320000 'C:\Windows\system32\advapi32.dll'
2015d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\userenv.dll
2016d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\userenv.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000704870:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2017d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd970000 'C:\Windows\system32\userenv.dll'
2018d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll
2019d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000704870:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2020d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077700000 'C:\Windows\system32\kernel32.dll'
2021d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000620 pwszName=\Device\HarddiskVolume2\Windows\System32\clbcatq.dll
2022d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006de810
2023d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
2024d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B01469787CE9D8C6FEE98FB207652B88B8494526
2025d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\clbcatq.dll'
2026d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2027d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
2028d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'ole32.dll'.
2029d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
2030d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
2031d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
2032d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'rpcrt4.dll'.
2033d98.d9c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\clbcatq.dll) WinVerifyTrust
2034d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\clbcatq.dll
2035d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
2036d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
2037d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
2038d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
2039d98.d9c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
2040d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
2041d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
2042d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
2043d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
2044d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
2045d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
2046d98.d9c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
2047d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
2048d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
2049d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CLBCatQ.DLL (Input=CLBCatQ.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000704870:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2050d98.d9c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\clbcatq.dll
2051d98.d9c: supR3HardenedDllNotificationCallback: load 000007feff430000 LB 0x00099000 C:\Windows\system32\CLBCatQ.DLL [fFlags=0x0]
2052d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\clbcatq.dll
2053d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff430000 'C:\Windows\system32\CLBCatQ.DLL'
2054d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
2055d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ADVAPI32.dll (Input=ADVAPI32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000704ea0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2056d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe320000 'C:\Windows\system32\ADVAPI32.dll'
2057d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cryptsp.dll
2058d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTSP.dll (Input=CRYPTSP.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000704b40:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2059d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcdd0000 'C:\Windows\system32\CRYPTSP.dll'
2060d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000640 pwszName=\Device\HarddiskVolume2\Windows\System32\RpcRtRemote.dll
2061d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006de810
2062d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
2063d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=DFC4A7C7E103D324218E6EF5D219B953746D6EC1
2064d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\RpcRtRemote.dll'
2065d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2066d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'rpcrt4.dll'.
2067d98.d9c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\RpcRtRemote.dll) WinVerifyTrust
2068d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\RpcRtRemote.dll
2069d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
2070d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
2071d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\RpcRtRemote.dll (Input=RpcRtRemote.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000704b40:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2072d98.d9c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\RpcRtRemote.dll
2073d98.d9c: supR3HardenedDllNotificationCallback: load 000007fefd520000 LB 0x00014000 C:\Windows\system32\RpcRtRemote.dll [fFlags=0x0]
2074d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\RpcRtRemote.dll
2075d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd520000 'C:\Windows\system32\RpcRtRemote.dll'
2076d98.e30: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
2077d98.e30: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
2078d98.e30: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'psapi.dll'.
2079d98.e30: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vboxrt.dll'.
2080d98.e30: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'advapi32.dll'.
2081d98.e30: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'version.dll'.
2082d98.e30: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'ws2_32.dll'.
2083d98.e30: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'ole32.dll'.
2084d98.e30: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'oleaut32.dll'.
2085d98.e30: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxC.dll) WinVerifyTrust
2086d98.e30: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxC.dll
2087d98.e30: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
2088d98.e30: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
2089d98.e30: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
2090d98.e30: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
2091d98.e30: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
2092d98.e30: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
2093d98.e30: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
2094d98.e30: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
2095d98.e30: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
2096d98.e30: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'version.dll'...
2097d98.e30: supR3HardenedWinVerifyCacheProcessImportTodos: 'version.dll' -> '\Device\HarddiskVolume2\Windows\System32\version.dll' [rcNtRedir=0xc0150008]
2098d98.e30: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\version.dll
2099d98.e30: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
2100d98.e30: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
2101d98.e30: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
2102d98.e30: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
2103d98.e30: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'psapi.dll'...
2104d98.e30: supR3HardenedWinVerifyCacheProcessImportTodos: 'psapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\psapi.dll' [rcNtRedir=0xc0150008]
2105d98.e30: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000680 pwszName=\Device\HarddiskVolume2\Windows\System32\psapi.dll
2106d98.e30: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006de810
2107d98.e30: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
2108d98.e30: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=561BAAB249C395B66D294444DF251EDB701DB607
2109d98.e30: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\psapi.dll'
2110d98.e30: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2111d98.e30: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\psapi.dll) WinVerifyTrust
2112d98.e30: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\psapi.dll
2113d98.e30: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
2114d98.e30: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
2115d98.e30: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
2116d98.e30: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
2117d98.e30: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
2118d98.e30: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
2119d98.e30: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxC.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000727900:C:\Program Files\Oracle\VirtualBox;C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2120d98.e30: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxC.dll
2121d98.e30: supR3HardenedDllNotificationCallback: load 000007fef1460000 LB 0x005d7000 C:\Program Files\Oracle\VirtualBox\VBoxC.dll [fFlags=0x0]
2122d98.e30: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxC.dll
2123d98.e30: supR3HardenedDllNotificationCallback: load 00000000779e0000 LB 0x00007000 C:\Windows\system32\PSAPI.DLL [fFlags=0x0]
2124d98.e30: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\psapi.dll
2125d98.e30: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef1460000 'C:\Program Files\Oracle\VirtualBox\VBoxC.dll'
2126d98.e30: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
2127d98.e30: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\oleaut32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000292d500:C:\Windows\system32;C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2128d98.e30: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff540000 'C:\Windows\system32\oleaut32.dll'
2129d98.e30: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000006a4 pwszName=\Device\HarddiskVolume2\Windows\System32\sxs.dll
2130d98.e30: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006de810
2131d98.e30: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
2132d98.e30: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=FCAC019C19F878C2B628662A84ECE75A01818BC9
2133d98.e30: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\sxs.dll'
2134d98.e30: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2135d98.e30: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\sxs.dll) WinVerifyTrust
2136d98.e30: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\sxs.dll
2137d98.e30: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\SXS.DLL (Input=SXS.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007053b0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2138d98.e30: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\sxs.dll
2139d98.e30: supR3HardenedDllNotificationCallback: load 000007fefd480000 LB 0x00091000 C:\Windows\system32\SXS.DLL [fFlags=0x0]
2140d98.e30: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\sxs.dll
2141d98.e30: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd480000 'C:\Windows\system32\SXS.DLL'
2142d98.e30: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe320000 'C:\Windows\system32\ADVAPI32.dll'
2143d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
2144d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\OLEAUT32.dll (Input=OLEAUT32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007058c0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2145d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff540000 'C:\Windows\system32\OLEAUT32.dll'
2146d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe320000 'C:\Windows\system32\ADVAPI32.dll'
2147d98.d9c: supR3HardenedMonitor_LdrLoadDll: error opening 'C:\Windows\system32\wintab32.dll': 0 (NtPath=\??\C:\Windows\system32\wintab32.dll; Input=C:\Windows\system32\wintab32.dll; rcNtGetDll=0x0
2148d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wintab32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007058c0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2149d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000135 'C:\Windows\system32\wintab32.dll'
2150d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feffac0000 'C:\Windows\system32\gdi32.dll'
2151d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll
2152d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\user32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000705830:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2153d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077600000 'C:\Windows\system32\user32.dll'
2154d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
2155d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000705830:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2156d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe4a0000 'C:\Windows\system32\shell32.dll'
2157d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000a6c pwszName=\Device\HarddiskVolume2\Windows\System32\apphelp.dll
2158d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006de810
2159d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
2160d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=8FFB8CDACDC5C9C6D9256E97FB0710E2753FFAA1
2161d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3045645~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\Windows\System32\apphelp.dll'
2162d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2163d98.d9c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\apphelp.dll) WinVerifyTrust
2164d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\apphelp.dll
2165d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\apphelp.dll (rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
2166d98.d9c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\apphelp.dll
2167d98.d9c: supR3HardenedDllNotificationCallback: load 000007fefd3d0000 LB 0x00057000 C:\Windows\system32\apphelp.dll [fFlags=0x0]
2168d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\apphelp.dll
2169d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd3d0000 'C:\Windows\system32\apphelp.dll'
2170d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'vboxoglhostcrutil.dll'.
2171d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
2172d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcr100.dll'.
2173d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qtcorevbox4.dll'.
2174d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qtguivbox4.dll'.
2175d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'qtopenglvbox4.dll'.
2176d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'opengl32.dll'.
2177d98.d9c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxTestOGL.exe)
2178d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxTestOGL.exe
2179d98.d9c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxTestOGL.exe'
2180d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
2181d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
2182d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
2183d98.d9c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
2184d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtopenglvbox4.dll'...
2185d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtopenglvbox4.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qtopenglvbox4.dll' [rcNtRedir=0xc0150008]
2186d98.d9c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll
2187d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtguivbox4.dll'...
2188d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtguivbox4.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qtguivbox4.dll' [rcNtRedir=0xc0150008]
2189d98.d9c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll
2190d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtcorevbox4.dll'...
2191d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtcorevbox4.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qtcorevbox4.dll' [rcNtRedir=0xc0150008]
2192d98.d9c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll
2193d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
2194d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
2195d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
2196d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
2197d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxoglhostcrutil.dll'...
2198d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxoglhostcrutil.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxoglhostcrutil.dll' [rcNtRedir=0xc0150008]
2199d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
2200d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
2201d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'shlwapi.dll'.
2202d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ws2_32.dll'.
2203d98.d9c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLhostcrutil.dll) WinVerifyTrust
2204d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLhostcrutil.dll
2205d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
2206d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
2207d98.d9c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
2208d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
2209d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
2210d98.d9c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll
2211d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
2212d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
2213d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
2214d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
2215d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ole32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000705830:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2216d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff6c0000 'C:\Windows\system32\ole32.dll'
2217d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
2218d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007054d0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2219d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe4a0000 'C:\Windows\system32\shell32.dll'
2220d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
2221d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007054d0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2222d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe4a0000 'C:\Windows\system32\shell32.dll'
2223d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff6c0000 'C:\Windows\system32\ole32.dll'
2224d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
2225d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\OLEAUT32.dll (Input=OLEAUT32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007054d0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2226d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff540000 'C:\Windows\system32\OLEAUT32.dll'
2227d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000ae0 pwszName=\Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll
2228d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006de810
2229d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
2230d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=41D7AA7A9ECA84ABF6801478BA3134174B21C472
2231d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll'
2232d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2233d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
2234d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'wbemcomn.dll'.
2235d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
2236d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
2237d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ole32.dll'.
2238d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'ws2_32.dll'.
2239d98.d9c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll) WinVerifyTrust
2240d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll
2241d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
2242d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
2243d98.d9c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
2244d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
2245d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
2246d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
2247d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
2248d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
2249d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
2250d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wbemcomn.dll'...
2251d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'wbemcomn.dll' -> '\Device\HarddiskVolume2\Windows\System32\wbemcomn.dll' [rcNtRedir=0xc0150008]
2252d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000ae8 pwszName=\Device\HarddiskVolume2\Windows\System32\wbemcomn.dll
2253d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006de810
2254d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
2255d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=03D0A77E5195AA70198FDE6C2FAC2C76FF200674
2256d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\wbemcomn.dll'
2257d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2258d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
2259d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'oleaut32.dll'.
2260d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'ole32.dll'.
2261d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
2262d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ws2_32.dll'.
2263d98.d9c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\wbemcomn.dll) WinVerifyTrust
2264d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wbemcomn.dll
2265d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
2266d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
2267d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
2268d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
2269d98.d9c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
2270d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
2271d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
2272d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
2273d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
2274d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
2275d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
2276d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
2277d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
2278d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wbem\wbemprox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000032e4a30:C:\Windows\system32\wbem;C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2279d98.d9c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll
2280d98.d9c: supR3HardenedDllNotificationCallback: load 000007fef9670000 LB 0x0000f000 C:\Windows\system32\wbem\wbemprox.dll [fFlags=0x0]
2281d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll
2282d98.d9c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbemcomn.dll
2283d98.d9c: supR3HardenedDllNotificationCallback: load 000007fef9920000 LB 0x00086000 C:\Windows\system32\wbemcomn.dll [fFlags=0x0]
2284d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbemcomn.dll
2285d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef9670000 'C:\Windows\system32\wbem\wbemprox.dll'
2286d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000b18 pwszName=\Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll
2287d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006de810
2288d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
2289d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=83AB88529BF28CFF670EA617E0B9C376CFE28B0F
2290d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll'
2291d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2292d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
2293d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'rpcrt4.dll'.
2294d98.d9c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll) WinVerifyTrust
2295d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll
2296d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
2297d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
2298d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
2299d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
2300d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wbem\wbemsvc.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000032e4a30:C:\Windows\system32\wbem;C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2301d98.d9c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll
2302d98.d9c: supR3HardenedDllNotificationCallback: load 000007fef9190000 LB 0x00014000 C:\Windows\system32\wbem\wbemsvc.dll [fFlags=0x0]
2303d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll
2304d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef9190000 'C:\Windows\system32\wbem\wbemsvc.dll'
2305d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000b3c pwszName=\Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll
2306d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006de810
2307d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
2308d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=391AD7580DBA8EA6A4190F5A010E834B8C320D79
2309d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll'
2310d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2311d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
2312d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'wbemcomn.dll'.
2313d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
2314d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'oleaut32.dll'.
2315d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ole32.dll'.
2316d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ntdsapi.dll'.
2317d98.d9c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll) WinVerifyTrust
2318d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll
2319d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntdsapi.dll'...
2320d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntdsapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\ntdsapi.dll' [rcNtRedir=0xc0150008]
2321d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000b2c pwszName=\Device\HarddiskVolume2\Windows\System32\ntdsapi.dll
2322d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006de810
2323d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
2324d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=67C74E045820FCAB3FC8AD5C180928A20C1F11CE
2325d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\ntdsapi.dll'
2326d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2327d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
2328d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'rpcrt4.dll'.
2329d98.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'ws2_32.dll'.
2330d98.d9c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ntdsapi.dll) WinVerifyTrust
2331d98.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ntdsapi.dll
2332d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
2333d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
2334d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
2335d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
2336d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
2337d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
2338d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wbemcomn.dll'...
2339d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'wbemcomn.dll' -> '\Device\HarddiskVolume2\Windows\System32\wbemcomn.dll' [rcNtRedir=0xc0150008]
2340d98.d9c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbemcomn.dll
2341d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
2342d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
2343d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
2344d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
2345d98.d9c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
2346d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
2347d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
2348d98.d9c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
2349d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
2350d98.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
2351d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wbem\fastprox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000032e4f70:C:\Windows\system32\wbem;C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2352d98.d9c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll
2353d98.d9c: supR3HardenedDllNotificationCallback: load 000007fef9750000 LB 0x000e2000 C:\Windows\system32\wbem\fastprox.dll [fFlags=0x0]
2354d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll
2355d98.d9c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ntdsapi.dll
2356d98.d9c: supR3HardenedDllNotificationCallback: load 000007fef9720000 LB 0x00027000 C:\Windows\system32\NTDSAPI.dll [fFlags=0x0]
2357d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ntdsapi.dll
2358d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef9750000 'C:\Windows\system32\wbem\fastprox.dll'
2359d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff540000 'C:\Windows\system32\OLEAUT32.dll'
2360d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
2361d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\WINMM.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000705560:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2362d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefb6b0000 'C:\Windows\system32\WINMM.dll'
2363d98.e8c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
2364d98.e8c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrem.dll'.
2365d98.e8c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
2366d98.e8c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll) WinVerifyTrust
2367d98.e8c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
2368d98.e8c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
2369d98.e8c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
2370d98.e8c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrem.dll'...
2371d98.e8c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrem.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrem.dll' [rcNtRedir=0xc0150008]
2372d98.e8c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'vboxrt.dll'.
2373d98.e8c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
2374d98.e8c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcrt.dll'.
2375d98.e8c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxREM.dll) WinVerifyTrust
2376d98.e8c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxREM.dll
2377d98.e8c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
2378d98.e8c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
2379d98.e8c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
2380d98.e8c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
2381d98.e8c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
2382d98.e8c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
2383d98.e8c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
2384d98.e8c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
2385d98.e8c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
2386d98.e8c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000705440:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2387d98.e8c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
2388d98.e8c: supR3HardenedDllNotificationCallback: load 000007feeeee0000 LB 0x0029c000 C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL [fFlags=0x0]
2389d98.e8c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
2390d98.e8c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxREM.dll
2391d98.e8c: supR3HardenedDllNotificationCallback: load 0000000074130000 LB 0x0010a000 C:\Program Files\Oracle\VirtualBox\VBoxREM.dll [fFlags=0x0]
2392d98.e8c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxREM.dll
2393d98.e8c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeeee0000 'C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL'
2394d98.ea8: \Device\HarddiskVolume2\Windows\System32\drivers\VBoxNetAdp6.sys: Owner is administrators group.
2395d98.ea8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ndis.sys'.
2396d98.ea8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'ntoskrnl.exe'.
2397d98.ea8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\drivers\VBoxNetAdp6.sys)
2398d98.ea8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\drivers\VBoxNetAdp6.sys
2399d98.ea8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\drivers\VBoxNetAdp6.sys [avoiding WinVerifyTrust]
2400d98.ea8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
2401d98.ea8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'ndis.sys'.
2402d98.ea8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'netio.sys'.
2403d98.ea8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\drivers\VBoxNetLwf.sys)
2404d98.ea8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\drivers\VBoxNetLwf.sys
2405d98.ea8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\drivers\VBoxNetLwf.sys [avoiding WinVerifyTrust]
2406d98.ea8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
2407d98.ea8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\drivers\VBoxUSBMon.sys)
2408d98.ea8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\drivers\VBoxUSBMon.sys
2409d98.ea8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\drivers\VBoxUSBMon.sys [avoiding WinVerifyTrust]
2410d98.ea8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
2411d98.ea8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\drivers\VBoxDrv.sys)
2412d98.ea8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\drivers\VBoxDrv.sys
2413d98.ea8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\drivers\VBoxDrv.sys [avoiding WinVerifyTrust]
2414d98.ecc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\drivers\VBoxDrv.sys'
2415d98.ecc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\drivers\VBoxUSBMon.sys'
2416d98.ecc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\drivers\VBoxNetLwf.sys'
2417d98.ecc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\drivers\VBoxNetAdp6.sys'
2418d98.ecc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
2419d98.ecc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
2420d98.ecc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
2421d98.ecc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
2422d98.ecc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll) WinVerifyTrust
2423d98.ecc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll
2424d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
2425d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
2426d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
2427d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
2428d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
2429d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
2430d98.ecc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
2431d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
2432d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
2433d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
2434d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume2\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
2435d98.ecc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'pshed.dll'.
2436d98.ecc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'hal.dll'.
2437d98.ecc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'kdcom.dll'.
2438d98.ecc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'clfs.sys'.
2439d98.ecc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ci.dll'.
2440d98.ecc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ntoskrnl.exe) WinVerifyTrust
2441d98.ecc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ntoskrnl.exe
2442d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
2443d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume2\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
2444d98.ecc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ntoskrnl.exe
2445d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'netio.sys'...
2446d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: 'netio.sys' -> '\Device\HarddiskVolume2\Windows\System32\drivers\netio.sys' [rcNtRedir=0xc0150008]
2447d98.ecc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
2448d98.ecc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'ndis.sys'.
2449d98.ecc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msrpc.sys'.
2450d98.ecc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\drivers\netio.sys) WinVerifyTrust
2451d98.ecc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\drivers\netio.sys
2452d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ndis.sys'...
2453d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: 'ndis.sys' -> '\Device\HarddiskVolume2\Windows\System32\drivers\ndis.sys' [rcNtRedir=0xc0150008]
2454d98.ecc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
2455d98.ecc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'hal.dll'.
2456d98.ecc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'netio.sys'.
2457d98.ecc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\drivers\ndis.sys) WinVerifyTrust
2458d98.ecc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\drivers\ndis.sys
2459d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
2460d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume2\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
2461d98.ecc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ntoskrnl.exe
2462d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
2463d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume2\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
2464d98.ecc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ntoskrnl.exe
2465d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ndis.sys'...
2466d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: 'ndis.sys' -> '\Device\HarddiskVolume2\Windows\System32\drivers\ndis.sys' [rcNtRedir=0xc0150008]
2467d98.ecc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\drivers\ndis.sys
2468d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'netio.sys'...
2469d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: 'netio.sys' -> '\Device\HarddiskVolume2\Windows\System32\drivers\netio.sys' [rcNtRedir=0xc0150008]
2470d98.ecc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\drivers\netio.sys
2471d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'hal.dll'...
2472d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: 'hal.dll' -> '\Device\HarddiskVolume2\Windows\System32\hal.dll' [rcNtRedir=0xc0150008]
2473d98.ecc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
2474d98.ecc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'kdcom.dll'.
2475d98.ecc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'pshed.dll'.
2476d98.ecc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\hal.dll) WinVerifyTrust
2477d98.ecc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\hal.dll
2478d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
2479d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume2\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
2480d98.ecc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ntoskrnl.exe
2481d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msrpc.sys'...
2482d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msrpc.sys' -> '\Device\HarddiskVolume2\Windows\System32\drivers\msrpc.sys' [rcNtRedir=0xc0150008]
2483d98.ecc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
2484d98.ecc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\drivers\msrpc.sys) WinVerifyTrust
2485d98.ecc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\drivers\msrpc.sys
2486d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ndis.sys'...
2487d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: 'ndis.sys' -> '\Device\HarddiskVolume2\Windows\System32\drivers\ndis.sys' [rcNtRedir=0xc0150008]
2488d98.ecc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\drivers\ndis.sys
2489d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
2490d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume2\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
2491d98.ecc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ntoskrnl.exe
2492d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ci.dll'...
2493d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: 'ci.dll' -> '\Device\HarddiskVolume2\Windows\System32\ci.dll' [rcNtRedir=0xc0150008]
2494d98.ecc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
2495d98.ecc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ci.dll) WinVerifyTrust
2496d98.ecc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ci.dll
2497d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'clfs.sys'...
2498d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: 'clfs.sys' -> '\Device\HarddiskVolume2\Windows\System32\clfs.sys' [rcNtRedir=0xc0150008]
2499d98.ecc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
2500d98.ecc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\clfs.sys) WinVerifyTrust
2501d98.ecc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\clfs.sys
2502d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'kdcom.dll'...
2503d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: 'kdcom.dll' -> '\Device\HarddiskVolume2\Windows\System32\kdcom.dll' [rcNtRedir=0xc0150008]
2504d98.ecc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
2505d98.ecc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'hal.dll'.
2506d98.ecc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\kdcom.dll) WinVerifyTrust
2507d98.ecc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\kdcom.dll
2508d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'hal.dll'...
2509d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: 'hal.dll' -> '\Device\HarddiskVolume2\Windows\System32\hal.dll' [rcNtRedir=0xc0150008]
2510d98.ecc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\hal.dll
2511d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'pshed.dll'...
2512d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: 'pshed.dll' -> '\Device\HarddiskVolume2\Windows\System32\pshed.dll' [rcNtRedir=0xc0150008]
2513d98.ecc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
2514d98.ecc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'hal.dll'.
2515d98.ecc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\PSHED.DLL) WinVerifyTrust
2516d98.ecc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\PSHED.DLL
2517d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'hal.dll'...
2518d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: 'hal.dll' -> '\Device\HarddiskVolume2\Windows\System32\hal.dll' [rcNtRedir=0xc0150008]
2519d98.ecc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\hal.dll
2520d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
2521d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume2\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
2522d98.ecc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ntoskrnl.exe
2523d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'hal.dll'...
2524d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: 'hal.dll' -> '\Device\HarddiskVolume2\Windows\System32\hal.dll' [rcNtRedir=0xc0150008]
2525d98.ecc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\hal.dll
2526d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
2527d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume2\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
2528d98.ecc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ntoskrnl.exe
2529d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
2530d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume2\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
2531d98.ecc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ntoskrnl.exe
2532d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
2533d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume2\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
2534d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
2535d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume2\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
2536d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'pshed.dll'...
2537d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: 'pshed.dll' -> '\Device\HarddiskVolume2\Windows\System32\pshed.dll' [rcNtRedir=0xc0150008]
2538d98.ecc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\PSHED.DLL
2539d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'kdcom.dll'...
2540d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: 'kdcom.dll' -> '\Device\HarddiskVolume2\Windows\System32\kdcom.dll' [rcNtRedir=0xc0150008]
2541d98.ecc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\kdcom.dll
2542d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
2543d98.ecc: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume2\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
2544d98.ecc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000705440:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2545d98.ecc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll
2546d98.ecc: supR3HardenedDllNotificationCallback: load 000007fef86e0000 LB 0x0000a000 C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL [fFlags=0x0]
2547d98.ecc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll
2548d98.ecc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef86e0000 'C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL'
2549d98.ed4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
2550d98.ed4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
2551d98.ed4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
2552d98.ed4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll) WinVerifyTrust
2553d98.ed4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll
2554d98.ed4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
2555d98.ed4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
2556d98.ed4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
2557d98.ed4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
2558d98.ed4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
2559d98.ed4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
2560d98.ed4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
2561d98.ed4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000705440:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2562d98.ed4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll
2563d98.ed4: supR3HardenedDllNotificationCallback: load 000007fef86d0000 LB 0x0000d000 C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL [fFlags=0x0]
2564d98.ed4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll
2565d98.ed4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef86d0000 'C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL'
2566d98.ea8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxTestOGL.exe
2567d98.efc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
2568d98.efc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxoglhostcrutil.dll'.
2569d98.efc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
2570d98.efc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vboxvmm.dll'.
2571d98.efc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'vboxoglrenderspu.dll'.
2572d98.efc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'advapi32.dll'.
2573d98.efc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'ole32.dll'.
2574d98.efc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'oleaut32.dll'.
2575d98.efc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedCrOpenGL.dll) WinVerifyTrust
2576d98.efc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedCrOpenGL.dll
2577d98.efc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
2578d98.efc: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
2579d98.efc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
2580d98.efc: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
2581d98.efc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
2582d98.efc: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
2583d98.efc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxoglrenderspu.dll'...
2584d98.efc: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxoglrenderspu.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxoglrenderspu.dll' [rcNtRedir=0xc0150008]
2585d98.efc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
2586d98.efc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxoglhostcrutil.dll'.
2587d98.efc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
2588d98.efc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
2589d98.efc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
2590d98.efc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'advapi32.dll'.
2591d98.efc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLrenderspu.dll) WinVerifyTrust
2592d98.efc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLrenderspu.dll
2593d98.efc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
2594d98.efc: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
2595d98.efc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
2596d98.efc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
2597d98.efc: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
2598d98.efc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxoglhostcrutil.dll'...
2599d98.efc: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxoglhostcrutil.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxoglhostcrutil.dll' [rcNtRedir=0xc0150008]
2600d98.efc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLhostcrutil.dll
2601d98.efc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
2602d98.efc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
2603d98.efc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
2604d98.efc: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
2605d98.efc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
2606d98.efc: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
2607d98.efc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
2608d98.efc: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
2609d98.efc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
2610d98.efc: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
2611d98.efc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxoglhostcrutil.dll'...
2612d98.efc: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxoglhostcrutil.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxoglhostcrutil.dll' [rcNtRedir=0xc0150008]
2613d98.efc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLhostcrutil.dll
2614d98.efc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
2615d98.efc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
2616d98.efc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSharedCrOpenGL.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000705440:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2617d98.efc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedCrOpenGL.dll
2618d98.efc: supR3HardenedDllNotificationCallback: load 000007feeedb0000 LB 0x0012c000 C:\Program Files\Oracle\VirtualBox\VBoxSharedCrOpenGL.DLL [fFlags=0x0]
2619d98.efc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedCrOpenGL.dll
2620d98.efc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLhostcrutil.dll
2621d98.efc: supR3HardenedDllNotificationCallback: load 000007feeed70000 LB 0x00034000 C:\Program Files\Oracle\VirtualBox\VBoxOGLhostcrutil.dll [fFlags=0x0]
2622d98.efc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLhostcrutil.dll
2623d98.efc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLrenderspu.dll
2624d98.efc: supR3HardenedDllNotificationCallback: load 000007fef8630000 LB 0x00028000 C:\Program Files\Oracle\VirtualBox\VBoxOGLrenderspu.dll [fFlags=0x0]
2625d98.efc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLrenderspu.dll
2626d98.efc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeedb0000 'C:\Program Files\Oracle\VirtualBox\VBoxSharedCrOpenGL.DLL'
2627d98.efc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLrenderspu.dll
2628d98.efc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxOGLrenderspu.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000705440:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2629d98.efc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef8630000 'C:\Program Files\Oracle\VirtualBox\VBoxOGLrenderspu.dll'
2630d98.efc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
2631d98.efc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxoglhostcrutil.dll'.
2632d98.efc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLhosterrorspu.dll) WinVerifyTrust
2633d98.efc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLhosterrorspu.dll
2634d98.efc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxoglhostcrutil.dll'...
2635d98.efc: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxoglhostcrutil.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxoglhostcrutil.dll' [rcNtRedir=0xc0150008]
2636d98.efc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLhostcrutil.dll
2637d98.efc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
2638d98.efc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
2639d98.efc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
2640d98.efc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxOGLhosterrorspu.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000705440:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2641d98.efc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLhosterrorspu.dll
2642d98.efc: supR3HardenedDllNotificationCallback: load 000007fef13b0000 LB 0x0001a000 C:\Program Files\Oracle\VirtualBox\VBoxOGLhosterrorspu.dll [fFlags=0x0]
2643d98.efc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLhosterrorspu.dll
2644d98.efc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef13b0000 'C:\Program Files\Oracle\VirtualBox\VBoxOGLhosterrorspu.dll'
2645d98.efc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
2646d98.efc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32/opengl32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000705440:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2647d98.efc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
2648d98.efc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef3f90000 'C:\Windows\system32/opengl32.dll'
2649d98.efc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
2650d98.efc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\OPENGL32.dll (Input=OPENGL32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000705440:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2651d98.efc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef3f90000 'C:\Windows\system32\OPENGL32.dll'
2652d98.efc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feffac0000 'C:\Windows\system32\gdi32.dll'
2653d98.efc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feffac0000 'C:\Windows\system32\gdi32.dll'
2654d98.efc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef3f90000 'C:\Windows\system32\OPENGL32.dll'
2655d98.efc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef3f90000 'C:\Windows\system32\OPENGL32.dll'
2656d98.efc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef3f90000 'C:\Windows\system32\OPENGL32.dll'
2657d98.efc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef3f90000 'C:\Windows\system32\OPENGL32.dll'
2658d98.efc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef3f90000 'C:\Windows\system32\OPENGL32.dll'
2659d98.efc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef3f90000 'C:\Windows\system32\OPENGL32.dll'
2660d98.f04: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
2661d98.f04: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
2662d98.f04: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
2663d98.f04: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll) WinVerifyTrust
2664d98.f04: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll
2665d98.f04: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
2666d98.f04: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
2667d98.f04: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
2668d98.f04: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
2669d98.f04: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
2670d98.f04: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
2671d98.f04: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
2672d98.f04: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000032db7d0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2673d98.f04: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll
2674d98.f04: supR3HardenedDllNotificationCallback: load 000007fef86c0000 LB 0x0000f000 C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL [fFlags=0x0]
2675d98.f04: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll
2676d98.f04: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef86c0000 'C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL'
2677d98.f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
2678d98.f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
2679d98.f0c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
2680d98.f0c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll) WinVerifyTrust
2681d98.f0c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll
2682d98.f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
2683d98.f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
2684d98.f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
2685d98.f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
2686d98.f0c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
2687d98.f0c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
2688d98.f0c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000032db7d0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2689d98.f0c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll
2690d98.f0c: supR3HardenedDllNotificationCallback: load 000007feeed60000 LB 0x0000e000 C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL [fFlags=0x0]
2691d98.f0c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll
2692d98.f0c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeed60000 'C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL'
2693d98.ea8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe4a0000 'C:\Windows\system32/Shell32.dll'
2694d98.ea8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff6c0000 'C:\Windows\system32\ole32.dll'
2695d98.ea8: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000032db7d0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2696d98.ea8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff230000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
2697d98.ea8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\profapi.dll
2698d98.ea8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\profapi.dll (Input=profapi.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000032db7d0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2699d98.ea8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd5e0000 'C:\Windows\system32\profapi.dll'
2700d98.ea8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
2701d98.ea8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
2702d98.ea8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
2703d98.ea8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vboxddu.dll'.
2704d98.ea8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'vboxdd2.dll'.
2705d98.ea8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
2706d98.ea8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'setupapi.dll'.
2707d98.ea8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'ws2_32.dll'.
2708d98.ea8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'ole32.dll'.
2709d98.ea8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'iphlpapi.dll'.
2710d98.ea8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD.dll) WinVerifyTrust
2711d98.ea8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD.dll
2712d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'iphlpapi.dll'...
2713d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: 'iphlpapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\iphlpapi.dll' [rcNtRedir=0xc0150008]
2714d98.ea8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000e44 pwszName=\Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL
2715d98.ea8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006de810
2716d98.ea8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
2717d98.ea8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=3BDC72529DA09BA841BE702C4C902C8AA1242642
2718d98.ea8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL'
2719d98.ea8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2720d98.ea8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
2721d98.ea8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'nsi.dll'.
2722d98.ea8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'winnsi.dll'.
2723d98.ea8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'rpcrt4.dll'.
2724d98.ea8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL) WinVerifyTrust
2725d98.ea8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL
2726d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
2727d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
2728d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
2729d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
2730d98.ea8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
2731d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
2732d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
2733d98.ea8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\setupapi.dll
2734d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
2735d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
2736d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxdd2.dll'...
2737d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxdd2.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxdd2.dll' [rcNtRedir=0xc0150008]
2738d98.ea8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
2739d98.ea8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
2740d98.ea8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
2741d98.ea8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD2.dll) WinVerifyTrust
2742d98.ea8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD2.dll
2743d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxddu.dll'...
2744d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxddu.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxddu.dll' [rcNtRedir=0xc0150008]
2745d98.ea8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
2746d98.ea8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
2747d98.ea8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
2748d98.ea8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'setupapi.dll'.
2749d98.ea8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'newdev.dll'.
2750d98.ea8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'advapi32.dll'.
2751d98.ea8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDDU.dll) WinVerifyTrust
2752d98.ea8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDDU.dll
2753d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
2754d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
2755d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
2756d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
2757d98.ea8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
2758d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
2759d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
2760d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
2761d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
2762d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'newdev.dll'...
2763d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: 'newdev.dll' -> '\Device\HarddiskVolume2\Windows\System32\newdev.dll' [rcNtRedir=0xc0150008]
2764d98.ea8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000e54 pwszName=\Device\HarddiskVolume2\Windows\System32\newdev.dll
2765d98.ea8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006de810
2766d98.ea8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
2767d98.ea8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2F4B2CF91DA6B4233E3BF5D2EC9677240BFF983C
2768d98.ea8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntph.cat'; file='\Device\HarddiskVolume2\Windows\System32\newdev.dll'
2769d98.ea8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2770d98.ea8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
2771d98.ea8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
2772d98.ea8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
2773d98.ea8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
2774d98.ea8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'uxtheme.dll'.
2775d98.ea8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'cfgmgr32.dll'.
2776d98.ea8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'setupapi.dll'.
2777d98.ea8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\newdev.dll) WinVerifyTrust
2778d98.ea8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\newdev.dll
2779d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
2780d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
2781d98.ea8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\setupapi.dll
2782d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
2783d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
2784d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
2785d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
2786d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
2787d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
2788d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
2789d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
2790d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
2791d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
2792d98.ea8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
2793d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
2794d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
2795d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
2796d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
2797d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winnsi.dll'...
2798d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: 'winnsi.dll' -> '\Device\HarddiskVolume2\Windows\System32\winnsi.dll' [rcNtRedir=0xc0150008]
2799d98.ea8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000e38 pwszName=\Device\HarddiskVolume2\Windows\System32\winnsi.dll
2800d98.ea8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006de810
2801d98.ea8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
2802d98.ea8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B28F3E0DF5586B9FB3AEAC48E4ECCA0AFB6ABD91
2803d98.ea8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\winnsi.dll'
2804d98.ea8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2805d98.ea8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
2806d98.ea8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'rpcrt4.dll'.
2807d98.ea8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'nsi.dll'.
2808d98.ea8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\winnsi.dll) WinVerifyTrust
2809d98.ea8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\winnsi.dll
2810d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
2811d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume2\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
2812d98.ea8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\nsi.dll
2813d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
2814d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
2815d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
2816d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume2\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
2817d98.ea8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\nsi.dll
2818d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
2819d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
2820d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
2821d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
2822d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
2823d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
2824d98.ea8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\setupapi.dll
2825d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
2826d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
2827d98.ea8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll
2828d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'uxtheme.dll'...
2829d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: 'uxtheme.dll' -> '\Device\HarddiskVolume2\Windows\System32\uxtheme.dll' [rcNtRedir=0xc0150008]
2830d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
2831d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
2832d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
2833d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
2834d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
2835d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
2836d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
2837d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
2838d98.ea8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox/VBoxDD.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000032db7d0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2839d98.ea8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD.dll
2840d98.ea8: supR3HardenedDllNotificationCallback: load 000007feee470000 LB 0x008e3000 C:\Program Files\Oracle\VirtualBox\VBoxDD.DLL [fFlags=0x0]
2841d98.ea8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD.dll
2842d98.ea8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDDU.dll
2843d98.ea8: supR3HardenedDllNotificationCallback: load 000007fef3a10000 LB 0x00061000 C:\Program Files\Oracle\VirtualBox\VBoxDDU.dll [fFlags=0x0]
2844d98.ea8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDDU.dll
2845d98.ea8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\newdev.dll
2846d98.ea8: supR3HardenedDllNotificationCallback: load 000007fef6e40000 LB 0x00051000 C:\Windows\system32\newdev.dll [fFlags=0x0]
2847d98.ea8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\newdev.dll
2848d98.ea8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
2849d98.ea8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\devrtl.dll)
2850d98.ea8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\devrtl.dll
2851d98.ea8: supR3HardenedDllNotificationCallback: load 000007fefc8b0000 LB 0x00012000 C:\Windows\system32\devrtl.DLL [fFlags=0x0]
2852d98.ea8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\devrtl.dll [avoiding WinVerifyTrust]
2853d98.ea8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD2.dll
2854d98.ea8: supR3HardenedDllNotificationCallback: load 000007feee430000 LB 0x00035000 C:\Program Files\Oracle\VirtualBox\VBoxDD2.dll [fFlags=0x0]
2855d98.ea8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD2.dll
2856d98.ea8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL
2857d98.ea8: supR3HardenedDllNotificationCallback: load 000007fefb220000 LB 0x00027000 C:\Windows\system32\IPHLPAPI.DLL [fFlags=0x0]
2858d98.ea8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL
2859d98.ea8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winnsi.dll
2860d98.ea8: supR3HardenedDllNotificationCallback: load 000007fefb210000 LB 0x0000b000 C:\Windows\system32\WINNSI.DLL [fFlags=0x0]
2861d98.ea8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winnsi.dll
2862d98.ea8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feee470000 'C:\Program Files\Oracle\VirtualBox/VBoxDD.DLL'
2863d98.ea8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000e4c pwszName=\Device\HarddiskVolume2\Windows\System32\devrtl.dll
2864d98.ea8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006de810
2865d98.ea8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
2866d98.ea8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=445E5B0E9F43B5D56A5B9C4BC3369E3D076ACA1A
2867d98.ea8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\devrtl.dll'
2868d98.ea8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2869d98.ea8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\devrtl.dll'
2870d98.ea8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxC.dll
2871d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
2872d98.ea8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
2873d98.ea8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox/VBoxC.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000032db7d0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2874d98.ea8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxC.dll
2875d98.ea8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef1460000 'C:\Program Files\Oracle\VirtualBox/VBoxC.DLL'
2876d98.ea8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD2.dll
2877d98.ea8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox/VBoxDD2.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000032db7d0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2878d98.ea8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD2.dll
2879d98.ea8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feee430000 'C:\Program Files\Oracle\VirtualBox/VBoxDD2.DLL'
2880d98.f30: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
2881d98.f30: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
2882d98.f30: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
2883d98.f30: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll) WinVerifyTrust
2884d98.f30: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll
2885d98.f30: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
2886d98.f30: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
2887d98.f30: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
2888d98.f30: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
2889d98.f30: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
2890d98.f30: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
2891d98.f30: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
2892d98.f30: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000032db7d0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2893d98.f30: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll
2894d98.f30: supR3HardenedDllNotificationCallback: load 000007feee420000 LB 0x0000d000 C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL [fFlags=0x0]
2895d98.f30: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll
2896d98.f30: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feee420000 'C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL'
2897d98.ea8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll
2898d98.ea8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32/kernel32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000032db7d0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2899d98.ea8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll
2900d98.ea8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077700000 'C:\Windows\system32/kernel32.dll'
2901d98.e8c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff540000 'C:\Windows\system32\OLEAUT32.dll'
2902d98.d9c: supR3HardenedMonitor_LdrLoadDll: 'C:\Windows\system32\comctl32.dll' -> 'C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll' [redir]
2903d98.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll [redoing WinVerifyTrust]
2904d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004fc pwszName=\Device\HarddiskVolume2\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll
2905d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006de810
2906d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006de810
2907d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=761964761EE466757E306124E042F4C2ACBEA092
2908d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3059317~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll'
2909d98.d9c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2910d98.d9c: supR3HardenedScreenImage/LdrLoadDll: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll'
2911d98.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll (Input=C:\Windows\system32\comctl32.dll, rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007057a0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2912d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef8140000 'C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll'
2913d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe4a0000 'C:\Windows\system32\shell32.dll'
2914d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe4a0000 'C:\Windows\system32\shell32.dll'
2915d98.f00: supR3HardenedDllNotificationCallback: Unload 000007fef6ca0000 LB 0x00048000 C:\Program Files (x86)\TeamViewer\tv_x64.dll [flags=0x0]
2916d98.ed0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files (x86)\TeamViewer\tv_x64.dll
2917d98.ed0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files (x86)\TeamViewer\tv_x64.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000004c470c0:C:\Program Files (x86)\TeamViewer;C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2918d98.ed0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files (x86)\TeamViewer\tv_x64.dll
2919d98.ed0: supR3HardenedDllNotificationCallback: load 000007fef6ca0000 LB 0x00048000 C:\Program Files (x86)\TeamViewer\tv_x64.dll [fFlags=0x0]
2920d98.ed0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files (x86)\TeamViewer\tv_x64.dll
2921d98.ed0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef6ca0000 'C:\Program Files (x86)\TeamViewer\tv_x64.dll'
2922d98.ed0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe320000 'C:\Windows\system32\advapi32.dll'
2923d98.d9c: supR3HardenedDllNotificationCallback: Unload 000007fef6ca0000 LB 0x00048000 C:\Program Files (x86)\TeamViewer\tv_x64.dll [flags=0x0]
2924d98.ed0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files (x86)\TeamViewer\tv_x64.dll
2925d98.ed0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files (x86)\TeamViewer\tv_x64.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003339c90:C:\Program Files (x86)\TeamViewer;C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2926d98.ed0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files (x86)\TeamViewer\tv_x64.dll
2927d98.ed0: supR3HardenedDllNotificationCallback: load 000007fef6ca0000 LB 0x00048000 C:\Program Files (x86)\TeamViewer\tv_x64.dll [fFlags=0x0]
2928d98.ed0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files (x86)\TeamViewer\tv_x64.dll
2929d98.ed0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef6ca0000 'C:\Program Files (x86)\TeamViewer\tv_x64.dll'
2930d98.ed0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe320000 'C:\Windows\system32\advapi32.dll'
2931d98.d9c: supR3HardenedDllNotificationCallback: Unload 000007fef6ca0000 LB 0x00048000 C:\Program Files (x86)\TeamViewer\tv_x64.dll [flags=0x0]
2932d98.d9c: supR3HardenedDllNotificationCallback: load 000007fef6ca0000 LB 0x00048000 C:\Program Files (x86)\TeamViewer\tv_x64.dll [fFlags=0x0]
2933d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef6ca0000 'C:\Program Files (x86)\TeamViewer\tv_x64.dll'
2934d98.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe320000 'C:\Windows\system32\advapi32.dll'
2935d98.d9c: supR3HardenedDllNotificationCallback: Unload 000007fef6ca0000 LB 0x00048000 C:\Program Files (x86)\TeamViewer\tv_x64.dll [flags=0x0]
2936d98.ed0: supR3HardenedDllNotificationCallback: load 000007fef6ca0000 LB 0x00048000 C:\Program Files (x86)\TeamViewer\tv_x64.dll [fFlags=0x0]
2937d98.ed0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef6ca0000 'C:\Program Files (x86)\TeamViewer\tv_x64.dll'
2938d98.ed0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe320000 'C:\Windows\system32\advapi32.dll'
2939d98.f30: supR3HardenedDllNotificationCallback: Unload 000007feee420000 LB 0x0000d000 C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL [flags=0x0]
2940d98.f0c: supR3HardenedDllNotificationCallback: Unload 000007feeed60000 LB 0x0000e000 C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL [flags=0x0]
2941d98.f04: supR3HardenedDllNotificationCallback: Unload 000007fef86c0000 LB 0x0000f000 C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL [flags=0x0]
2942d98.efc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef3f90000 'C:\Windows\system32\OPENGL32.dll'
2943d98.efc: supR3HardenedDllNotificationCallback: Unload 000007fef13b0000 LB 0x0001a000 C:\Program Files\Oracle\VirtualBox\VBoxOGLhosterrorspu.dll [flags=0x0]
2944d98.efc: supR3HardenedDllNotificationCallback: Unload 000007feeedb0000 LB 0x0012c000 C:\Program Files\Oracle\VirtualBox\VBoxSharedCrOpenGL.DLL [flags=0x0]
2945d98.efc: supR3HardenedDllNotificationCallback: Unload 000007fef8630000 LB 0x00028000 C:\Program Files\Oracle\VirtualBox\VBoxOGLrenderspu.dll [flags=0x0]
2946d98.efc: supR3HardenedDllNotificationCallback: Unload 000007feeed70000 LB 0x00034000 C:\Program Files\Oracle\VirtualBox\VBoxOGLhostcrutil.dll [flags=0x0]
2947d98.ed4: supR3HardenedDllNotificationCallback: Unload 000007fef86d0000 LB 0x0000d000 C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL [flags=0x0]
2948d98.ecc: supR3HardenedDllNotificationCallback: Unload 000007fef86e0000 LB 0x0000a000 C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL [flags=0x0]
2949d98.ea8: supR3HardenedDllNotificationCallback: Unload 000007feee470000 LB 0x008e3000 C:\Program Files\Oracle\VirtualBox\VBoxDD.DLL [flags=0x0]
2950d98.ea8: supR3HardenedDllNotificationCallback: Unload 000007fefb220000 LB 0x00027000 C:\Windows\system32\IPHLPAPI.DLL [flags=0x0]
2951d98.ea8: supR3HardenedDllNotificationCallback: Unload 000007fefb210000 LB 0x0000b000 C:\Windows\system32\WINNSI.DLL [flags=0x0]
2952d98.ea8: supR3HardenedDllNotificationCallback: Unload 000007feee430000 LB 0x00035000 C:\Program Files\Oracle\VirtualBox\VBoxDD2.dll [flags=0x0]
2953d98.ea8: supR3HardenedDllNotificationCallback: Unload 000007fef3a10000 LB 0x00061000 C:\Program Files\Oracle\VirtualBox\VBoxDDU.dll [flags=0x0]
2954d98.ea8: supR3HardenedDllNotificationCallback: Unload 000007fef6e40000 LB 0x00051000 C:\Windows\system32\newdev.dll [flags=0x0]
2955d98.d9c: supR3HardenedDllNotificationCallback: Unload 000007fef9750000 LB 0x000e2000 C:\Windows\system32\wbem\fastprox.dll [flags=0x0]
2956d98.d9c: supR3HardenedDllNotificationCallback: Unload 000007fef9720000 LB 0x00027000 C:\Windows\system32\NTDSAPI.dll [flags=0x0]
2957d98.d9c: supR3HardenedDllNotificationCallback: Unload 000007fef9190000 LB 0x00014000 C:\Windows\system32\wbem\wbemsvc.dll [flags=0x0]
2958d98.d9c: supR3HardenedDllNotificationCallback: Unload 000007fef9670000 LB 0x0000f000 C:\Windows\system32\wbem\wbemprox.dll [flags=0x0]
2959d98.d9c: supR3HardenedDllNotificationCallback: Unload 000007fef9920000 LB 0x00086000 C:\Windows\system32\wbemcomn.dll [flags=0x0]
2960d98.d9c: supR3HardenedDllNotificationCallback: Unload 000007fef1460000 LB 0x005d7000 C:\Program Files\Oracle\VirtualBox\VBoxC.dll [flags=0x0]
2961d98.d9c: supR3HardenedDllNotificationCallback: Unload 00000000779e0000 LB 0x00007000 C:\Windows\system32\PSAPI.DLL [flags=0x0]
2962d98.d9c: Terminating the normal way: rcExit=0
2963d90.d94: supR3HardNtChildWaitFor[2]: Quitting: ExitCode=0x0 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 370297325 ms, the end);
2964d88.d8c: supR3HardNtChildWaitFor[1]: Quitting: ExitCode=0x0 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 370297918 ms, the end);

© 2024 Oracle Support Privacy / Do Not Sell My Info Terms of Use Trademark Policy Automated Access Etiquette