VirtualBox

Ticket #14774: VBoxHardening.log

File VBoxHardening.log, 334.0 KB (added by GoodGodd, 9 years ago)
Line 
17e8.b30: Log file opened: 5.0.9r103713 g_hStartupLog=0000000000000014 g_uNtVerCombined=0x611db110
27e8.b30: \SystemRoot\System32\ntdll.dll:
37e8.b30: CreationTime: 2015-06-30T18:24:53.606504900Z
47e8.b30: LastWriteTime: 2015-05-25T18:21:21.289963400Z
57e8.b30: ChangeTime: 2015-06-30T22:16:12.090281900Z
67e8.b30: FileAttributes: 0x20
77e8.b30: Size: 0x1a61c0
87e8.b30: NT Headers: 0xe0
97e8.b30: Timestamp: 0x556366f2
107e8.b30: Machine: 0x8664 - amd64
117e8.b30: Timestamp: 0x556366f2
127e8.b30: Image Version: 6.1
137e8.b30: SizeOfImage: 0x1a9000 (1740800)
147e8.b30: Resource Dir: 0x14d000 LB 0x5a028
157e8.b30: ProductName: Microsoft® Windows® Operating System
167e8.b30: ProductVersion: 6.1.7601.18869
177e8.b30: FileVersion: 6.1.7601.18869 (win7sp1_gdr.150525-0603)
187e8.b30: FileDescription: NT Layer DLL
197e8.b30: \SystemRoot\System32\kernel32.dll:
207e8.b30: CreationTime: 2015-06-30T18:24:53.107304100Z
217e8.b30: LastWriteTime: 2015-05-25T18:19:02.585000000Z
227e8.b30: ChangeTime: 2015-06-30T22:16:12.324282300Z
237e8.b30: FileAttributes: 0x20
247e8.b30: Size: 0x11be00
257e8.b30: NT Headers: 0xe8
267e8.b30: Timestamp: 0x556366fc
277e8.b30: Machine: 0x8664 - amd64
287e8.b30: Timestamp: 0x556366fc
297e8.b30: Image Version: 6.1
307e8.b30: SizeOfImage: 0x11f000 (1175552)
317e8.b30: Resource Dir: 0x116000 LB 0x528
327e8.b30: ProductName: Microsoft® Windows® Operating System
337e8.b30: ProductVersion: 6.1.7601.18869
347e8.b30: FileVersion: 6.1.7601.18869 (win7sp1_gdr.150525-0603)
357e8.b30: FileDescription: Windows NT BASE API Client DLL
367e8.b30: \SystemRoot\System32\KernelBase.dll:
377e8.b30: CreationTime: 2015-06-30T18:24:53.060504000Z
387e8.b30: LastWriteTime: 2015-05-25T18:19:02.585000000Z
397e8.b30: ChangeTime: 2015-06-30T22:16:12.324282300Z
407e8.b30: FileAttributes: 0x20
417e8.b30: Size: 0x67c00
427e8.b30: NT Headers: 0xe8
437e8.b30: Timestamp: 0x556366fd
447e8.b30: Machine: 0x8664 - amd64
457e8.b30: Timestamp: 0x556366fd
467e8.b30: Image Version: 6.1
477e8.b30: SizeOfImage: 0x6c000 (442368)
487e8.b30: Resource Dir: 0x6a000 LB 0x530
497e8.b30: ProductName: Microsoft® Windows® Operating System
507e8.b30: ProductVersion: 6.1.7601.18869
517e8.b30: FileVersion: 6.1.7601.18869 (win7sp1_gdr.150525-0603)
527e8.b30: FileDescription: Windows NT BASE API Client DLL
537e8.b30: \SystemRoot\System32\apisetschema.dll:
547e8.b30: CreationTime: 2015-06-30T18:24:52.124502300Z
557e8.b30: LastWriteTime: 2015-05-25T18:11:40.254000000Z
567e8.b30: ChangeTime: 2015-06-30T22:16:12.074681900Z
577e8.b30: FileAttributes: 0x20
587e8.b30: Size: 0x1a00
597e8.b30: NT Headers: 0xc0
607e8.b30: Timestamp: 0x55636622
617e8.b30: Machine: 0x8664 - amd64
627e8.b30: Timestamp: 0x55636622
637e8.b30: Image Version: 6.1
647e8.b30: SizeOfImage: 0x50000 (327680)
657e8.b30: Resource Dir: 0x30000 LB 0x3f8
667e8.b30: ProductName: Microsoft® Windows® Operating System
677e8.b30: ProductVersion: 6.1.7601.18869
687e8.b30: FileVersion: 6.1.7601.18869 (win7sp1_gdr.150525-0603)
697e8.b30: FileDescription: ApiSet Schema DLL
707e8.b30: supR3HardenedWinFindAdversaries: 0x80
717e8.b30: \SystemRoot\System32\drivers\MBAMSwissArmy.sys:
727e8.b30: CreationTime: 2015-07-18T23:42:46.446818300Z
737e8.b30: LastWriteTime: 2015-07-27T17:41:10.541992700Z
747e8.b30: ChangeTime: 2015-07-27T17:41:10.541992700Z
757e8.b30: FileAttributes: 0x20
767e8.b30: Size: 0x1bcd8
777e8.b30: NT Headers: 0xe8
787e8.b30: Timestamp: 0x552c190f
797e8.b30: Machine: 0x8664 - amd64
807e8.b30: Timestamp: 0x552c190f
817e8.b30: Image Version: 6.1
827e8.b30: SizeOfImage: 0x21000 (135168)
837e8.b30: Resource Dir: 0x1f000 LB 0x3f0
847e8.b30: ProductName: Malwarebytes Anti-Malware
857e8.b30: ProductVersion: 0.2.22.0
867e8.b30: FileVersion: 0.2.22.0
877e8.b30: FileDescription: Malwarebytes Anti-Malware
887e8.b30: \SystemRoot\System32\drivers\mwac.sys:
897e8.b30: CreationTime: 2015-07-18T23:42:36.308030900Z
907e8.b30: LastWriteTime: 2015-06-18T08:48:04.000000000Z
917e8.b30: ChangeTime: 2015-07-18T23:43:21.166227100Z
927e8.b30: FileAttributes: 0x20
937e8.b30: Size: 0xf8d8
947e8.b30: NT Headers: 0xf8
957e8.b30: Timestamp: 0x53a0f42a
967e8.b30: Machine: 0x8664 - amd64
977e8.b30: Timestamp: 0x53a0f42a
987e8.b30: Image Version: 6.2
997e8.b30: SizeOfImage: 0x12000 (73728)
1007e8.b30: Resource Dir: 0x10000 LB 0x3e0
1017e8.b30: ProductName: Malwarebytes Web Access Control
1027e8.b30: ProductVersion: 1.0.6.0
1037e8.b30: FileVersion: 1.0.6.0
1047e8.b30: FileDescription: Malwarebytes Web Access Control
1057e8.b30: \SystemRoot\System32\drivers\mbamchameleon.sys:
1067e8.b30: CreationTime: 2015-07-18T23:42:36.315031800Z
1077e8.b30: LastWriteTime: 2015-06-18T08:47:54.000000000Z
1087e8.b30: ChangeTime: 2015-07-18T23:43:21.178228700Z
1097e8.b30: FileAttributes: 0x20
1107e8.b30: Size: 0x1aad8
1117e8.b30: NT Headers: 0xd8
1127e8.b30: Timestamp: 0x554cf757
1137e8.b30: Machine: 0x8664 - amd64
1147e8.b30: Timestamp: 0x554cf757
1157e8.b30: Image Version: 6.1
1167e8.b30: SizeOfImage: 0x1e000 (122880)
1177e8.b30: Resource Dir: 0x1c000 LB 0xbd8
1187e8.b30: ProductName: Malwarebytes Chameleon
1197e8.b30: ProductVersion: 1.1.20.0
1207e8.b30: FileVersion: 1.1.20.0
1217e8.b30: FileDescription: Malwarebytes Chameleon Protection Driver
1227e8.b30: \SystemRoot\System32\drivers\mbam.sys:
1237e8.b30: CreationTime: 2015-07-18T23:42:36.304030400Z
1247e8.b30: LastWriteTime: 2015-06-18T08:47:50.000000000Z
1257e8.b30: ChangeTime: 2015-07-18T23:43:21.159226300Z
1267e8.b30: FileAttributes: 0x20
1277e8.b30: Size: 0x64d8
1287e8.b30: NT Headers: 0xd8
1297e8.b30: Timestamp: 0x540754e1
1307e8.b30: Machine: 0x8664 - amd64
1317e8.b30: Timestamp: 0x540754e1
1327e8.b30: Image Version: 6.1
1337e8.b30: SizeOfImage: 0xa000 (40960)
1347e8.b30: Resource Dir: 0x8000 LB 0x3d0
1357e8.b30: ProductName: Malwarebytes Anti-Malware
1367e8.b30: ProductVersion: 0.1.15.0
1377e8.b30: FileVersion: 0.1.15.0
1387e8.b30: FileDescription: Malwarebytes Anti-Malware
1397e8.b30: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
1407e8.b30: Calling main()
1417e8.b30: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
1427e8.b30: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
1437e8.b30: SUPR3HardenedMain: Respawn #1
1447e8.b30: System32: \Device\HarddiskVolume2\Windows\System32
1457e8.b30: WinSxS: \Device\HarddiskVolume2\Windows\winsxs
1467e8.b30: KnownDllPath: C:\Windows\system32
1477e8.b30: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
1487e8.b30: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe)
1497e8.b30: supR3HardNtEnableThreadCreation:
1507e8.b30: supR3HardNtDisableThreadCreation: pvLdrInitThunk=000000007732b780 pvNtTerminateThread=000000007734e0e0
1517e8.b30: supR3HardenedWinDoReSpawn(1): New child ec8.e6c [kernel32].
1527e8.b30: supR3HardNtChildGatherData: PebBaseAddress=000007fffffdf000 cbPeb=0x380
1537e8.b30: supR3HardNtPuChFindNtdll: uNtDllParentAddr=0000000077300000 uNtDllChildAddr=0000000077300000
1547e8.b30: supR3HardenedWinSetupChildInit: uLdrInitThunk=000000007732b780
1557e8.b30: supR3HardenedWinSetupChildInit: Start child.
1567e8.b30: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
1577e8.b30: supR3HardNtChildPurify: Startup delay kludge #1/0: 515 ms, 33 sleeps
1587e8.b30: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
1597e8.b30: *0000000000000000-fffffffffffeffff 0x0001/0x0000 0x0000000
1607e8.b30: *0000000000010000-fffffffffffeffff 0x0004/0x0004 0x0020000
1617e8.b30: *0000000000030000-000000000002bfff 0x0002/0x0002 0x0040000
1627e8.b30: 0000000000034000-0000000000027fff 0x0001/0x0000 0x0000000
1637e8.b30: *0000000000040000-000000000003efff 0x0004/0x0004 0x0020000
1647e8.b30: 0000000000041000-0000000000011fff 0x0001/0x0000 0x0000000
1657e8.b30: *0000000000070000-fffffffffff73fff 0x0000/0x0004 0x0020000
1667e8.b30: 000000000016c000-0000000000168fff 0x0104/0x0004 0x0020000
1677e8.b30: 000000000016f000-000000000016dfff 0x0004/0x0004 0x0020000
1687e8.b30: 0000000000170000-ffffffff88fdffff 0x0001/0x0000 0x0000000
1697e8.b30: *0000000077300000-0000000077300fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
1707e8.b30: 0000000077301000-00000000773fefff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
1717e8.b30: 00000000773ff000-000000007742dfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
1727e8.b30: 000000007742e000-0000000077435fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
1737e8.b30: 0000000077436000-0000000077436fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
1747e8.b30: 0000000077437000-0000000077439fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
1757e8.b30: 000000007743a000-00000000774a8fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
1767e8.b30: 00000000774a9000-000000006f971fff 0x0001/0x0000 0x0000000
1777e8.b30: *000000007efe0000-000000007dfdffff 0x0000/0x0002 0x0020000
1787e8.b30: *000000007ffe0000-000000007ffdefff 0x0002/0x0002 0x0020000
1797e8.b30: 000000007ffe1000-000000007ffd1fff 0x0000/0x0002 0x0020000
1807e8.b30: 000000007fff0000-ffffffffc060ffff 0x0001/0x0000 0x0000000
1817e8.b30: *000000013f9d0000-000000013f9d0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
1827e8.b30: 000000013f9d1000-000000013fa57fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
1837e8.b30: 000000013fa58000-000000013fa58fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
1847e8.b30: 000000013fa59000-000000013faa3fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
1857e8.b30: 000000013faa4000-000000013faa4fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
1867e8.b30: 000000013faa5000-000000013faa5fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
1877e8.b30: 000000013faa6000-000000013faaafff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
1887e8.b30: 000000013faab000-000000013faabfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
1897e8.b30: 000000013faac000-000000013faacfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
1907e8.b30: 000000013faad000-000000013fab0fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
1917e8.b30: 000000013fab1000-000000013fafbfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
1927e8.b30: 000000013fafc000-fffff8037ffd7fff 0x0001/0x0000 0x0000000
1937e8.b30: *000007feff620000-000007feff620fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\apisetschema.dll
1947e8.b30: 000007feff621000-000007fdfec91fff 0x0001/0x0000 0x0000000
1957e8.b30: *000007fffffb0000-000007fffff8cfff 0x0002/0x0002 0x0040000
1967e8.b30: 000007fffffd3000-000007fffffc8fff 0x0001/0x0000 0x0000000
1977e8.b30: *000007fffffdd000-000007fffffdafff 0x0004/0x0004 0x0020000
1987e8.b30: *000007fffffdf000-000007fffffddfff 0x0004/0x0004 0x0020000
1997e8.b30: *000007fffffe0000-000007fffffcffff 0x0001/0x0002 0x0020000
2007e8.b30: apisetschema.dll: timestamp 0x55636622 (rc=VINF_SUCCESS)
2017e8.b30: VirtualBox.exe: timestamp 0x5630b0b7 (rc=VINF_SUCCESS)
2027e8.b30: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
2037e8.b30: '\Device\HarddiskVolume2\Windows\System32\apisetschema.dll' has no imports
2047e8.b30: '\Device\HarddiskVolume2\Windows\System32\ntdll.dll' has no imports
2057e8.b30: supR3HardNtChildPurify: Done after 546 ms and 0 fixes (loop #0).
206ec8.e6c: Log file opened: 5.0.9r103713 g_hStartupLog=0000000000000004 g_uNtVerCombined=0x611db110
207ec8.e6c: supR3HardenedVmProcessInit: uNtDllAddr=0000000077300000
208ec8.e6c: ntdll.dll: timestamp 0x556366f2 (rc=VINF_SUCCESS)
209ec8.e6c: New simple heap: #1 0000000000270000 LB 0x400000 (for 1740800 allocation)
2107e8.b30: supR3HardNtEnableThreadCreation:
211ec8.e6c: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
212ec8.e6c: System32: \Device\HarddiskVolume2\Windows\System32
213ec8.e6c: WinSxS: \Device\HarddiskVolume2\Windows\winsxs
214ec8.e6c: KnownDllPath: C:\Windows\system32
215ec8.e6c: supR3HardenedVmProcessInit: Opening vboxdrv stub...
216ec8.e6c: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
217ec8.e6c: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
218ec8.e6c: Registered Dll notification callback with NTDLL.
219ec8.e6c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\kernel32.dll)
220ec8.e6c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\kernel32.dll
221ec8.e6c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
222ec8.e6c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
223ec8.e6c: supR3HardenedDllNotificationCallback: load 00000000771e0000 LB 0x0011f000 C:\Windows\system32\kernel32.dll [fFlags=0x0]
224ec8.e6c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
225ec8.e6c: supR3HardenedDllNotificationCallback: load 000007fefd2c0000 LB 0x0006c000 C:\Windows\system32\KERNELBASE.dll [fFlags=0x0]
226ec8.e6c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\KernelBase.dll)
227ec8.e6c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\KernelBase.dll
228ec8.e6c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00000000771e0000 'C:\Windows\system32\kernel32.dll'
229ec8.e6c: supR3HardNtDisableThreadCreation: pvLdrInitThunk=000000007732b780 pvNtTerminateThread=000000007734e0e0
2307e8.b30: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 16 ms.
231ec8.e6c: \SystemRoot\System32\ntdll.dll:
232ec8.e6c: CreationTime: 2015-06-30T18:24:53.606504900Z
233ec8.e6c: LastWriteTime: 2015-05-25T18:21:21.289963400Z
234ec8.e6c: ChangeTime: 2015-06-30T22:16:12.090281900Z
235ec8.e6c: FileAttributes: 0x20
236ec8.e6c: Size: 0x1a61c0
237ec8.e6c: NT Headers: 0xe0
238ec8.e6c: Timestamp: 0x556366f2
239ec8.e6c: Machine: 0x8664 - amd64
240ec8.e6c: Timestamp: 0x556366f2
241ec8.e6c: Image Version: 6.1
242ec8.e6c: SizeOfImage: 0x1a9000 (1740800)
243ec8.e6c: Resource Dir: 0x14d000 LB 0x5a028
244ec8.e6c: ProductName: Microsoft® Windows® Operating System
245ec8.e6c: ProductVersion: 6.1.7601.18869
246ec8.e6c: FileVersion: 6.1.7601.18869 (win7sp1_gdr.150525-0603)
247ec8.e6c: FileDescription: NT Layer DLL
248ec8.e6c: \SystemRoot\System32\kernel32.dll:
249ec8.e6c: CreationTime: 2015-06-30T18:24:53.107304100Z
250ec8.e6c: LastWriteTime: 2015-05-25T18:19:02.585000000Z
251ec8.e6c: ChangeTime: 2015-06-30T22:16:12.324282300Z
252ec8.e6c: FileAttributes: 0x20
253ec8.e6c: Size: 0x11be00
254ec8.e6c: NT Headers: 0xe8
255ec8.e6c: Timestamp: 0x556366fc
256ec8.e6c: Machine: 0x8664 - amd64
257ec8.e6c: Timestamp: 0x556366fc
258ec8.e6c: Image Version: 6.1
259ec8.e6c: SizeOfImage: 0x11f000 (1175552)
260ec8.e6c: Resource Dir: 0x116000 LB 0x528
261ec8.e6c: ProductName: Microsoft® Windows® Operating System
262ec8.e6c: ProductVersion: 6.1.7601.18869
263ec8.e6c: FileVersion: 6.1.7601.18869 (win7sp1_gdr.150525-0603)
264ec8.e6c: FileDescription: Windows NT BASE API Client DLL
265ec8.e6c: \SystemRoot\System32\KernelBase.dll:
266ec8.e6c: CreationTime: 2015-06-30T18:24:53.060504000Z
267ec8.e6c: LastWriteTime: 2015-05-25T18:19:02.585000000Z
268ec8.e6c: ChangeTime: 2015-06-30T22:16:12.324282300Z
269ec8.e6c: FileAttributes: 0x20
270ec8.e6c: Size: 0x67c00
271ec8.e6c: NT Headers: 0xe8
272ec8.e6c: Timestamp: 0x556366fd
273ec8.e6c: Machine: 0x8664 - amd64
274ec8.e6c: Timestamp: 0x556366fd
275ec8.e6c: Image Version: 6.1
276ec8.e6c: SizeOfImage: 0x6c000 (442368)
277ec8.e6c: Resource Dir: 0x6a000 LB 0x530
278ec8.e6c: ProductName: Microsoft® Windows® Operating System
279ec8.e6c: ProductVersion: 6.1.7601.18869
280ec8.e6c: FileVersion: 6.1.7601.18869 (win7sp1_gdr.150525-0603)
281ec8.e6c: FileDescription: Windows NT BASE API Client DLL
282ec8.e6c: \SystemRoot\System32\apisetschema.dll:
283ec8.e6c: CreationTime: 2015-06-30T18:24:52.124502300Z
284ec8.e6c: LastWriteTime: 2015-05-25T18:11:40.254000000Z
285ec8.e6c: ChangeTime: 2015-06-30T22:16:12.074681900Z
286ec8.e6c: FileAttributes: 0x20
287ec8.e6c: Size: 0x1a00
288ec8.e6c: NT Headers: 0xc0
289ec8.e6c: Timestamp: 0x55636622
290ec8.e6c: Machine: 0x8664 - amd64
291ec8.e6c: Timestamp: 0x55636622
292ec8.e6c: Image Version: 6.1
293ec8.e6c: SizeOfImage: 0x50000 (327680)
294ec8.e6c: Resource Dir: 0x30000 LB 0x3f8
295ec8.e6c: ProductName: Microsoft® Windows® Operating System
296ec8.e6c: ProductVersion: 6.1.7601.18869
297ec8.e6c: FileVersion: 6.1.7601.18869 (win7sp1_gdr.150525-0603)
298ec8.e6c: FileDescription: ApiSet Schema DLL
299ec8.e6c: supR3HardenedWinFindAdversaries: 0x80
300ec8.e6c: \SystemRoot\System32\drivers\MBAMSwissArmy.sys:
301ec8.e6c: CreationTime: 2015-07-18T23:42:46.446818300Z
302ec8.e6c: LastWriteTime: 2015-07-27T17:41:10.541992700Z
303ec8.e6c: ChangeTime: 2015-07-27T17:41:10.541992700Z
304ec8.e6c: FileAttributes: 0x20
305ec8.e6c: Size: 0x1bcd8
306ec8.e6c: NT Headers: 0xe8
307ec8.e6c: Timestamp: 0x552c190f
308ec8.e6c: Machine: 0x8664 - amd64
309ec8.e6c: Timestamp: 0x552c190f
310ec8.e6c: Image Version: 6.1
311ec8.e6c: SizeOfImage: 0x21000 (135168)
312ec8.e6c: Resource Dir: 0x1f000 LB 0x3f0
313ec8.e6c: ProductName: Malwarebytes Anti-Malware
314ec8.e6c: ProductVersion: 0.2.22.0
315ec8.e6c: FileVersion: 0.2.22.0
316ec8.e6c: FileDescription: Malwarebytes Anti-Malware
317ec8.e6c: \SystemRoot\System32\drivers\mwac.sys:
318ec8.e6c: CreationTime: 2015-07-18T23:42:36.308030900Z
319ec8.e6c: LastWriteTime: 2015-06-18T08:48:04.000000000Z
320ec8.e6c: ChangeTime: 2015-07-18T23:43:21.166227100Z
321ec8.e6c: FileAttributes: 0x20
322ec8.e6c: Size: 0xf8d8
323ec8.e6c: NT Headers: 0xf8
324ec8.e6c: Timestamp: 0x53a0f42a
325ec8.e6c: Machine: 0x8664 - amd64
326ec8.e6c: Timestamp: 0x53a0f42a
327ec8.e6c: Image Version: 6.2
328ec8.e6c: SizeOfImage: 0x12000 (73728)
329ec8.e6c: Resource Dir: 0x10000 LB 0x3e0
330ec8.e6c: ProductName: Malwarebytes Web Access Control
331ec8.e6c: ProductVersion: 1.0.6.0
332ec8.e6c: FileVersion: 1.0.6.0
333ec8.e6c: FileDescription: Malwarebytes Web Access Control
334ec8.e6c: \SystemRoot\System32\drivers\mbamchameleon.sys:
335ec8.e6c: CreationTime: 2015-07-18T23:42:36.315031800Z
336ec8.e6c: LastWriteTime: 2015-06-18T08:47:54.000000000Z
337ec8.e6c: ChangeTime: 2015-07-18T23:43:21.178228700Z
338ec8.e6c: FileAttributes: 0x20
339ec8.e6c: Size: 0x1aad8
340ec8.e6c: NT Headers: 0xd8
341ec8.e6c: Timestamp: 0x554cf757
342ec8.e6c: Machine: 0x8664 - amd64
343ec8.e6c: Timestamp: 0x554cf757
344ec8.e6c: Image Version: 6.1
345ec8.e6c: SizeOfImage: 0x1e000 (122880)
346ec8.e6c: Resource Dir: 0x1c000 LB 0xbd8
347ec8.e6c: ProductName: Malwarebytes Chameleon
348ec8.e6c: ProductVersion: 1.1.20.0
349ec8.e6c: FileVersion: 1.1.20.0
350ec8.e6c: FileDescription: Malwarebytes Chameleon Protection Driver
351ec8.e6c: \SystemRoot\System32\drivers\mbam.sys:
352ec8.e6c: CreationTime: 2015-07-18T23:42:36.304030400Z
353ec8.e6c: LastWriteTime: 2015-06-18T08:47:50.000000000Z
354ec8.e6c: ChangeTime: 2015-07-18T23:43:21.159226300Z
355ec8.e6c: FileAttributes: 0x20
356ec8.e6c: Size: 0x64d8
357ec8.e6c: NT Headers: 0xd8
358ec8.e6c: Timestamp: 0x540754e1
359ec8.e6c: Machine: 0x8664 - amd64
360ec8.e6c: Timestamp: 0x540754e1
361ec8.e6c: Image Version: 6.1
362ec8.e6c: SizeOfImage: 0xa000 (40960)
363ec8.e6c: Resource Dir: 0x8000 LB 0x3d0
364ec8.e6c: ProductName: Malwarebytes Anti-Malware
365ec8.e6c: ProductVersion: 0.1.15.0
366ec8.e6c: FileVersion: 0.1.15.0
367ec8.e6c: FileDescription: Malwarebytes Anti-Malware
368ec8.e6c: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
369ec8.e6c: Calling main()
370ec8.e6c: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
371ec8.e6c: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
372ec8.e6c: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
373ec8.e6c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe)
374ec8.e6c: SUPR3HardenedMain: Respawn #2
375ec8.e6c: supR3HardNtEnableThreadCreation:
376ec8.e6c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\apphelp.dll)
377ec8.e6c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\apphelp.dll
378ec8.e6c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\apphelp.dll (rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
379ec8.e6c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\apphelp.dll [lacks WinVerifyTrust]
380ec8.e6c: supR3HardenedDllNotificationCallback: load 000007fefcef0000 LB 0x00057000 C:\Windows\system32\apphelp.dll [fFlags=0x0]
381ec8.e6c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\apphelp.dll [lacks WinVerifyTrust]
382ec8.e6c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcef0000 'C:\Windows\system32\apphelp.dll'
383ec8.e6c: supR3HardNtDisableThreadCreation: pvLdrInitThunk=000000007732b780 pvNtTerminateThread=000000007734e0e0
384ec8.e6c: supR3HardenedWinDoReSpawn(2): New child e18.c94 [kernel32].
385ec8.e6c: supR3HardNtChildGatherData: PebBaseAddress=000007fffffd7000 cbPeb=0x380
386ec8.e6c: supR3HardNtPuChFindNtdll: uNtDllParentAddr=0000000077300000 uNtDllChildAddr=0000000077300000
387ec8.e6c: supR3HardenedWinSetupChildInit: uLdrInitThunk=000000007732b780
388ec8.e6c: supR3HardenedWinSetupChildInit: Start child.
389ec8.e6c: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 15 ms.
390ec8.e6c: supR3HardNtChildPurify: Startup delay kludge #1/0: 515 ms, 33 sleeps
391ec8.e6c: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
392ec8.e6c: *0000000000000000-fffffffffffeffff 0x0001/0x0000 0x0000000
393ec8.e6c: *0000000000010000-fffffffffffeffff 0x0004/0x0004 0x0020000
394ec8.e6c: *0000000000030000-000000000002bfff 0x0002/0x0002 0x0040000
395ec8.e6c: 0000000000034000-0000000000027fff 0x0001/0x0000 0x0000000
396ec8.e6c: *0000000000040000-000000000003efff 0x0004/0x0004 0x0020000
397ec8.e6c: 0000000000041000-0000000000031fff 0x0001/0x0000 0x0000000
398ec8.e6c: *0000000000050000-fffffffffff53fff 0x0000/0x0004 0x0020000
399ec8.e6c: 000000000014c000-0000000000148fff 0x0104/0x0004 0x0020000
400ec8.e6c: 000000000014f000-000000000014dfff 0x0004/0x0004 0x0020000
401ec8.e6c: 0000000000150000-ffffffff88f9ffff 0x0001/0x0000 0x0000000
402ec8.e6c: *0000000077300000-0000000077300fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
403ec8.e6c: 0000000077301000-00000000773fefff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
404ec8.e6c: 00000000773ff000-000000007742dfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
405ec8.e6c: 000000007742e000-0000000077435fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
406ec8.e6c: 0000000077436000-0000000077436fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
407ec8.e6c: 0000000077437000-0000000077439fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
408ec8.e6c: 000000007743a000-00000000774a8fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
409ec8.e6c: 00000000774a9000-000000006f971fff 0x0001/0x0000 0x0000000
410ec8.e6c: *000000007efe0000-000000007dfdffff 0x0000/0x0002 0x0020000
411ec8.e6c: *000000007ffe0000-000000007ffdefff 0x0002/0x0002 0x0020000
412ec8.e6c: 000000007ffe1000-000000007ffd1fff 0x0000/0x0002 0x0020000
413ec8.e6c: 000000007fff0000-ffffffffc060ffff 0x0001/0x0000 0x0000000
414ec8.e6c: *000000013f9d0000-000000013f9d0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
415ec8.e6c: 000000013f9d1000-000000013fa57fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
416ec8.e6c: 000000013fa58000-000000013fa58fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
417ec8.e6c: 000000013fa59000-000000013faa3fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
418ec8.e6c: 000000013faa4000-000000013faa4fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
419ec8.e6c: 000000013faa5000-000000013faa5fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
420ec8.e6c: 000000013faa6000-000000013faaafff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
421ec8.e6c: 000000013faab000-000000013faabfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
422ec8.e6c: 000000013faac000-000000013faacfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
423ec8.e6c: 000000013faad000-000000013fab0fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
424ec8.e6c: 000000013fab1000-000000013fafbfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
425ec8.e6c: 000000013fafc000-fffff8037ffd7fff 0x0001/0x0000 0x0000000
426ec8.e6c: *000007feff620000-000007feff620fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\apisetschema.dll
427ec8.e6c: 000007feff621000-000007fdfec91fff 0x0001/0x0000 0x0000000
428ec8.e6c: *000007fffffb0000-000007fffff8cfff 0x0002/0x0002 0x0040000
429ec8.e6c: 000007fffffd3000-000007fffffcefff 0x0001/0x0000 0x0000000
430ec8.e6c: *000007fffffd7000-000007fffffd5fff 0x0004/0x0004 0x0020000
431ec8.e6c: 000007fffffd8000-000007fffffd1fff 0x0001/0x0000 0x0000000
432ec8.e6c: *000007fffffde000-000007fffffdbfff 0x0004/0x0004 0x0020000
433ec8.e6c: *000007fffffe0000-000007fffffcffff 0x0001/0x0002 0x0020000
434ec8.e6c: apisetschema.dll: timestamp 0x55636622 (rc=VINF_SUCCESS)
435ec8.e6c: VirtualBox.exe: timestamp 0x5630b0b7 (rc=VINF_SUCCESS)
436ec8.e6c: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
437ec8.e6c: '\Device\HarddiskVolume2\Windows\System32\apisetschema.dll' has no imports
438ec8.e6c: '\Device\HarddiskVolume2\Windows\System32\ntdll.dll' has no imports
439ec8.e6c: supR3HardNtChildPurify: Done after 531 ms and 0 fixes (loop #0).
440e18.c94: Log file opened: 5.0.9r103713 g_hStartupLog=0000000000000004 g_uNtVerCombined=0x611db110
441e18.c94: supR3HardenedVmProcessInit: uNtDllAddr=0000000077300000
442e18.c94: ntdll.dll: timestamp 0x556366f2 (rc=VINF_SUCCESS)
443e18.c94: New simple heap: #1 0000000000250000 LB 0x400000 (for 1740800 allocation)
444ec8.e6c: supR3HardenedEarlyCompact: Removed heap 1 (0x00000000270000 LB 0x400000)
445ec8.e6c: supR3HardNtEnableThreadCreation:
446e18.c94: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
447e18.c94: System32: \Device\HarddiskVolume2\Windows\System32
448e18.c94: WinSxS: \Device\HarddiskVolume2\Windows\winsxs
449e18.c94: KnownDllPath: C:\Windows\system32
450e18.c94: supR3HardenedVmProcessInit: Opening vboxdrv...
451e18.c94: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
452e18.c94: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
453e18.c94: Registered Dll notification callback with NTDLL.
454e18.c94: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\kernel32.dll)
455e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\kernel32.dll
456e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
457e18.c94: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
458e18.c94: supR3HardenedDllNotificationCallback: load 00000000771e0000 LB 0x0011f000 C:\Windows\system32\kernel32.dll [fFlags=0x0]
459e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
460e18.c94: supR3HardenedDllNotificationCallback: load 000007fefd2c0000 LB 0x0006c000 C:\Windows\system32\KERNELBASE.dll [fFlags=0x0]
461e18.c94: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\KernelBase.dll)
462e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\KernelBase.dll
463e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00000000771e0000 'C:\Windows\system32\kernel32.dll'
464e18.c94: supR3HardNtDisableThreadCreation: pvLdrInitThunk=000000007732b780 pvNtTerminateThread=000000007734e0e0
465ec8.e6c: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 15 ms.
466e18.c94: \SystemRoot\System32\ntdll.dll:
467e18.c94: CreationTime: 2015-06-30T18:24:53.606504900Z
468e18.c94: LastWriteTime: 2015-05-25T18:21:21.289963400Z
469e18.c94: ChangeTime: 2015-06-30T22:16:12.090281900Z
470e18.c94: FileAttributes: 0x20
471e18.c94: Size: 0x1a61c0
472e18.c94: NT Headers: 0xe0
473e18.c94: Timestamp: 0x556366f2
474e18.c94: Machine: 0x8664 - amd64
475e18.c94: Timestamp: 0x556366f2
476e18.c94: Image Version: 6.1
477e18.c94: SizeOfImage: 0x1a9000 (1740800)
478e18.c94: Resource Dir: 0x14d000 LB 0x5a028
479e18.c94: ProductName: Microsoft® Windows® Operating System
480e18.c94: ProductVersion: 6.1.7601.18869
481e18.c94: FileVersion: 6.1.7601.18869 (win7sp1_gdr.150525-0603)
482e18.c94: FileDescription: NT Layer DLL
483e18.c94: \SystemRoot\System32\kernel32.dll:
484e18.c94: CreationTime: 2015-06-30T18:24:53.107304100Z
485e18.c94: LastWriteTime: 2015-05-25T18:19:02.585000000Z
486e18.c94: ChangeTime: 2015-06-30T22:16:12.324282300Z
487e18.c94: FileAttributes: 0x20
488e18.c94: Size: 0x11be00
489e18.c94: NT Headers: 0xe8
490e18.c94: Timestamp: 0x556366fc
491e18.c94: Machine: 0x8664 - amd64
492e18.c94: Timestamp: 0x556366fc
493e18.c94: Image Version: 6.1
494e18.c94: SizeOfImage: 0x11f000 (1175552)
495e18.c94: Resource Dir: 0x116000 LB 0x528
496e18.c94: ProductName: Microsoft® Windows® Operating System
497e18.c94: ProductVersion: 6.1.7601.18869
498e18.c94: FileVersion: 6.1.7601.18869 (win7sp1_gdr.150525-0603)
499e18.c94: FileDescription: Windows NT BASE API Client DLL
500e18.c94: \SystemRoot\System32\KernelBase.dll:
501e18.c94: CreationTime: 2015-06-30T18:24:53.060504000Z
502e18.c94: LastWriteTime: 2015-05-25T18:19:02.585000000Z
503e18.c94: ChangeTime: 2015-06-30T22:16:12.324282300Z
504e18.c94: FileAttributes: 0x20
505e18.c94: Size: 0x67c00
506e18.c94: NT Headers: 0xe8
507e18.c94: Timestamp: 0x556366fd
508e18.c94: Machine: 0x8664 - amd64
509e18.c94: Timestamp: 0x556366fd
510e18.c94: Image Version: 6.1
511e18.c94: SizeOfImage: 0x6c000 (442368)
512e18.c94: Resource Dir: 0x6a000 LB 0x530
513e18.c94: ProductName: Microsoft® Windows® Operating System
514e18.c94: ProductVersion: 6.1.7601.18869
515e18.c94: FileVersion: 6.1.7601.18869 (win7sp1_gdr.150525-0603)
516e18.c94: FileDescription: Windows NT BASE API Client DLL
517e18.c94: \SystemRoot\System32\apisetschema.dll:
518e18.c94: CreationTime: 2015-06-30T18:24:52.124502300Z
519e18.c94: LastWriteTime: 2015-05-25T18:11:40.254000000Z
520e18.c94: ChangeTime: 2015-06-30T22:16:12.074681900Z
521e18.c94: FileAttributes: 0x20
522e18.c94: Size: 0x1a00
523e18.c94: NT Headers: 0xc0
524e18.c94: Timestamp: 0x55636622
525e18.c94: Machine: 0x8664 - amd64
526e18.c94: Timestamp: 0x55636622
527e18.c94: Image Version: 6.1
528e18.c94: SizeOfImage: 0x50000 (327680)
529e18.c94: Resource Dir: 0x30000 LB 0x3f8
530e18.c94: ProductName: Microsoft® Windows® Operating System
531e18.c94: ProductVersion: 6.1.7601.18869
532e18.c94: FileVersion: 6.1.7601.18869 (win7sp1_gdr.150525-0603)
533e18.c94: FileDescription: ApiSet Schema DLL
534e18.c94: supR3HardenedWinFindAdversaries: 0x80
535e18.c94: \SystemRoot\System32\drivers\MBAMSwissArmy.sys:
536e18.c94: CreationTime: 2015-07-18T23:42:46.446818300Z
537e18.c94: LastWriteTime: 2015-07-27T17:41:10.541992700Z
538e18.c94: ChangeTime: 2015-07-27T17:41:10.541992700Z
539e18.c94: FileAttributes: 0x20
540e18.c94: Size: 0x1bcd8
541e18.c94: NT Headers: 0xe8
542e18.c94: Timestamp: 0x552c190f
543e18.c94: Machine: 0x8664 - amd64
544e18.c94: Timestamp: 0x552c190f
545e18.c94: Image Version: 6.1
546e18.c94: SizeOfImage: 0x21000 (135168)
547e18.c94: Resource Dir: 0x1f000 LB 0x3f0
548e18.c94: ProductName: Malwarebytes Anti-Malware
549e18.c94: ProductVersion: 0.2.22.0
550e18.c94: FileVersion: 0.2.22.0
551e18.c94: FileDescription: Malwarebytes Anti-Malware
552e18.c94: \SystemRoot\System32\drivers\mwac.sys:
553e18.c94: CreationTime: 2015-07-18T23:42:36.308030900Z
554e18.c94: LastWriteTime: 2015-06-18T08:48:04.000000000Z
555e18.c94: ChangeTime: 2015-07-18T23:43:21.166227100Z
556e18.c94: FileAttributes: 0x20
557e18.c94: Size: 0xf8d8
558e18.c94: NT Headers: 0xf8
559e18.c94: Timestamp: 0x53a0f42a
560e18.c94: Machine: 0x8664 - amd64
561e18.c94: Timestamp: 0x53a0f42a
562e18.c94: Image Version: 6.2
563e18.c94: SizeOfImage: 0x12000 (73728)
564e18.c94: Resource Dir: 0x10000 LB 0x3e0
565e18.c94: ProductName: Malwarebytes Web Access Control
566e18.c94: ProductVersion: 1.0.6.0
567e18.c94: FileVersion: 1.0.6.0
568e18.c94: FileDescription: Malwarebytes Web Access Control
569e18.c94: \SystemRoot\System32\drivers\mbamchameleon.sys:
570e18.c94: CreationTime: 2015-07-18T23:42:36.315031800Z
571e18.c94: LastWriteTime: 2015-06-18T08:47:54.000000000Z
572e18.c94: ChangeTime: 2015-07-18T23:43:21.178228700Z
573e18.c94: FileAttributes: 0x20
574e18.c94: Size: 0x1aad8
575e18.c94: NT Headers: 0xd8
576e18.c94: Timestamp: 0x554cf757
577e18.c94: Machine: 0x8664 - amd64
578e18.c94: Timestamp: 0x554cf757
579e18.c94: Image Version: 6.1
580e18.c94: SizeOfImage: 0x1e000 (122880)
581e18.c94: Resource Dir: 0x1c000 LB 0xbd8
582e18.c94: ProductName: Malwarebytes Chameleon
583e18.c94: ProductVersion: 1.1.20.0
584e18.c94: FileVersion: 1.1.20.0
585e18.c94: FileDescription: Malwarebytes Chameleon Protection Driver
586e18.c94: \SystemRoot\System32\drivers\mbam.sys:
587e18.c94: CreationTime: 2015-07-18T23:42:36.304030400Z
588e18.c94: LastWriteTime: 2015-06-18T08:47:50.000000000Z
589e18.c94: ChangeTime: 2015-07-18T23:43:21.159226300Z
590e18.c94: FileAttributes: 0x20
591e18.c94: Size: 0x64d8
592e18.c94: NT Headers: 0xd8
593e18.c94: Timestamp: 0x540754e1
594e18.c94: Machine: 0x8664 - amd64
595e18.c94: Timestamp: 0x540754e1
596e18.c94: Image Version: 6.1
597e18.c94: SizeOfImage: 0xa000 (40960)
598e18.c94: Resource Dir: 0x8000 LB 0x3d0
599e18.c94: ProductName: Malwarebytes Anti-Malware
600e18.c94: ProductVersion: 0.1.15.0
601e18.c94: FileVersion: 0.1.15.0
602e18.c94: FileDescription: Malwarebytes Anti-Malware
603e18.c94: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
604e18.c94: Calling main()
605e18.c94: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
606e18.c94: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
607e18.c94: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
608e18.c94: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe)
609e18.c94: SUPR3HardenedMain: Final process, opening VBoxDrv...
610e18.c94: supR3HardenedEarlyCompact: Removed heap 1 (0x00000000250000 LB 0x400000)
611e18.c94: supR3HardNtEnableThreadCreation:
612e18.c94: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll)
613e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll
614e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000783fc0:C:\Windows\system32 [calling]
615e18.c94: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
616e18.c94: supR3HardenedDllNotificationCallback: load 000007fef9330000 LB 0x00005000 C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL [fFlags=0x0]
617e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
618e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
619e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007843f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files (x86)\Mozilla Firefox;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
620e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef9330000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
621e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
622e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007843f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files (x86)\Mozilla Firefox;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
623e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef9330000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
624e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef9330000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
625e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
626e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'crypt32.dll'.
627e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msasn1.dll'.
628e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
629e18.c94: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\wintrust.dll)
630e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wintrust.dll
631e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
632e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
633e18.c94: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll)
634e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
635e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
636e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume2\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
637e18.c94: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\msasn1.dll)
638e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msasn1.dll
639e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
640e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume2\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
641e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
642e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msasn1.dll'.
643e18.c94: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\crypt32.dll)
644e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\crypt32.dll
645e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
646e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
647e18.c94: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\msvcrt.dll)
648e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
649e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
650e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume2\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
651e18.c94: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
652e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
653e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
654e18.c94: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
655e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000783fc0:C:\Windows\system32 [calling]
656e18.c94: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
657e18.c94: supR3HardenedDllNotificationCallback: load 000007fefd350000 LB 0x0003b000 C:\Windows\system32\Wintrust.dll [fFlags=0x0]
658e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
659e18.c94: supR3HardenedDllNotificationCallback: load 000007fefdc40000 LB 0x0009f000 C:\Windows\system32\msvcrt.dll [fFlags=0x0]
660e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
661e18.c94: supR3HardenedDllNotificationCallback: load 000007fefd0e0000 LB 0x0016d000 C:\Windows\system32\CRYPT32.dll [fFlags=0x0]
662e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
663e18.c94: supR3HardenedDllNotificationCallback: load 000007fefd0b0000 LB 0x0000f000 C:\Windows\system32\MSASN1.dll [fFlags=0x0]
664e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
665e18.c94: supR3HardenedDllNotificationCallback: load 000007fefeca0000 LB 0x0012d000 C:\Windows\system32\RPCRT4.dll [fFlags=0x0]
666e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
667e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd350000 'C:\Windows\system32\Wintrust.dll'
668e18.c94: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\bcrypt.dll)
669e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\bcrypt.dll
670e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcrypt.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c9240:C:\Windows\system32 [calling]
671e18.c94: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
672e18.c94: supR3HardenedDllNotificationCallback: load 000007fefca40000 LB 0x00022000 C:\Windows\system32\bcrypt.dll [fFlags=0x0]
673e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
674e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefca40000 'C:\Windows\system32\bcrypt.dll'
675e18.c94: bcrypt.dll loaded at 000007fefca40000, BCryptOpenAlgorithmProvider at 000007fefca42640, preloading providers:
676e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
677e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'bcrypt.dll'.
678e18.c94: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll)
679e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll
680e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
681e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume2\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
682e18.c94: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
683e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
684e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
685e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
686e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'rpcrt4.dll'.
687e18.c94: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\advapi32.dll)
688e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\advapi32.dll
689e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
690e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
691e18.c94: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
692e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
693e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
694e18.c94: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
695e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcryptprimitives.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007843f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files (x86)\Mozilla Firefox;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
696e18.c94: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
697e18.c94: supR3HardenedDllNotificationCallback: load 000007fefc530000 LB 0x0004c000 C:\Windows\system32\bcryptprimitives.dll [fFlags=0x0]
698e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
699e18.c94: supR3HardenedDllNotificationCallback: load 000007fefdb60000 LB 0x000db000 C:\Windows\system32\ADVAPI32.dll [fFlags=0x0]
700e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
701e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msvcrt.dll'.
702e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'rpcrt4.dll'.
703e18.c94: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\sechost.dll)
704e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\sechost.dll
705e18.c94: supR3HardenedDllNotificationCallback: load 000007fefede0000 LB 0x0001f000 C:\Windows\SYSTEM32\sechost.dll [fFlags=0x0]
706e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\sechost.dll [lacks WinVerifyTrust]
707e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc530000 'C:\Windows\system32\bcryptprimitives.dll'
708e18.c94: BCryptOpenAlgorithmProvider(,'MD2',0,0) -> 0x0 (hAlgo=00000000007ca920)
709e18.c94: BCryptOpenAlgorithmProvider(,'MD4',0,0) -> 0x0 (hAlgo=00000000007cd7e0)
710e18.c94: BCryptOpenAlgorithmProvider(,'MD5',0,0) -> 0x0 (hAlgo=00000000007cd900)
711e18.c94: BCryptOpenAlgorithmProvider(,'SHA1',0,0) -> 0x0 (hAlgo=00000000007cdb10)
712e18.c94: BCryptOpenAlgorithmProvider(,'SHA256',0,0) -> 0x0 (hAlgo=00000000007cdc30)
713e18.c94: BCryptOpenAlgorithmProvider(,'SHA512',0,0) -> 0x0 (hAlgo=00000000007cdd50)
714e18.c94: BCryptOpenAlgorithmProvider(,'RSA',0,0) -> 0x0 (hAlgo=00000000007cdf90)
715e18.c94: BCryptOpenAlgorithmProvider(,'DSA',0,0) -> 0x0 (hAlgo=00000000007ce0b0)
716e18.c94: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\cryptsp.dll)
717e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cryptsp.dll
718e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
719e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
720e18.c94: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
721e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
722e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
723e18.c94: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
724e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTSP.dll (Input=CRYPTSP.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007843f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files (x86)\Mozilla Firefox;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
725e18.c94: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
726e18.c94: supR3HardenedDllNotificationCallback: load 000007fefc8f0000 LB 0x00018000 C:\Windows\system32\CRYPTSP.dll [fFlags=0x0]
727e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
728e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc8f0000 'C:\Windows\system32\CRYPTSP.dll'
729e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
730e18.c94: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\rsaenh.dll)
731e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\rsaenh.dll
732e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
733e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
734e18.c94: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
735e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007843f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files (x86)\Mozilla Firefox;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
736e18.c94: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
737e18.c94: supR3HardenedDllNotificationCallback: load 000007fefc5f0000 LB 0x00047000 C:\Windows\system32\rsaenh.dll [fFlags=0x0]
738e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
739e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc5f0000 'C:\Windows\system32\rsaenh.dll'
740e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
741e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ADVAPI32.dll (Input=ADVAPI32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007843f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files (x86)\Mozilla Firefox;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
742e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdb60000 'C:\Windows\system32\ADVAPI32.dll'
743e18.c94: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\cryptbase.dll)
744e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cryptbase.dll
745e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTBASE.dll (Input=CRYPTBASE.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007843f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files (x86)\Mozilla Firefox;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
746e18.c94: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptbase.dll [lacks WinVerifyTrust]
747e18.c94: supR3HardenedDllNotificationCallback: load 000007fefcf50000 LB 0x0000f000 C:\Windows\system32\CRYPTBASE.dll [fFlags=0x0]
748e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptbase.dll [lacks WinVerifyTrust]
749e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcf50000 'C:\Windows\system32\CRYPTBASE.dll'
750e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
751e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007843f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files (x86)\Mozilla Firefox;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
752e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00000000771e0000 'C:\Windows\system32\kernel32.dll'
753e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
754e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\WINTRUST.DLL (Input=WINTRUST.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007843f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files (x86)\Mozilla Firefox;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
755e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd350000 'C:\Windows\system32\WINTRUST.DLL'
756e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
757e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPT32.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00000000007843f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files (x86)\Mozilla Firefox;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
758e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd0e0000 'C:\Windows\system32\CRYPT32.dll'
759e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
760e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'advapi32.dll'.
761e18.c94: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\imagehlp.dll)
762e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\imagehlp.dll
763e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
764e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
765e18.c94: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
766e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
767e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
768e18.c94: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
769e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\imagehlp.dll (Input=imagehlp.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007843f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files (x86)\Mozilla Firefox;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
770e18.c94: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\imagehlp.dll [lacks WinVerifyTrust]
771e18.c94: supR3HardenedDllNotificationCallback: load 000007fefea70000 LB 0x00019000 C:\Windows\system32\imagehlp.dll [fFlags=0x0]
772e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\imagehlp.dll [lacks WinVerifyTrust]
773e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefea70000 'C:\Windows\system32\imagehlp.dll'
774e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
775e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTSP.dll (Input=CRYPTSP.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007843f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files (x86)\Mozilla Firefox;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
776e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc8f0000 'C:\Windows\system32\CRYPTSP.dll'
777e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
778e18.c94: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\user32.dll)
779e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\user32.dll
780e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
781e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
782e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
783e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'lpk.dll'.
784e18.c94: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\gdi32.dll)
785e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\gdi32.dll
786e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'lpk.dll'...
787e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'lpk.dll' -> '\Device\HarddiskVolume2\Windows\System32\lpk.dll' [rcNtRedir=0xc0150008]
788e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'gdi32.dll'.
789e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'user32.dll'.
790e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'usp10.dll'.
791e18.c94: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\lpk.dll)
792e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\lpk.dll
793e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
794e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
795e18.c94: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
796e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'usp10.dll'...
797e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'usp10.dll' -> '\Device\HarddiskVolume2\Windows\System32\usp10.dll' [rcNtRedir=0xc0150008]
798e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
799e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
800e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'gdi32.dll'.
801e18.c94: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\usp10.dll)
802e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\usp10.dll
803e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
804e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
805e18.c94: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
806e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
807e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
808e18.c94: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
809e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
810e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
811e18.c94: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
812e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
813e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
814e18.c94: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
815e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
816e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
817e18.c94: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
818e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\USER32.dll (Input=USER32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007843f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files (x86)\Mozilla Firefox;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
819e18.c94: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
820e18.c94: supR3HardenedDllNotificationCallback: load 00000000770e0000 LB 0x000fa000 C:\Windows\system32\USER32.dll [fFlags=0x0]
821e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
822e18.c94: supR3HardenedDllNotificationCallback: load 000007fefee30000 LB 0x00067000 C:\Windows\system32\GDI32.dll [fFlags=0x0]
823e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
824e18.c94: supR3HardenedDllNotificationCallback: load 000007feff2d0000 LB 0x0000e000 C:\Windows\system32\LPK.dll [fFlags=0x0]
825e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\lpk.dll [lacks WinVerifyTrust]
826e18.c94: supR3HardenedDllNotificationCallback: load 000007fefef80000 LB 0x000c9000 C:\Windows\system32\USP10.dll [fFlags=0x0]
827e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\usp10.dll [lacks WinVerifyTrust]
828e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
829e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\gdi32.dll (Input=gdi32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007843f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files (x86)\Mozilla Firefox;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
830e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefee30000 'C:\Windows\system32\gdi32.dll'
831e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'user32.dll'.
832e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
833e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msctf.dll'.
834e18.c94: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\imm32.dll)
835e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\imm32.dll
836e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msctf.dll'...
837e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'msctf.dll' -> '\Device\HarddiskVolume2\Windows\System32\msctf.dll' [rcNtRedir=0xc0150008]
838e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
839e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
840e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'gdi32.dll'.
841e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'imm32.dll'.
842e18.c94: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\msctf.dll)
843e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msctf.dll
844e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
845e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
846e18.c94: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
847e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
848e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
849e18.c94: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
850e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
851e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume2\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
852e18.c94: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\imm32.dll [lacks WinVerifyTrust]
853e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
854e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
855e18.c94: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
856e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
857e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
858e18.c94: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
859e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
860e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
861e18.c94: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
862e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\IMM32.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007843f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files (x86)\Mozilla Firefox;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
863e18.c94: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\imm32.dll [lacks WinVerifyTrust]
864e18.c94: supR3HardenedDllNotificationCallback: load 000007fefee00000 LB 0x0002e000 C:\Windows\system32\IMM32.DLL [fFlags=0x0]
865e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\imm32.dll [lacks WinVerifyTrust]
866e18.c94: supR3HardenedDllNotificationCallback: load 000007fefd600000 LB 0x00109000 C:\Windows\system32\MSCTF.dll [fFlags=0x0]
867e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msctf.dll [lacks WinVerifyTrust]
868e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefee00000 'C:\Windows\system32\IMM32.DLL'
869e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00000000770e0000 'C:\Windows\system32\USER32.dll'
870e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'bcrypt.dll'.
871e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
872e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msasn1.dll'.
873e18.c94: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\ncrypt.dll)
874e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ncrypt.dll
875e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
876e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume2\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
877e18.c94: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
878e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
879e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
880e18.c94: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
881e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
882e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume2\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
883e18.c94: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
884e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ncrypt.dll (Input=ncrypt.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007843f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files (x86)\Mozilla Firefox;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
885e18.c94: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\ncrypt.dll [lacks WinVerifyTrust]
886e18.c94: supR3HardenedDllNotificationCallback: load 000007fefca70000 LB 0x00050000 C:\Windows\system32\ncrypt.dll [fFlags=0x0]
887e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\ncrypt.dll [lacks WinVerifyTrust]
888e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefca70000 'C:\Windows\system32\ncrypt.dll'
889e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
890e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcrypt.dll (Input=bcrypt.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007843f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files (x86)\Mozilla Firefox;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
891e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefca40000 'C:\Windows\system32\bcrypt.dll'
892e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
893e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'rpcrt4.dll'.
894e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'profapi.dll'.
895e18.c94: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\userenv.dll)
896e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\userenv.dll
897e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'profapi.dll'...
898e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'profapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\profapi.dll' [rcNtRedir=0xc0150008]
899e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
900e18.c94: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\profapi.dll)
901e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\profapi.dll
902e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
903e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
904e18.c94: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
905e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
906e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
907e18.c94: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
908e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
909e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
910e18.c94: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
911e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\USERENV.dll (Input=USERENV.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007843f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files (x86)\Mozilla Firefox;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
912e18.c94: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\userenv.dll [lacks WinVerifyTrust]
913e18.c94: supR3HardenedDllNotificationCallback: load 000007fefd290000 LB 0x0001e000 C:\Windows\system32\USERENV.dll [fFlags=0x0]
914e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\userenv.dll [lacks WinVerifyTrust]
915e18.c94: supR3HardenedDllNotificationCallback: load 000007fefd0c0000 LB 0x0000f000 C:\Windows\system32\profapi.dll [fFlags=0x0]
916e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\profapi.dll [lacks WinVerifyTrust]
917e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd290000 'C:\Windows\system32\USERENV.dll'
918e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007843f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files (x86)\Mozilla Firefox;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
919e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefede0000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
920e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007843f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files (x86)\Mozilla Firefox;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
921e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefede0000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
922e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
923e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'rpcrt4.dll'.
924e18.c94: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\gpapi.dll)
925e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\gpapi.dll
926e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
927e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
928e18.c94: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
929e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
930e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
931e18.c94: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
932e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\GPAPI.dll (Input=GPAPI.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007843f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files (x86)\Mozilla Firefox;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
933e18.c94: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gpapi.dll [lacks WinVerifyTrust]
934e18.c94: supR3HardenedDllNotificationCallback: load 000007fefc360000 LB 0x0001b000 C:\Windows\system32\GPAPI.dll [fFlags=0x0]
935e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gpapi.dll [lacks WinVerifyTrust]
936e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc360000 'C:\Windows\system32\GPAPI.dll'
937e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-Management-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007843f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files (x86)\Mozilla Firefox;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
938e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefede0000 'API-MS-WIN-Service-Management-L1-1-0.dll'
939e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
940e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rpcrt4.dll (Input=rpcrt4.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007843f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files (x86)\Mozilla Firefox;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
941e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefeca0000 'C:\Windows\system32\rpcrt4.dll'
942e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-Management-L2-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007843f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files (x86)\Mozilla Firefox;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
943e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefede0000 'API-MS-WIN-Service-Management-L2-1-0.dll'
944e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007843f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files (x86)\Mozilla Firefox;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
945e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefede0000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
946e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
947e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'advapi32.dll'.
948e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'crypt32.dll'.
949e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'wldap32.dll'.
950e18.c94: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\cryptnet.dll)
951e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cryptnet.dll
952e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wldap32.dll'...
953e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'wldap32.dll' -> '\Device\HarddiskVolume2\Windows\System32\wldap32.dll' [rcNtRedir=0xc0150008]
954e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
955e18.c94: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\Wldap32.dll)
956e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\Wldap32.dll
957e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
958e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume2\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
959e18.c94: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
960e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
961e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
962e18.c94: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
963e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
964e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
965e18.c94: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
966e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
967e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
968e18.c94: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
969e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (Input=cryptnet.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007843f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files (x86)\Mozilla Firefox;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
970e18.c94: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
971e18.c94: supR3HardenedDllNotificationCallback: load 000007fefa220000 LB 0x00027000 C:\Windows\system32\cryptnet.dll [fFlags=0x0]
972e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
973e18.c94: supR3HardenedDllNotificationCallback: load 000007feff2e0000 LB 0x00052000 C:\Windows\system32\WLDAP32.dll [fFlags=0x0]
974e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\Wldap32.dll [lacks WinVerifyTrust]
975e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
976e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00000000007843f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files (x86)\Mozilla Firefox;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
977e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa220000 'C:\Windows\system32\cryptnet.dll'
978e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
979e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00000000007843f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files (x86)\Mozilla Firefox;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
980e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa220000 'C:\Windows\system32\cryptnet.dll'
981e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
982e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00000000007843f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files (x86)\Mozilla Firefox;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
983e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa220000 'C:\Windows\system32\cryptnet.dll'
984e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
985e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00000000007843f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files (x86)\Mozilla Firefox;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
986e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa220000 'C:\Windows\system32\cryptnet.dll'
987e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
988e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00000000007843f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files (x86)\Mozilla Firefox;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
989e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa220000 'C:\Windows\system32\cryptnet.dll'
990e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
991e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00000000007843f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files (x86)\Mozilla Firefox;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
992e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa220000 'C:\Windows\system32\cryptnet.dll'
993e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
994e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa220000 'C:\Windows\system32\cryptnet.dll'
995e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
996e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa220000 'C:\Windows\system32\cryptnet.dll'
997e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
998e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa220000 'C:\Windows\system32\cryptnet.dll'
999e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
1000e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa220000 'C:\Windows\system32\cryptnet.dll'
1001e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
1002e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa220000 'C:\Windows\system32\cryptnet.dll'
1003e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa220000 'C:\Windows\system32\cryptnet.dll'
1004e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
1005e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa220000 'C:\Windows\system32\cryptnet.dll'
1006e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007843f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files (x86)\Mozilla Firefox;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
1007e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefede0000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
1008e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\profapi.dll [lacks WinVerifyTrust]
1009e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\profapi.dll (Input=profapi.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007843f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files (x86)\Mozilla Firefox;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
1010e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd0c0000 'C:\Windows\system32\profapi.dll'
1011e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
1012e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
1013e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msvcrt.dll'.
1014e18.c94: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\shlwapi.dll)
1015e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\shlwapi.dll
1016e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1017e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1018e18.c94: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
1019e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1020e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1021e18.c94: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
1022e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1023e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1024e18.c94: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
1025e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\SHLWAPI.dll (Input=SHLWAPI.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007843f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files (x86)\Mozilla Firefox;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
1026e18.c94: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll [lacks WinVerifyTrust]
1027e18.c94: supR3HardenedDllNotificationCallback: load 000007fefd710000 LB 0x00071000 C:\Windows\system32\SHLWAPI.dll [fFlags=0x0]
1028e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll [lacks WinVerifyTrust]
1029e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd710000 'C:\Windows\system32\SHLWAPI.dll'
1030e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000000 pwszName=\SystemRoot\System32\ntdll.dll
1031e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: New context 00000000007ca840
1032e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
1033e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=EDC3F71C5551972E1510D1BCC6D436D5B6B426E8
1034e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007843f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files (x86)\Mozilla Firefox;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
1035e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefede0000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
1036e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-Management-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007843f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files (x86)\Mozilla Firefox;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
1037e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefede0000 'API-MS-WIN-Service-Management-L1-1-0.dll'
1038e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-winsvc-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007843f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files (x86)\Mozilla Firefox;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
1039e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefede0000 'API-MS-WIN-Service-winsvc-L1-1-0.dll'
1040e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
1041e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ADVAPI32.dll (Input=ADVAPI32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007843f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files (x86)\Mozilla Firefox;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
1042e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdb60000 'C:\Windows\system32\ADVAPI32.dll'
1043e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-LSALookup-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007843f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files (x86)\Mozilla Firefox;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
1044e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefede0000 'API-MS-Win-Security-LSALookup-L1-1-0.dll'
1045e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-LSALookup-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007843f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files (x86)\Mozilla Firefox;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
1046e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefede0000 'API-MS-Win-Security-LSALookup-L1-1-0.dll'
1047e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_85_for_KB3068708~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\SystemRoot\System32\ntdll.dll'
1048e18.c94: g_pfnWinVerifyTrust=000007fefd351010
1049e18.c94: supR3HardenedScreenImage/preload: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [redoing WinVerifyTrust]
1050e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000e0 pwszName=\Device\HarddiskVolume2\Windows\System32\crypt32.dll
1051e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ca840
1052e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
1053e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=BFD41401EDEBD4D914977D62B588ECABEE60CFD3
1054e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_112_for_KB3040272~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\crypt32.dll'
1055e18.c94: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1056e18.c94: supR3HardenedScreenImage/preload: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\crypt32.dll'
1057e18.c94: supR3HardenedScreenImage/preload: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [redoing WinVerifyTrust]
1058e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000d4 pwszName=\Device\HarddiskVolume2\Windows\System32\wintrust.dll
1059e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ca840
1060e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
1061e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=E1BBE4EB6D114F50142F24E2E2749EFD81021486
1062e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_75_for_KB3040272~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\wintrust.dll'
1063e18.c94: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1064e18.c94: supR3HardenedScreenImage/preload: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\wintrust.dll'
1065e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000038c pwszName=\Device\HarddiskVolume2\Windows\System32\shlwapi.dll
1066e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ca840
1067e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
1068e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=0AB8D9C9D3E1FC95D01F9A984B16ED031BB40CD8
1069e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\shlwapi.dll'
1070e18.c94: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1071e18.c94: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll'
1072e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000380 pwszName=\Device\HarddiskVolume2\Windows\System32\Wldap32.dll
1073e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ca840
1074e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
1075e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=87E73086F2528CF31D3AD5F0D71E04F8B942D5D8
1076e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\Wldap32.dll'
1077e18.c94: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1078e18.c94: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\Wldap32.dll'
1079e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000037c pwszName=\Device\HarddiskVolume2\Windows\System32\cryptnet.dll
1080e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ca840
1081e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
1082e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=756DC088EE40CF9369C990D71B200F3CB59FC35D
1083e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_75_for_KB3040272~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\cryptnet.dll'
1084e18.c94: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1085e18.c94: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\cryptnet.dll'
1086e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000258 pwszName=\Device\HarddiskVolume2\Windows\System32\gpapi.dll
1087e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ca840
1088e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
1089e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=470795C189226F7BDB8E50F42104CC34488B9340
1090e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\gpapi.dll'
1091e18.c94: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1092e18.c94: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\gpapi.dll'
1093e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000001c4 pwszName=\Device\HarddiskVolume2\Windows\System32\profapi.dll
1094e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ca840
1095e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
1096e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2449672745D9BA339420451D13FA0380AA768231
1097e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\profapi.dll'
1098e18.c94: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1099e18.c94: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\profapi.dll'
1100e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000001c0 pwszName=\Device\HarddiskVolume2\Windows\System32\userenv.dll
1101e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ca840
1102e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
1103e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=D3E1A2CC7367F751C19EBF4E6EDF5E9A10E47313
1104e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\userenv.dll'
1105e18.c94: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1106e18.c94: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\userenv.dll'
1107e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000001ac pwszName=\Device\HarddiskVolume2\Windows\System32\ncrypt.dll
1108e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ca840
1109e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
1110e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B24A74F7868A1824679A2006F7E6D98D206BCD0A
1111e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_85_for_KB3068708~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\Windows\System32\ncrypt.dll'
1112e18.c94: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1113e18.c94: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\ncrypt.dll'
1114e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000194 pwszName=\Device\HarddiskVolume2\Windows\System32\msctf.dll
1115e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ca840
1116e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
1117e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=03916BC73EE5A0E312E3D3100D0ACE1B78E93BB1
1118e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3033889~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\Windows\System32\msctf.dll'
1119e18.c94: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1120e18.c94: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\msctf.dll'
1121e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000190 pwszName=\Device\HarddiskVolume2\Windows\System32\imm32.dll
1122e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ca840
1123e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
1124e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=6EEE1AB3B6D79AFF857940FF5F51ED27698153EC
1125e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\imm32.dll'
1126e18.c94: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1127e18.c94: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\imm32.dll'
1128e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000018c pwszName=\Device\HarddiskVolume2\Windows\System32\usp10.dll
1129e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ca840
1130e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
1131e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=1F1AA8340DE02FC1B6341EE2706E55D56EDF63B8
1132e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB2957509~31bf3856ad364e35~amd64~~6.1.1.2.cat'; file='\Device\HarddiskVolume2\Windows\System32\usp10.dll'
1133e18.c94: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1134e18.c94: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\usp10.dll'
1135e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000188 pwszName=\Device\HarddiskVolume2\Windows\System32\lpk.dll
1136e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ca840
1137e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
1138e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=A9BD2F77F6F16827206A18B4C9CB5FCFA62A60CF
1139e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3032323~31bf3856ad364e35~amd64~~6.1.1.3.cat'; file='\Device\HarddiskVolume2\Windows\System32\lpk.dll'
1140e18.c94: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1141e18.c94: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\lpk.dll'
1142e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000184 pwszName=\Device\HarddiskVolume2\Windows\System32\gdi32.dll
1143e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ca840
1144e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
1145e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=1707E74860DCBF0241835EF4A1E7C39B40ED3ACA
1146e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3046306~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\Windows\System32\gdi32.dll'
1147e18.c94: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1148e18.c94: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\gdi32.dll'
1149e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000180 pwszName=\Device\HarddiskVolume2\Windows\System32\user32.dll
1150e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ca840
1151e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
1152e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B723D1B8AD72750B0CF5F6BEC66171B1254ED879
1153e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\user32.dll'
1154e18.c94: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1155e18.c94: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\user32.dll'
1156e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000017c pwszName=\Device\HarddiskVolume2\Windows\System32\imagehlp.dll
1157e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ca840
1158e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
1159e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2702EE05F1B717B0F2CE0FBE32784A47B8419DCA
1160e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_2_for_KB2893294~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\imagehlp.dll'
1161e18.c94: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1162e18.c94: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\imagehlp.dll'
1163e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000130 pwszName=\Device\HarddiskVolume2\Windows\System32\cryptbase.dll
1164e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ca840
1165e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
1166e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=A965CC5DB13A5FB23BBB1B6B5FA6D400DC49462F
1167e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\cryptbase.dll'
1168e18.c94: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1169e18.c94: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\cryptbase.dll'
1170e18.c94: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\rsaenh.dll'
1171e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000012c pwszName=\Device\HarddiskVolume2\Windows\System32\cryptsp.dll
1172e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ca840
1173e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
1174e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=BA7AC4A7E8ADDFEA90AC951ECB6D6546E4873613
1175e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_115_for_KB3033929~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\cryptsp.dll'
1176e18.c94: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1177e18.c94: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\cryptsp.dll'
1178e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000120 pwszName=\Device\HarddiskVolume2\Windows\System32\sechost.dll
1179e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ca840
1180e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
1181e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=CB669FA8DB80F8E50A29D055BB8D558E10E5E6B4
1182e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_85_for_KB3068708~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\Windows\System32\sechost.dll'
1183e18.c94: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1184e18.c94: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\sechost.dll'
1185e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000011c pwszName=\Device\HarddiskVolume2\Windows\System32\advapi32.dll
1186e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ca840
1187e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
1188e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=9BBB1FC4DED54F17702B287B63F8FE24EE5D7844
1189e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_85_for_KB3068708~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\Windows\System32\advapi32.dll'
1190e18.c94: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1191e18.c94: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\advapi32.dll'
1192e18.c94: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll'
1193e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000104 pwszName=\Device\HarddiskVolume2\Windows\System32\bcrypt.dll
1194e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ca840
1195e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
1196e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=62E377A1F0AD0C2EDC0A73CB3EFF841FF18D00D2
1197e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\bcrypt.dll'
1198e18.c94: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1199e18.c94: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\bcrypt.dll'
1200e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000e4 pwszName=\Device\HarddiskVolume2\Windows\System32\msvcrt.dll
1201e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ca840
1202e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
1203e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2CA2FD632B264C063162F71474266E3615B6420C
1204e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB2654428~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\Windows\System32\msvcrt.dll'
1205e18.c94: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1206e18.c94: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll'
1207e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000dc pwszName=\Device\HarddiskVolume2\Windows\System32\msasn1.dll
1208e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ca840
1209e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
1210e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F2FF57DC30D774F93061607060DAA0DD15E39CCE
1211e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\msasn1.dll'
1212e18.c94: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1213e18.c94: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\msasn1.dll'
1214e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000d8 pwszName=\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
1215e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ca840
1216e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
1217e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=03E871CFC4A3E7194619AFC99CEEA1EC75982D12
1218e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB2978668~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll'
1219e18.c94: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1220e18.c94: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll'
1221e18.c94: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll'
1222e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000028 pwszName=\Device\HarddiskVolume2\Windows\System32\KernelBase.dll
1223e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ca840
1224e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
1225e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=FD34F960ED54F1FB26E76A32FB91273E3093869E
1226e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_85_for_KB3068708~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\Windows\System32\KernelBase.dll'
1227e18.c94: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1228e18.c94: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\KernelBase.dll'
1229e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000020 pwszName=\Device\HarddiskVolume2\Windows\System32\kernel32.dll
1230e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ca840
1231e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
1232e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=1C47BBB61CB0D4D781B3BEC602422D40A0784762
1233e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_85_for_KB3068708~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\Windows\System32\kernel32.dll'
1234e18.c94: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1235e18.c94: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\kernel32.dll'
1236e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll
1237e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\crypt32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000838050:C:\Windows\system32 [calling]
1238e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd0e0000 'C:\Windows\system32\crypt32.dll'
1239e18.c94: supR3HardenedWinIsDesiredRootCA: Adding 0x5ad46780fa5df300 DC=com, DC=microsoft, CN=Microsoft Root Certificate Authority
1240e18.c94: supR3HardenedWinIsDesiredRootCA: Adding 0xea5386456178582b C=ZA, ST=Western Cape, L=Durbanville, O=Thawte, OU=Thawte Certification, CN=Thawte Timestamping CA
1241e18.c94: supR3HardenedWinIsDesiredRootCA: Adding 0x3be670c1bd02a900 OU=Copyright (c) 1997 Microsoft Corp., OU=Microsoft Corporation, CN=Microsoft Root Authority
1242e18.c94: supR3HardenedWinIsDesiredRootCA: Adding 0x4d3835aa4180b200 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2011
1243e18.c94: supR3HardenedWinIsDesiredRootCA: Adding 0x646e3fe3ba08df00 C=US, O=MSFT, CN=Microsoft Authenticode(tm) Root Authority
1244e18.c94: supR3HardenedWinIsDesiredRootCA: Adding 0xece4e4289e08b900 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010
1245e18.c94: supR3HardenedWinIsDesiredRootCA: Adding 0x43a9cc371ff5385a O=Microsoft Trust Network, OU=Microsoft Corporation, OU=Microsoft Time Stamping Service Root, OU=Copyright (c) 1997 Microsoft Corp.
1246e18.c94: supR3HardenedWinIsDesiredRootCA: Adding 0x2e2d2c7c68f0202e O=VeriSign Trust Network, OU=VeriSign, Inc., OU=VeriSign Time Stamping Service Root, OU=NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.
1247e18.c94: supR3HardenedWinIsDesiredRootCA: Adding 0xf4fd306318ccda00 C=US, O=GeoTrust Inc., CN=GeoTrust Global CA
1248e18.c94: supR3HardenedWinIsDesiredRootCA: Adding 0x3d98ab22bb04a300 C=IE, O=Baltimore, OU=CyberTrust, CN=Baltimore CyberTrust Root
1249e18.c94: supR3HardenedWinIsDesiredRootCA: Adding 0xa0ee62086758b15d C=US, O=Equifax, OU=Equifax Secure Certificate Authority
1250e18.c94: supR3HardenedWinIsDesiredRootCA: Adding 0xa3ce8d99e60eda00 C=BE, O=GlobalSign nv-sa, OU=Root CA, CN=GlobalSign Root CA
1251e18.c94: supR3HardenedWinIsDesiredRootCA: Adding 0xa8de7211e13be200 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root CA
1252e18.c94: supR3HardenedWinIsDesiredRootCA: Adding 0x7ae89c50f0b6a00f C=US, O=GTE Corporation, OU=GTE CyberTrust Solutions, Inc., CN=GTE CyberTrust Global Root
1253e18.c94: supR3HardenedWinIsDesiredRootCA: Adding 0x4d3835aa4180b200 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2011
1254e18.c94: supR3HardenedWinIsDesiredRootCA: Adding 0x14018a1bf29e595c C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority
1255e18.c94: supR3HardenedWinIsDesiredRootCA: Adding 0x9e5bc2d78b6a3636 C=ZA, ST=Western Cape, L=Cape Town, O=Thawte Consulting cc, OU=Certification Services Division, CN=Thawte Premium Server CA, [email protected]
1256e18.c94: supR3HardenedWinIsDesiredRootCA: Adding 0xd4fbe673e5ccc600 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA
1257e18.c94: supR3HardenedWinIsDesiredRootCA: Adding 0x357a29080824af00 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2006 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G5
1258e18.c94: supR3HardenedWinIsDesiredRootCA: Adding 0x8043e4ce150ead00 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID Root CA
1259e18.c94: supR3HardenedWinRetrieveTrustedRootCAs: cAdded=20
1260e18.c94: SUPR3HardenedMain: Load Runtime...
1261e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
1262e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
1263e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ws2_32.dll'.
1264e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'rpcrt4.dll'.
1265e18.c94: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll) WinVerifyTrust
1266e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
1267e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
1268e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
1269e18.c94: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
1270e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
1271e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
1272e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000040c pwszName=\Device\HarddiskVolume2\Windows\System32\ws2_32.dll
1273e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ca840
1274e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
1275e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=3EF3BDC1E84DFA17EA056313214EE88EC3E66F79
1276e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\ws2_32.dll'
1277e18.c94: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1278e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1279e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'rpcrt4.dll'.
1280e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'nsi.dll'.
1281e18.c94: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ws2_32.dll) WinVerifyTrust
1282e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
1283e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
1284e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
1285e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
1286e18.c94: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll) WinVerifyTrust
1287e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
1288e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
1289e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
1290e18.c94: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll) WinVerifyTrust
1291e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
1292e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
1293e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
1294e18.c94: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
1295e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
1296e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume2\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
1297e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000438 pwszName=\Device\HarddiskVolume2\Windows\System32\nsi.dll
1298e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ca840
1299e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
1300e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=7AFD8538945F2D05BC1AF949B9B19B7D2D9FBBF8
1301e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\nsi.dll'
1302e18.c94: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1303e18.c94: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\nsi.dll) WinVerifyTrust
1304e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\nsi.dll
1305e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
1306e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
1307e18.c94: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
1308e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1309e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1310e18.c94: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
1311e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007f3160:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
1312e18.c94: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
1313e18.c94: supR3HardenedDllNotificationCallback: load 000007fef0cf0000 LB 0x0055f000 C:\Program Files\Oracle\VirtualBox\VBoxRT.dll [fFlags=0x0]
1314e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
1315e18.c94: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
1316e18.c94: supR3HardenedDllNotificationCallback: load 0000000074d40000 LB 0x000d2000 C:\Program Files\Oracle\VirtualBox\MSVCR100.dll [fFlags=0x0]
1317e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
1318e18.c94: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
1319e18.c94: supR3HardenedDllNotificationCallback: load 0000000074ca0000 LB 0x00098000 C:\Program Files\Oracle\VirtualBox\MSVCP100.dll [fFlags=0x0]
1320e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
1321e18.c94: supR3HardenedDllNotificationCallback: load 000007fefd8b0000 LB 0x0004d000 C:\Windows\system32\WS2_32.dll [fFlags=0x0]
1322e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
1323e18.c94: supR3HardenedDllNotificationCallback: load 000007fefedd0000 LB 0x00008000 C:\Windows\system32\NSI.dll [fFlags=0x0]
1324e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\nsi.dll
1325e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
1326e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007843f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files (x86)\Mozilla Firefox;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
1327e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef0cf0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1328e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
1329e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007843f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files (x86)\Mozilla Firefox;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
1330e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef0cf0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1331e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
1332e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007843f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files (x86)\Mozilla Firefox;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
1333e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef0cf0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1334e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
1335e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007843f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files (x86)\Mozilla Firefox;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
1336e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef0cf0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1337e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
1338e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007843f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files (x86)\Mozilla Firefox;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
1339e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef0cf0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1340e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
1341e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007843f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files (x86)\Mozilla Firefox;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
1342e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef0cf0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1343e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef0cf0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1344e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef0cf0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1345e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef0cf0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1346e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef0cf0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1347e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef0cf0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1348e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef0cf0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1349e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef0cf0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1350e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
1351e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007843f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files (x86)\Mozilla Firefox;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
1352e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef0cf0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1353e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef0cf0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1354e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef0cf0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1355e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef0cf0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1356e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef0cf0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1357e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef0cf0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1358e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef0cf0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1359e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef0cf0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1360e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef0cf0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1361e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef0cf0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1362e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef0cf0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1363e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef0cf0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1364e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef0cf0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1365e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef0cf0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1366e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef0cf0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1367e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef0cf0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1368e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
1369e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007843f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files (x86)\Mozilla Firefox;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
1370e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef0cf0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1371e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef0cf0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1372e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef0cf0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1373e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef0cf0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1374e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll
1375e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007eb160:C:\Windows\system32 [calling]
1376e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd350000 'C:\Windows\system32\Wintrust.dll'
1377e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll
1378e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\crypt32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007eb160:C:\Windows\system32 [calling]
1379e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd0e0000 'C:\Windows\system32\crypt32.dll'
1380e18.c94: SUPR3HardenedMain: Load TrustedMain...
1381e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'opengl32.dll'.
1382e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
1383e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcp100.dll'.
1384e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcr100.dll'.
1385e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qtcorevbox4.dll'.
1386e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'qtguivbox4.dll'.
1387e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'qtnetworkvbox4.dll'.
1388e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'qtopenglvbox4.dll'.
1389e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'user32.dll'.
1390e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'gdi32.dll'.
1391e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'advapi32.dll'.
1392e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'shell32.dll'.
1393e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'ole32.dll'.
1394e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'oleaut32.dll'.
1395e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #15 'comdlg32.dll'.
1396e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'winmm.dll'.
1397e18.c94: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.dll) WinVerifyTrust
1398e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.dll
1399e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
1400e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
1401e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000480 pwszName=\Device\HarddiskVolume2\Windows\System32\winmm.dll
1402e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ca840
1403e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
1404e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=82E2B2A7826F88BEB98FFF0540C9BDB0A12F001A
1405e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\winmm.dll'
1406e18.c94: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1407e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
1408e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
1409e18.c94: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\winmm.dll) WinVerifyTrust
1410e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\winmm.dll
1411e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comdlg32.dll'...
1412e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'comdlg32.dll' -> '\Device\HarddiskVolume2\Windows\System32\comdlg32.dll' [rcNtRedir=0xc0150008]
1413e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000460 pwszName=\Device\HarddiskVolume2\Windows\System32\comdlg32.dll
1414e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ca840
1415e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
1416e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=66EE5BDFFA413AEA9E1FE7838A08646E94136DA5
1417e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\comdlg32.dll'
1418e18.c94: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1419e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1420e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'shlwapi.dll'.
1421e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
1422e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'gdi32.dll'.
1423e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'comctl32.dll'.
1424e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'shell32.dll'.
1425e18.c94: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\comdlg32.dll) WinVerifyTrust
1426e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\comdlg32.dll
1427e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
1428e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
1429e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000474 pwszName=\Device\HarddiskVolume2\Windows\System32\oleaut32.dll
1430e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ca840
1431e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
1432e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=8A837B0D823EB506C6A4C447C1962174D27ED954
1433e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3020338~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\oleaut32.dll'
1434e18.c94: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1435e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ole32.dll'.
1436e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
1437e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
1438e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'user32.dll'.
1439e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'gdi32.dll'.
1440e18.c94: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\oleaut32.dll) WinVerifyTrust
1441e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
1442e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
1443e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
1444e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000048c pwszName=\Device\HarddiskVolume2\Windows\System32\ole32.dll
1445e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ca840
1446e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
1447e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2E64AE329BD5124592BC8CB0B327AA3B95DC65B7
1448e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\ole32.dll'
1449e18.c94: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1450e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1451e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
1452e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'user32.dll'.
1453e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'rpcrt4.dll'.
1454e18.c94: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ole32.dll) WinVerifyTrust
1455e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ole32.dll
1456e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
1457e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
1458e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000484 pwszName=\Device\HarddiskVolume2\Windows\System32\shell32.dll
1459e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ca840
1460e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
1461e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=0ED534A13973A0F8A98CD4EDC6CBC56E0448E994
1462e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_2_for_KB3039066~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\shell32.dll'
1463e18.c94: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1464e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1465e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #21 'shlwapi.dll'.
1466e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'user32.dll'.
1467e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #24 'gdi32.dll'.
1468e18.c94: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\shell32.dll) WinVerifyTrust
1469e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\shell32.dll
1470e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
1471e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
1472e18.c94: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
1473e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1474e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1475e18.c94: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll
1476e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1477e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1478e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtopenglvbox4.dll'...
1479e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtopenglvbox4.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qtopenglvbox4.dll' [rcNtRedir=0xc0150008]
1480e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'opengl32.dll'.
1481e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
1482e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
1483e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qtguivbox4.dll'.
1484e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qtcorevbox4.dll'.
1485e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcr100.dll'.
1486e18.c94: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll) WinVerifyTrust
1487e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll
1488e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtnetworkvbox4.dll'...
1489e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtnetworkvbox4.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qtnetworkvbox4.dll' [rcNtRedir=0xc0150008]
1490e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ws2_32.dll'.
1491e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'qtcorevbox4.dll'.
1492e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcr100.dll'.
1493e18.c94: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtNetworkVBox4.dll) WinVerifyTrust
1494e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtNetworkVBox4.dll
1495e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtguivbox4.dll'...
1496e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtguivbox4.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qtguivbox4.dll' [rcNtRedir=0xc0150008]
1497e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
1498e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'comdlg32.dll'.
1499e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'oleaut32.dll'.
1500e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'imm32.dll'.
1501e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'winmm.dll'.
1502e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'winspool.drv'.
1503e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ole32.dll'.
1504e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'user32.dll'.
1505e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'advapi32.dll'.
1506e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'shell32.dll'.
1507e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'qtcorevbox4.dll'.
1508e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'msvcp100.dll'.
1509e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'msvcr100.dll'.
1510e18.c94: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll) WinVerifyTrust
1511e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll
1512e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtcorevbox4.dll'...
1513e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtcorevbox4.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qtcorevbox4.dll' [rcNtRedir=0xc0150008]
1514e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
1515e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'ole32.dll'.
1516e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
1517e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ws2_32.dll'.
1518e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcp100.dll'.
1519e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcr100.dll'.
1520e18.c94: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll) WinVerifyTrust
1521e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll
1522e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
1523e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
1524e18.c94: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
1525e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
1526e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
1527e18.c94: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
1528e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
1529e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
1530e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
1531e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
1532e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004c8 pwszName=\Device\HarddiskVolume2\Windows\System32\opengl32.dll
1533e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ca840
1534e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
1535e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=608AC397FCC42B9FBAE25CB8C25EAF4C19AA384D
1536e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\opengl32.dll'
1537e18.c94: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1538e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1539e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
1540e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'gdi32.dll'.
1541e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'glu32.dll'.
1542e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ddraw.dll'.
1543e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'user32.dll'.
1544e18.c94: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\opengl32.dll) WinVerifyTrust
1545e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\opengl32.dll
1546e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1547e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1548e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ddraw.dll'...
1549e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'ddraw.dll' -> '\Device\HarddiskVolume2\Windows\System32\ddraw.dll' [rcNtRedir=0xc0150008]
1550e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004bc pwszName=\Device\HarddiskVolume2\Windows\System32\ddraw.dll
1551e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ca840
1552e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
1553e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=24C763EA54CD792A0F1618411061DC356EE31FF6
1554e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\ddraw.dll'
1555e18.c94: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1556e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1557e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
1558e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'dciman32.dll'.
1559e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
1560e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'setupapi.dll'.
1561e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'dwmapi.dll'.
1562e18.c94: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ddraw.dll) WinVerifyTrust
1563e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ddraw.dll
1564e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'glu32.dll'...
1565e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'glu32.dll' -> '\Device\HarddiskVolume2\Windows\System32\glu32.dll' [rcNtRedir=0xc0150008]
1566e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004b8 pwszName=\Device\HarddiskVolume2\Windows\System32\glu32.dll
1567e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ca840
1568e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
1569e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=60E45AB914E06A11F44EA76C6EF750AF892F9EA2
1570e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\glu32.dll'
1571e18.c94: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1572e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1573e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'opengl32.dll'.
1574e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
1575e18.c94: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\glu32.dll) WinVerifyTrust
1576e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\glu32.dll
1577e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1578e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1579e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
1580e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
1581e18.c94: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
1582e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1583e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1584e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
1585e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
1586e18.c94: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
1587e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
1588e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
1589e18.c94: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
1590e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
1591e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
1592e18.c94: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
1593e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
1594e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
1595e18.c94: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
1596e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
1597e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
1598e18.c94: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
1599e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1600e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1601e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
1602e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
1603e18.c94: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
1604e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
1605e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
1606e18.c94: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
1607e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtcorevbox4.dll'...
1608e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtcorevbox4.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qtcorevbox4.dll' [rcNtRedir=0xc0150008]
1609e18.c94: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll
1610e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
1611e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
1612e18.c94: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
1613e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
1614e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
1615e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1616e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1617e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
1618e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
1619e18.c94: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
1620e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winspool.drv'...
1621e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'winspool.drv' -> '\Device\HarddiskVolume2\Windows\System32\winspool.drv' [rcNtRedir=0xc0150008]
1622e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004ac pwszName=\Device\HarddiskVolume2\Windows\System32\winspool.drv
1623e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ca840
1624e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
1625e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=C89A2ED7B99A056D78CA6BAC9CCAB8B1FF119A14
1626e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\winspool.drv'
1627e18.c94: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1628e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1629e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
1630e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
1631e18.c94: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\winspool.drv) WinVerifyTrust
1632e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\winspool.drv
1633e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
1634e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
1635e18.c94: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
1636e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
1637e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume2\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
1638e18.c94: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\imm32.dll
1639e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
1640e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
1641e18.c94: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
1642e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comdlg32.dll'...
1643e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'comdlg32.dll' -> '\Device\HarddiskVolume2\Windows\System32\comdlg32.dll' [rcNtRedir=0xc0150008]
1644e18.c94: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\comdlg32.dll
1645e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1646e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1647e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
1648e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
1649e18.c94: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
1650e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtcorevbox4.dll'...
1651e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtcorevbox4.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qtcorevbox4.dll' [rcNtRedir=0xc0150008]
1652e18.c94: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll
1653e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
1654e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
1655e18.c94: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
1656e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
1657e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
1658e18.c94: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
1659e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtcorevbox4.dll'...
1660e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtcorevbox4.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qtcorevbox4.dll' [rcNtRedir=0xc0150008]
1661e18.c94: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll
1662e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtguivbox4.dll'...
1663e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtguivbox4.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qtguivbox4.dll' [rcNtRedir=0xc0150008]
1664e18.c94: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll
1665e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1666e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1667e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1668e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1669e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
1670e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
1671e18.c94: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
1672e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1673e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1674e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1675e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1676e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
1677e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
1678e18.c94: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll
1679e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1680e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1681e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
1682e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
1683e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1684e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1685e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1686e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1687e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1688e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1689e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1690e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1691e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1692e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1693e18.c94: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll
1694e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
1695e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
1696e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1697e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1698e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
1699e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
1700e18.c94: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
1701e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
1702e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
1703e18.c94: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
1704e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comctl32.dll'...
1705e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'comctl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\comctl32.dll' [rcNtRedir=0x0]
1706e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004d8 pwszName=\Device\HarddiskVolume2\Windows\System32\comctl32.dll
1707e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ca840
1708e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
1709e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=761964761EE466757E306124E042F4C2ACBEA092
1710e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3059317~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\Windows\System32\comctl32.dll'
1711e18.c94: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1712e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'advapi32.dll'.
1713e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
1714e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
1715e18.c94: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\comctl32.dll) WinVerifyTrust
1716e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\comctl32.dll
1717e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1718e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1719e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1720e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1721e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
1722e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
1723e18.c94: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll
1724e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1725e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1726e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1727e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1728e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1729e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1730e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1731e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1732e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1733e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1734e18.c94: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll
1735e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
1736e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
1737e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1738e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1739e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1740e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1741e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1742e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1743e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1744e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1745e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
1746e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
1747e18.c94: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
1748e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1749e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1750e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dwmapi.dll'...
1751e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'dwmapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\dwmapi.dll' [rcNtRedir=0xc0150008]
1752e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000049c pwszName=\Device\HarddiskVolume2\Windows\System32\dwmapi.dll
1753e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ca840
1754e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
1755e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=C408F88301F22BE596490B4A80BD2E09034763B4
1756e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3048761~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\Windows\System32\dwmapi.dll'
1757e18.c94: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1758e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1759e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
1760e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
1761e18.c94: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\dwmapi.dll) WinVerifyTrust
1762e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\dwmapi.dll
1763e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
1764e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
1765e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000498 pwszName=\Device\HarddiskVolume2\Windows\System32\setupapi.dll
1766e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ca840
1767e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
1768e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=1499C4FEA6E143F9BEC35B4FFA098917D3A6EBF2
1769e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\setupapi.dll'
1770e18.c94: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1771e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'cfgmgr32.dll'.
1772e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcrt.dll'.
1773e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'gdi32.dll'.
1774e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
1775e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'user32.dll'.
1776e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'oleaut32.dll'.
1777e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'devobj.dll'.
1778e18.c94: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\setupapi.dll) WinVerifyTrust
1779e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\setupapi.dll
1780e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1781e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1782e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dciman32.dll'...
1783e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'dciman32.dll' -> '\Device\HarddiskVolume2\Windows\System32\dciman32.dll' [rcNtRedir=0xc0150008]
1784e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004e8 pwszName=\Device\HarddiskVolume2\Windows\System32\dciman32.dll
1785e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ca840
1786e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
1787e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=8C17410BD716DCF557221B982F7A015B5B6AC2B4
1788e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3032323~31bf3856ad364e35~amd64~~6.1.1.3.cat'; file='\Device\HarddiskVolume2\Windows\System32\dciman32.dll'
1789e18.c94: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1790e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1791e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'gdi32.dll'.
1792e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
1793e18.c94: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\dciman32.dll) WinVerifyTrust
1794e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\dciman32.dll
1795e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1796e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1797e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1798e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1799e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1800e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1801e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1802e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1803e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1804e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1805e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'devobj.dll'...
1806e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'devobj.dll' -> '\Device\HarddiskVolume2\Windows\System32\devobj.dll' [rcNtRedir=0xc0150008]
1807e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004f0 pwszName=\Device\HarddiskVolume2\Windows\System32\devobj.dll
1808e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ca840
1809e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
1810e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B410A095222E69F0ECE7D66E4AC27A7125D2EB5A
1811e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\devobj.dll'
1812e18.c94: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1813e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1814e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'cfgmgr32.dll'.
1815e18.c94: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\devobj.dll) WinVerifyTrust
1816e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\devobj.dll
1817e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
1818e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
1819e18.c94: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
1820e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1821e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1822e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
1823e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
1824e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1825e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1826e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1827e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1828e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
1829e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
1830e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004e4 pwszName=\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll
1831e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ca840
1832e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
1833e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=8F731777EFC4BC982C1E1467FBF29A74CC14D93A
1834e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll'
1835e18.c94: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1836e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1837e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'rpcrt4.dll'.
1838e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
1839e18.c94: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll) WinVerifyTrust
1840e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll
1841e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1842e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1843e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1844e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1845e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1846e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1847e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
1848e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
1849e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
1850e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
1851e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1852e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1853e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
1854e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
1855e18.c94: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll
1856e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1857e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1858e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VirtualBox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007f3160:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
1859e18.c94: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.dll
1860e18.c94: supR3HardenedDllNotificationCallback: load 000007feefc60000 LB 0x00ab9000 C:\Program Files\Oracle\VirtualBox\VirtualBox.dll [fFlags=0x0]
1861e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.dll
1862e18.c94: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
1863e18.c94: supR3HardenedDllNotificationCallback: load 000007fef3870000 LB 0x0011d000 C:\Windows\system32\OPENGL32.dll [fFlags=0x0]
1864e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
1865e18.c94: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\glu32.dll
1866e18.c94: supR3HardenedDllNotificationCallback: load 000007fef8590000 LB 0x0002d000 C:\Windows\system32\GLU32.dll [fFlags=0x0]
1867e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\glu32.dll
1868e18.c94: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ddraw.dll
1869e18.c94: supR3HardenedDllNotificationCallback: load 000007fef19e0000 LB 0x000f1000 C:\Windows\system32\DDRAW.dll [fFlags=0x0]
1870e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ddraw.dll
1871e18.c94: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dciman32.dll
1872e18.c94: supR3HardenedDllNotificationCallback: load 000007fef87b0000 LB 0x00008000 C:\Windows\system32\DCIMAN32.dll [fFlags=0x0]
1873e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dciman32.dll
1874e18.c94: supR3HardenedDllNotificationCallback: load 000007feff0f0000 LB 0x001d7000 C:\Windows\system32\SETUPAPI.dll [fFlags=0x0]
1875e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\setupapi.dll
1876e18.c94: supR3HardenedDllNotificationCallback: load 000007fefd430000 LB 0x00036000 C:\Windows\system32\CFGMGR32.dll [fFlags=0x0]
1877e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll
1878e18.c94: supR3HardenedDllNotificationCallback: load 000007fefeea0000 LB 0x000d7000 C:\Windows\system32\OLEAUT32.dll [fFlags=0x0]
1879e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
1880e18.c94: supR3HardenedDllNotificationCallback: load 000007fefea90000 LB 0x00203000 C:\Windows\system32\ole32.dll [fFlags=0x0]
1881e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
1882e18.c94: supR3HardenedDllNotificationCallback: load 000007fefd330000 LB 0x0001a000 C:\Windows\system32\DEVOBJ.dll [fFlags=0x0]
1883e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\devobj.dll
1884e18.c94: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dwmapi.dll
1885e18.c94: supR3HardenedDllNotificationCallback: load 000007fefadb0000 LB 0x00018000 C:\Windows\system32\dwmapi.dll [fFlags=0x0]
1886e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dwmapi.dll
1887e18.c94: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll
1888e18.c94: supR3HardenedDllNotificationCallback: load 00000000749c0000 LB 0x002de000 C:\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll [fFlags=0x0]
1889e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll
1890e18.c94: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll
1891e18.c94: supR3HardenedDllNotificationCallback: load 000000006bd00000 LB 0x0096c000 C:\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll [fFlags=0x0]
1892e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll
1893e18.c94: supR3HardenedDllNotificationCallback: load 000007feff050000 LB 0x00097000 C:\Windows\system32\COMDLG32.dll [fFlags=0x0]
1894e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\comdlg32.dll
1895e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'advapi32.dll'.
1896e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
1897e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
1898e18.c94: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll)
1899e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll
1900e18.c94: supR3HardenedDllNotificationCallback: load 000007fef7dd0000 LB 0x000a0000 C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\COMCTL32.dll [fFlags=0x0]
1901e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll [avoiding WinVerifyTrust]
1902e18.c94: supR3HardenedDllNotificationCallback: load 000007fefdce0000 LB 0x00d89000 C:\Windows\system32\SHELL32.dll [fFlags=0x0]
1903e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
1904e18.c94: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
1905e18.c94: supR3HardenedDllNotificationCallback: load 000007fefaea0000 LB 0x0003b000 C:\Windows\system32\WINMM.dll [fFlags=0x0]
1906e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
1907e18.c94: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winspool.drv
1908e18.c94: supR3HardenedDllNotificationCallback: load 000007fef8070000 LB 0x00071000 C:\Windows\system32\WINSPOOL.DRV [fFlags=0x0]
1909e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winspool.drv
1910e18.c94: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtNetworkVBox4.dll
1911e18.c94: supR3HardenedDllNotificationCallback: load 00000000748b0000 LB 0x00105000 C:\Program Files\Oracle\VirtualBox\QtNetworkVBox4.dll [fFlags=0x0]
1912e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtNetworkVBox4.dll
1913e18.c94: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll
1914e18.c94: supR3HardenedDllNotificationCallback: load 00000000747d0000 LB 0x000dc000 C:\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll [fFlags=0x0]
1915e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll
1916e18.c94: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume2\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll'.
1917e18.c94: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll' [rescheduled]
1918e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\imm32.dll
1919e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1920e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1921e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1922e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1923e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
1924e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
1925e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\imm32.dll (Input=imm32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007f3430:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
1926e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefee00000 'C:\Windows\system32\imm32.dll'
1927e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feefc60000 'C:\Program Files\Oracle\VirtualBox\VirtualBox.dll'
1928e18.c94: SUPR3HardenedMain: Calling TrustedMain (000007feefc610d0)...
1929e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
1930e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\winmm.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007f3160:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
1931e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefaea0000 'C:\Windows\system32\winmm.dll'
1932e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000588 pwszName=\Device\HarddiskVolume2\Windows\System32\uxtheme.dll
1933e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ca840
1934e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
1935e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=936D45CC7026757A151F62882B557DD75D5FCB21
1936e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\uxtheme.dll'
1937e18.c94: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1938e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1939e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
1940e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'gdi32.dll'.
1941e18.c94: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\uxtheme.dll) WinVerifyTrust
1942e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
1943e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1944e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1945e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1946e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1947e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1948e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1949e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000003da0e0:C:\Windows\system32;C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
1950e18.c94: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
1951e18.c94: supR3HardenedDllNotificationCallback: load 000007fefb4b0000 LB 0x00056000 C:\Windows\system32\uxtheme.dll [fFlags=0x0]
1952e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
1953e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefb4b0000 'C:\Windows\system32\uxtheme.dll'
1954e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
1955e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000003da0e0:C:\Windows\system32;C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
1956e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefb4b0000 'C:\Windows\system32\uxtheme.dll'
1957e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
1958e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000003dad40:C:\Windows\system32;C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
1959e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefb4b0000 'C:\Windows\system32\uxtheme.dll'
1960e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
1961e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000003dad40:C:\Windows\system32;C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
1962e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefb4b0000 'C:\Windows\system32\uxtheme.dll'
1963e18.c94: \Device\HarddiskVolume2\Program Files (x86)\TeamViewer\tv_x64.dll: Owner is administrators group.
1964e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'version.dll'.
1965e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'comctl32.dll'.
1966e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
1967e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'gdi32.dll'.
1968e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'shell32.dll'.
1969e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ole32.dll'.
1970e18.c94: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files (x86)\TeamViewer\tv_x64.dll) WinVerifyTrust
1971e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files (x86)\TeamViewer\tv_x64.dll
1972e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
1973e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
1974e18.c94: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
1975e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
1976e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
1977e18.c94: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
1978e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1979e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1980e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1981e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1982e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comctl32.dll'...
1983e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'comctl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\comctl32.dll' [rcNtRedir=0x0]
1984e18.c94: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\comctl32.dll
1985e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'version.dll'...
1986e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'version.dll' -> '\Device\HarddiskVolume2\Windows\System32\version.dll' [rcNtRedir=0xc0150008]
1987e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000005ac pwszName=\Device\HarddiskVolume2\Windows\System32\version.dll
1988e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ca840
1989e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
1990e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=A3AB94A028D0330A3DBCAE54C04C648532198DB9
1991e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\version.dll'
1992e18.c94: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1993e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
1994e18.c94: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\version.dll) WinVerifyTrust
1995e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\version.dll
1996e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1997e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1998e18.c94: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
1999e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files (x86)\TeamViewer\tv_x64.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000008155b0:C:\Program Files (x86)\TeamViewer;C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2000e18.c94: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files (x86)\TeamViewer\tv_x64.dll
2001e18.c94: supR3HardenedDllNotificationCallback: load 000007fef6bf0000 LB 0x00048000 C:\Program Files (x86)\TeamViewer\tv_x64.dll [fFlags=0x0]
2002e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files (x86)\TeamViewer\tv_x64.dll
2003e18.c94: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\version.dll
2004e18.c94: supR3HardenedDllNotificationCallback: load 000007fefc1a0000 LB 0x0000c000 C:\Windows\system32\VERSION.dll [fFlags=0x0]
2005e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\version.dll
2006e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef6bf0000 'C:\Program Files (x86)\TeamViewer\tv_x64.dll'
2007e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdb60000 'C:\Windows\system32\advapi32.dll'
2008e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dwmapi.dll
2009e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\dwmapi.dll (Input=dwmapi.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007f35e0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2010e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefadb0000 'C:\Windows\system32\dwmapi.dll'
2011e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cryptbase.dll
2012e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTBASE.dll (Input=CRYPTBASE.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007f35e0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2013e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcf50000 'C:\Windows\system32\CRYPTBASE.dll'
2014e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
2015e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007f35e0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2016e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdce0000 'C:\Windows\system32\shell32.dll'
2017e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll
2018e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007f35e0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2019e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00000000771e0000 'C:\Windows\system32\kernel32.dll'
2020e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
2021e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007f35e0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2022e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefb4b0000 'C:\Windows\system32\uxtheme.dll'
2023e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
2024e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007f35e0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2025e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefb4b0000 'C:\Windows\system32\uxtheme.dll'
2026e18.c94: supR3HardenedMonitor_LdrLoadDll: error opening 'C:\Windows\system32\wintab32.dll': 0 (NtPath=\??\C:\Windows\system32\wintab32.dll; Input=C:\Windows\system32\wintab32.dll; rcNtGetDll=0x0
2027e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wintab32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007f35e0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2028e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000135 'C:\Windows\system32\wintab32.dll'
2029e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00000000770e0000 'C:\Windows\system32\user32.dll'
2030e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
2031e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007f35e0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2032e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefb4b0000 'C:\Windows\system32\uxtheme.dll'
2033e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00000000770e0000 'C:\Windows\system32\user32.dll'
2034e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdb60000 'C:\Windows\system32\advapi32.dll'
2035e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\userenv.dll
2036e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\userenv.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007f35e0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2037e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd290000 'C:\Windows\system32\userenv.dll'
2038e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll
2039e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007f35e0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2040e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00000000771e0000 'C:\Windows\system32\kernel32.dll'
2041e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000624 pwszName=\Device\HarddiskVolume2\Windows\System32\clbcatq.dll
2042e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ca840
2043e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
2044e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B01469787CE9D8C6FEE98FB207652B88B8494526
2045e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\clbcatq.dll'
2046e18.c94: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2047e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
2048e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'ole32.dll'.
2049e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
2050e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
2051e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
2052e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'rpcrt4.dll'.
2053e18.c94: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\clbcatq.dll) WinVerifyTrust
2054e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\clbcatq.dll
2055e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
2056e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
2057e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
2058e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
2059e18.c94: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
2060e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
2061e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
2062e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
2063e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
2064e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
2065e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
2066e18.c94: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
2067e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
2068e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
2069e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CLBCatQ.DLL (Input=CLBCatQ.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007f35e0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2070e18.c94: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\clbcatq.dll
2071e18.c94: supR3HardenedDllNotificationCallback: load 000007fefd790000 LB 0x00099000 C:\Windows\system32\CLBCatQ.DLL [fFlags=0x0]
2072e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\clbcatq.dll
2073e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd790000 'C:\Windows\system32\CLBCatQ.DLL'
2074e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
2075e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ADVAPI32.dll (Input=ADVAPI32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007f3820:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2076e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdb60000 'C:\Windows\system32\ADVAPI32.dll'
2077e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cryptsp.dll
2078e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTSP.dll (Input=CRYPTSP.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007f3550:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2079e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc8f0000 'C:\Windows\system32\CRYPTSP.dll'
2080e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000644 pwszName=\Device\HarddiskVolume2\Windows\System32\RpcRtRemote.dll
2081e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ca840
2082e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
2083e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=DFC4A7C7E103D324218E6EF5D219B953746D6EC1
2084e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\RpcRtRemote.dll'
2085e18.c94: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2086e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'rpcrt4.dll'.
2087e18.c94: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\RpcRtRemote.dll) WinVerifyTrust
2088e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\RpcRtRemote.dll
2089e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
2090e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
2091e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\RpcRtRemote.dll (Input=RpcRtRemote.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007f3550:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2092e18.c94: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\RpcRtRemote.dll
2093e18.c94: supR3HardenedDllNotificationCallback: load 000007fefd000000 LB 0x00014000 C:\Windows\system32\RpcRtRemote.dll [fFlags=0x0]
2094e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\RpcRtRemote.dll
2095e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd000000 'C:\Windows\system32\RpcRtRemote.dll'
2096e18.e5c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
2097e18.e5c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
2098e18.e5c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'psapi.dll'.
2099e18.e5c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vboxrt.dll'.
2100e18.e5c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'advapi32.dll'.
2101e18.e5c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'version.dll'.
2102e18.e5c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'ws2_32.dll'.
2103e18.e5c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'ole32.dll'.
2104e18.e5c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'oleaut32.dll'.
2105e18.e5c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxC.dll) WinVerifyTrust
2106e18.e5c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxC.dll
2107e18.e5c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
2108e18.e5c: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
2109e18.e5c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
2110e18.e5c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
2111e18.e5c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
2112e18.e5c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
2113e18.e5c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
2114e18.e5c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
2115e18.e5c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
2116e18.e5c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'version.dll'...
2117e18.e5c: supR3HardenedWinVerifyCacheProcessImportTodos: 'version.dll' -> '\Device\HarddiskVolume2\Windows\System32\version.dll' [rcNtRedir=0xc0150008]
2118e18.e5c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\version.dll
2119e18.e5c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
2120e18.e5c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
2121e18.e5c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
2122e18.e5c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
2123e18.e5c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'psapi.dll'...
2124e18.e5c: supR3HardenedWinVerifyCacheProcessImportTodos: 'psapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\psapi.dll' [rcNtRedir=0xc0150008]
2125e18.e5c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000684 pwszName=\Device\HarddiskVolume2\Windows\System32\psapi.dll
2126e18.e5c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ca840
2127e18.e5c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
2128e18.e5c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=561BAAB249C395B66D294444DF251EDB701DB607
2129e18.e5c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\psapi.dll'
2130e18.e5c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2131e18.e5c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\psapi.dll) WinVerifyTrust
2132e18.e5c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\psapi.dll
2133e18.e5c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
2134e18.e5c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
2135e18.e5c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
2136e18.e5c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
2137e18.e5c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
2138e18.e5c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxC.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000008158f0:C:\Program Files\Oracle\VirtualBox;C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2139e18.e5c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxC.dll
2140e18.e5c: supR3HardenedDllNotificationCallback: load 000007feef680000 LB 0x005d7000 C:\Program Files\Oracle\VirtualBox\VBoxC.dll [fFlags=0x0]
2141e18.e5c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxC.dll
2142e18.e5c: supR3HardenedDllNotificationCallback: load 00000000774d0000 LB 0x00007000 C:\Windows\system32\PSAPI.DLL [fFlags=0x0]
2143e18.e5c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\psapi.dll
2144e18.e5c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feef680000 'C:\Program Files\Oracle\VirtualBox\VBoxC.dll'
2145e18.e5c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
2146e18.e5c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\oleaut32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000003daea0:C:\Windows\system32;C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2147e18.e5c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefeea0000 'C:\Windows\system32\oleaut32.dll'
2148e18.e5c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000006a8 pwszName=\Device\HarddiskVolume2\Windows\System32\sxs.dll
2149e18.e5c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ca840
2150e18.e5c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
2151e18.e5c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=FCAC019C19F878C2B628662A84ECE75A01818BC9
2152e18.e5c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\sxs.dll'
2153e18.e5c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2154e18.e5c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\sxs.dll) WinVerifyTrust
2155e18.e5c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\sxs.dll
2156e18.e5c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\SXS.DLL (Input=SXS.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007f3d30:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2157e18.e5c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\sxs.dll
2158e18.e5c: supR3HardenedDllNotificationCallback: load 000007fefcf60000 LB 0x00091000 C:\Windows\system32\SXS.DLL [fFlags=0x0]
2159e18.e5c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\sxs.dll
2160e18.e5c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcf60000 'C:\Windows\system32\SXS.DLL'
2161e18.e5c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdb60000 'C:\Windows\system32\ADVAPI32.dll'
2162e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
2163e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\OLEAUT32.dll (Input=OLEAUT32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007f4000:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2164e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefeea0000 'C:\Windows\system32\OLEAUT32.dll'
2165e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdb60000 'C:\Windows\system32\ADVAPI32.dll'
2166e18.c94: supR3HardenedMonitor_LdrLoadDll: error opening 'C:\Windows\system32\wintab32.dll': 0 (NtPath=\??\C:\Windows\system32\wintab32.dll; Input=C:\Windows\system32\wintab32.dll; rcNtGetDll=0x0
2167e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wintab32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000032b3d20:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2168e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000135 'C:\Windows\system32\wintab32.dll'
2169e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefee30000 'C:\Windows\system32\gdi32.dll'
2170e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll
2171e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\user32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007f3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2172e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00000000770e0000 'C:\Windows\system32\user32.dll'
2173e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
2174e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007f3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2175e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdce0000 'C:\Windows\system32\shell32.dll'
2176e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'vboxoglhostcrutil.dll'.
2177e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
2178e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcr100.dll'.
2179e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qtcorevbox4.dll'.
2180e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qtguivbox4.dll'.
2181e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'qtopenglvbox4.dll'.
2182e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'opengl32.dll'.
2183e18.c94: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxTestOGL.exe)
2184e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxTestOGL.exe
2185e18.c94: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxTestOGL.exe'
2186e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000a98 pwszName=\Device\HarddiskVolume2\Windows\System32\apphelp.dll
2187e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ca840
2188e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
2189e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=8FFB8CDACDC5C9C6D9256E97FB0710E2753FFAA1
2190e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3045645~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\Windows\System32\apphelp.dll'
2191e18.c94: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2192e18.c94: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\apphelp.dll) WinVerifyTrust
2193e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\apphelp.dll
2194e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
2195e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
2196e18.c94: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
2197e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtopenglvbox4.dll'...
2198e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtopenglvbox4.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qtopenglvbox4.dll' [rcNtRedir=0xc0150008]
2199e18.c94: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll
2200e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtguivbox4.dll'...
2201e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtguivbox4.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qtguivbox4.dll' [rcNtRedir=0xc0150008]
2202e18.c94: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll
2203e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtcorevbox4.dll'...
2204e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtcorevbox4.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qtcorevbox4.dll' [rcNtRedir=0xc0150008]
2205e18.c94: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll
2206e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
2207e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
2208e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
2209e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
2210e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxoglhostcrutil.dll'...
2211e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxoglhostcrutil.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxoglhostcrutil.dll' [rcNtRedir=0xc0150008]
2212e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
2213e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
2214e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'shlwapi.dll'.
2215e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ws2_32.dll'.
2216e18.c94: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLhostcrutil.dll) WinVerifyTrust
2217e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLhostcrutil.dll
2218e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
2219e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
2220e18.c94: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
2221e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
2222e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
2223e18.c94: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll
2224e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
2225e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
2226e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
2227e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
2228e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\apphelp.dll (rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
2229e18.c94: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\apphelp.dll
2230e18.c94: supR3HardenedDllNotificationCallback: load 000007fefcef0000 LB 0x00057000 C:\Windows\system32\apphelp.dll [fFlags=0x0]
2231e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\apphelp.dll
2232e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcef0000 'C:\Windows\system32\apphelp.dll'
2233e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
2234e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ole32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007f3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2235e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefea90000 'C:\Windows\system32\ole32.dll'
2236e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
2237e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007f3dc0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2238e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdce0000 'C:\Windows\system32\shell32.dll'
2239e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
2240e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007f3dc0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2241e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdce0000 'C:\Windows\system32\shell32.dll'
2242e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefea90000 'C:\Windows\system32\ole32.dll'
2243e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
2244e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\OLEAUT32.dll (Input=OLEAUT32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007f3dc0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2245e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefeea0000 'C:\Windows\system32\OLEAUT32.dll'
2246e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000af0 pwszName=\Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll
2247e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ca840
2248e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
2249e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=41D7AA7A9ECA84ABF6801478BA3134174B21C472
2250e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll'
2251e18.c94: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2252e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
2253e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'wbemcomn.dll'.
2254e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
2255e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
2256e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ole32.dll'.
2257e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'ws2_32.dll'.
2258e18.c94: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll) WinVerifyTrust
2259e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll
2260e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
2261e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
2262e18.c94: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
2263e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
2264e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
2265e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
2266e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
2267e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
2268e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
2269e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wbemcomn.dll'...
2270e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'wbemcomn.dll' -> '\Device\HarddiskVolume2\Windows\System32\wbemcomn.dll' [rcNtRedir=0xc0150008]
2271e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000af8 pwszName=\Device\HarddiskVolume2\Windows\System32\wbemcomn.dll
2272e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ca840
2273e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
2274e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=03D0A77E5195AA70198FDE6C2FAC2C76FF200674
2275e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\wbemcomn.dll'
2276e18.c94: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2277e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
2278e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'oleaut32.dll'.
2279e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'ole32.dll'.
2280e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
2281e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ws2_32.dll'.
2282e18.c94: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\wbemcomn.dll) WinVerifyTrust
2283e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wbemcomn.dll
2284e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
2285e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
2286e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
2287e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
2288e18.c94: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
2289e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
2290e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
2291e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
2292e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
2293e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
2294e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
2295e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
2296e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
2297e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wbem\wbemprox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000032917f0:C:\Windows\system32\wbem;C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2298e18.c94: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll
2299e18.c94: supR3HardenedDllNotificationCallback: load 000007fef8fd0000 LB 0x0000f000 C:\Windows\system32\wbem\wbemprox.dll [fFlags=0x0]
2300e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll
2301e18.c94: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbemcomn.dll
2302e18.c94: supR3HardenedDllNotificationCallback: load 000007fef9400000 LB 0x00086000 C:\Windows\system32\wbemcomn.dll [fFlags=0x0]
2303e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbemcomn.dll
2304e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef8fd0000 'C:\Windows\system32\wbem\wbemprox.dll'
2305e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000b28 pwszName=\Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll
2306e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ca840
2307e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
2308e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=83AB88529BF28CFF670EA617E0B9C376CFE28B0F
2309e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll'
2310e18.c94: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2311e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
2312e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'rpcrt4.dll'.
2313e18.c94: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll) WinVerifyTrust
2314e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll
2315e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
2316e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
2317e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
2318e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
2319e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wbem\wbemsvc.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000032917f0:C:\Windows\system32\wbem;C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2320e18.c94: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll
2321e18.c94: supR3HardenedDllNotificationCallback: load 000007fef8c90000 LB 0x00014000 C:\Windows\system32\wbem\wbemsvc.dll [fFlags=0x0]
2322e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll
2323e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef8c90000 'C:\Windows\system32\wbem\wbemsvc.dll'
2324e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000b2c pwszName=\Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll
2325e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ca840
2326e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
2327e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=391AD7580DBA8EA6A4190F5A010E834B8C320D79
2328e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll'
2329e18.c94: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2330e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
2331e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'wbemcomn.dll'.
2332e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
2333e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'oleaut32.dll'.
2334e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ole32.dll'.
2335e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ntdsapi.dll'.
2336e18.c94: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll) WinVerifyTrust
2337e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll
2338e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntdsapi.dll'...
2339e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntdsapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\ntdsapi.dll' [rcNtRedir=0xc0150008]
2340e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000b0c pwszName=\Device\HarddiskVolume2\Windows\System32\ntdsapi.dll
2341e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ca840
2342e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
2343e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=67C74E045820FCAB3FC8AD5C180928A20C1F11CE
2344e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\ntdsapi.dll'
2345e18.c94: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2346e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
2347e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'rpcrt4.dll'.
2348e18.c94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'ws2_32.dll'.
2349e18.c94: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ntdsapi.dll) WinVerifyTrust
2350e18.c94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ntdsapi.dll
2351e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
2352e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
2353e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
2354e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
2355e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
2356e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
2357e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wbemcomn.dll'...
2358e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'wbemcomn.dll' -> '\Device\HarddiskVolume2\Windows\System32\wbemcomn.dll' [rcNtRedir=0xc0150008]
2359e18.c94: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbemcomn.dll
2360e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
2361e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
2362e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
2363e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
2364e18.c94: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
2365e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
2366e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
2367e18.c94: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
2368e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
2369e18.c94: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
2370e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wbem\fastprox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000032917f0:C:\Windows\system32\wbem;C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2371e18.c94: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll
2372e18.c94: supR3HardenedDllNotificationCallback: load 000007fef9050000 LB 0x000e2000 C:\Windows\system32\wbem\fastprox.dll [fFlags=0x0]
2373e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll
2374e18.c94: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ntdsapi.dll
2375e18.c94: supR3HardenedDllNotificationCallback: load 000007fef9380000 LB 0x00027000 C:\Windows\system32\NTDSAPI.dll [fFlags=0x0]
2376e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ntdsapi.dll
2377e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef9050000 'C:\Windows\system32\wbem\fastprox.dll'
2378e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefeea0000 'C:\Windows\system32\OLEAUT32.dll'
2379e18.c94: supR3HardenedMonitor_LdrLoadDll: 'C:\Windows\system32\comctl32.dll' -> 'C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll' [redir]
2380e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll [redoing WinVerifyTrust]
2381e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000500 pwszName=\Device\HarddiskVolume2\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll
2382e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ca840
2383e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
2384e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=761964761EE466757E306124E042F4C2ACBEA092
2385e18.c94: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3059317~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll'
2386e18.c94: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2387e18.c94: supR3HardenedScreenImage/LdrLoadDll: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll'
2388e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll (Input=C:\Windows\system32\comctl32.dll, rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000004a17fc0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2389e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef7dd0000 'C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll'
2390e18.5f4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
2391e18.5f4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrem.dll'.
2392e18.5f4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
2393e18.5f4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll) WinVerifyTrust
2394e18.5f4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
2395e18.5f4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
2396e18.5f4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
2397e18.5f4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrem.dll'...
2398e18.5f4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrem.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrem.dll' [rcNtRedir=0xc0150008]
2399e18.c94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
2400e18.c94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\WINMM.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000004a17b40:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2401e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefaea0000 'C:\Windows\system32\WINMM.dll'
2402e18.5f4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'vboxrt.dll'.
2403e18.5f4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
2404e18.5f4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcrt.dll'.
2405e18.5f4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxREM.dll) WinVerifyTrust
2406e18.5f4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxREM.dll
2407e18.5f4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
2408e18.5f4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
2409e18.5f4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
2410e18.5f4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
2411e18.5f4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
2412e18.5f4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
2413e18.5f4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
2414e18.5f4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
2415e18.5f4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
2416e18.5f4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000004a17ab0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2417e18.5f4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
2418e18.5f4: supR3HardenedDllNotificationCallback: load 000007feede80000 LB 0x00293000 C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL [fFlags=0x0]
2419e18.5f4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
2420e18.5f4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxREM.dll
2421e18.5f4: supR3HardenedDllNotificationCallback: load 0000000074410000 LB 0x0010a000 C:\Program Files\Oracle\VirtualBox\VBoxREM.dll [fFlags=0x0]
2422e18.5f4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxREM.dll
2423e18.5f4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feede80000 'C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL'
2424e18.ef4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
2425e18.ef4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\drivers\VBoxUSBMon.sys)
2426e18.ef4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\drivers\VBoxUSBMon.sys
2427e18.ef4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\drivers\VBoxUSBMon.sys [avoiding WinVerifyTrust]
2428e18.ef4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
2429e18.ef4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\drivers\VBoxDrv.sys)
2430e18.ef4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\drivers\VBoxDrv.sys
2431e18.ef4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\drivers\VBoxDrv.sys [avoiding WinVerifyTrust]
2432e18.ef4: \Device\HarddiskVolume2\Windows\System32\drivers\VBoxNetAdp6.sys: Owner is administrators group.
2433e18.ef4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ndis.sys'.
2434e18.ef4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'ntoskrnl.exe'.
2435e18.ef4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\drivers\VBoxNetAdp6.sys)
2436e18.ef4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\drivers\VBoxNetAdp6.sys
2437e18.ef4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\drivers\VBoxNetAdp6.sys [avoiding WinVerifyTrust]
2438e18.ef4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
2439e18.ef4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'ndis.sys'.
2440e18.ef4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'netio.sys'.
2441e18.ef4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\drivers\VBoxNetLwf.sys)
2442e18.ef4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\drivers\VBoxNetLwf.sys
2443e18.ef4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\drivers\VBoxNetLwf.sys [avoiding WinVerifyTrust]
2444e18.42c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\drivers\VBoxNetLwf.sys'
2445e18.42c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\drivers\VBoxNetAdp6.sys'
2446e18.42c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\drivers\VBoxDrv.sys'
2447e18.42c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\drivers\VBoxUSBMon.sys'
2448e18.42c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
2449e18.42c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
2450e18.42c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
2451e18.42c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
2452e18.42c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll) WinVerifyTrust
2453e18.42c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll
2454e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
2455e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
2456e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
2457e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
2458e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
2459e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
2460e18.42c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
2461e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
2462e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
2463e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'netio.sys'...
2464e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: 'netio.sys' -> '\Device\HarddiskVolume2\Windows\System32\drivers\netio.sys' [rcNtRedir=0xc0150008]
2465e18.42c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
2466e18.42c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'ndis.sys'.
2467e18.42c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msrpc.sys'.
2468e18.42c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\drivers\netio.sys) WinVerifyTrust
2469e18.42c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\drivers\netio.sys
2470e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ndis.sys'...
2471e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ndis.sys' -> '\Device\HarddiskVolume2\Windows\System32\drivers\ndis.sys' [rcNtRedir=0xc0150008]
2472e18.42c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
2473e18.42c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'hal.dll'.
2474e18.42c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'netio.sys'.
2475e18.42c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\drivers\ndis.sys) WinVerifyTrust
2476e18.42c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\drivers\ndis.sys
2477e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
2478e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume2\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
2479e18.42c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'pshed.dll'.
2480e18.42c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'hal.dll'.
2481e18.42c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'kdcom.dll'.
2482e18.42c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'clfs.sys'.
2483e18.42c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ci.dll'.
2484e18.42c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ntoskrnl.exe) WinVerifyTrust
2485e18.42c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ntoskrnl.exe
2486e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
2487e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume2\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
2488e18.42c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ntoskrnl.exe
2489e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ndis.sys'...
2490e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ndis.sys' -> '\Device\HarddiskVolume2\Windows\System32\drivers\ndis.sys' [rcNtRedir=0xc0150008]
2491e18.42c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\drivers\ndis.sys
2492e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
2493e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume2\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
2494e18.42c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ntoskrnl.exe
2495e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
2496e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume2\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
2497e18.42c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ntoskrnl.exe
2498e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ci.dll'...
2499e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ci.dll' -> '\Device\HarddiskVolume2\Windows\System32\ci.dll' [rcNtRedir=0xc0150008]
2500e18.42c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
2501e18.42c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ci.dll) WinVerifyTrust
2502e18.42c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ci.dll
2503e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'clfs.sys'...
2504e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: 'clfs.sys' -> '\Device\HarddiskVolume2\Windows\System32\clfs.sys' [rcNtRedir=0xc0150008]
2505e18.42c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
2506e18.42c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\clfs.sys) WinVerifyTrust
2507e18.42c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\clfs.sys
2508e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'kdcom.dll'...
2509e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: 'kdcom.dll' -> '\Device\HarddiskVolume2\Windows\System32\kdcom.dll' [rcNtRedir=0xc0150008]
2510e18.42c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
2511e18.42c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'hal.dll'.
2512e18.42c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\kdcom.dll) WinVerifyTrust
2513e18.42c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\kdcom.dll
2514e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'hal.dll'...
2515e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: 'hal.dll' -> '\Device\HarddiskVolume2\Windows\System32\hal.dll' [rcNtRedir=0xc0150008]
2516e18.42c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
2517e18.42c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'kdcom.dll'.
2518e18.42c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'pshed.dll'.
2519e18.42c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\hal.dll) WinVerifyTrust
2520e18.42c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\hal.dll
2521e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'pshed.dll'...
2522e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: 'pshed.dll' -> '\Device\HarddiskVolume2\Windows\System32\pshed.dll' [rcNtRedir=0xc0150008]
2523e18.42c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
2524e18.42c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'hal.dll'.
2525e18.42c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\PSHED.DLL) WinVerifyTrust
2526e18.42c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\PSHED.DLL
2527e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'netio.sys'...
2528e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: 'netio.sys' -> '\Device\HarddiskVolume2\Windows\System32\drivers\netio.sys' [rcNtRedir=0xc0150008]
2529e18.42c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\drivers\netio.sys
2530e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'hal.dll'...
2531e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: 'hal.dll' -> '\Device\HarddiskVolume2\Windows\System32\hal.dll' [rcNtRedir=0xc0150008]
2532e18.42c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\hal.dll
2533e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
2534e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume2\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
2535e18.42c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ntoskrnl.exe
2536e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msrpc.sys'...
2537e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msrpc.sys' -> '\Device\HarddiskVolume2\Windows\System32\drivers\msrpc.sys' [rcNtRedir=0xc0150008]
2538e18.42c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
2539e18.42c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\drivers\msrpc.sys) WinVerifyTrust
2540e18.42c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\drivers\msrpc.sys
2541e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ndis.sys'...
2542e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ndis.sys' -> '\Device\HarddiskVolume2\Windows\System32\drivers\ndis.sys' [rcNtRedir=0xc0150008]
2543e18.42c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\drivers\ndis.sys
2544e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
2545e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume2\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
2546e18.42c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ntoskrnl.exe
2547e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
2548e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume2\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
2549e18.42c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ntoskrnl.exe
2550e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'hal.dll'...
2551e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: 'hal.dll' -> '\Device\HarddiskVolume2\Windows\System32\hal.dll' [rcNtRedir=0xc0150008]
2552e18.42c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\hal.dll
2553e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
2554e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume2\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
2555e18.42c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ntoskrnl.exe
2556e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'pshed.dll'...
2557e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: 'pshed.dll' -> '\Device\HarddiskVolume2\Windows\System32\pshed.dll' [rcNtRedir=0xc0150008]
2558e18.42c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\PSHED.DLL
2559e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'kdcom.dll'...
2560e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: 'kdcom.dll' -> '\Device\HarddiskVolume2\Windows\System32\kdcom.dll' [rcNtRedir=0xc0150008]
2561e18.42c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\kdcom.dll
2562e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
2563e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume2\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
2564e18.42c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ntoskrnl.exe
2565e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'hal.dll'...
2566e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: 'hal.dll' -> '\Device\HarddiskVolume2\Windows\System32\hal.dll' [rcNtRedir=0xc0150008]
2567e18.42c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\hal.dll
2568e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
2569e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume2\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
2570e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
2571e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume2\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
2572e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
2573e18.42c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume2\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
2574e18.42c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000004a17ab0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2575e18.42c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll
2576e18.42c: supR3HardenedDllNotificationCallback: load 000007fef9640000 LB 0x0000a000 C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL [fFlags=0x0]
2577e18.42c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll
2578e18.42c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef9640000 'C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL'
2579e18.278: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
2580e18.278: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
2581e18.278: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
2582e18.278: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll) WinVerifyTrust
2583e18.278: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll
2584e18.278: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
2585e18.278: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
2586e18.278: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
2587e18.278: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
2588e18.278: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
2589e18.278: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
2590e18.278: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
2591e18.278: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000004a17ab0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2592e18.278: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll
2593e18.278: supR3HardenedDllNotificationCallback: load 000007fef9320000 LB 0x0000d000 C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL [fFlags=0x0]
2594e18.278: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll
2595e18.278: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef9320000 'C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL'
2596e18.ef4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxTestOGL.exe
2597e18.5bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
2598e18.5bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxoglhostcrutil.dll'.
2599e18.5bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
2600e18.5bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vboxvmm.dll'.
2601e18.5bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'vboxoglrenderspu.dll'.
2602e18.5bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'advapi32.dll'.
2603e18.5bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'ole32.dll'.
2604e18.5bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'oleaut32.dll'.
2605e18.5bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedCrOpenGL.dll) WinVerifyTrust
2606e18.5bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedCrOpenGL.dll
2607e18.5bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
2608e18.5bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
2609e18.5bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
2610e18.5bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
2611e18.5bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
2612e18.5bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
2613e18.5bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxoglrenderspu.dll'...
2614e18.5bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxoglrenderspu.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxoglrenderspu.dll' [rcNtRedir=0xc0150008]
2615e18.5bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
2616e18.5bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxoglhostcrutil.dll'.
2617e18.5bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
2618e18.5bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
2619e18.5bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
2620e18.5bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'advapi32.dll'.
2621e18.5bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLrenderspu.dll) WinVerifyTrust
2622e18.5bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLrenderspu.dll
2623e18.5bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
2624e18.5bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
2625e18.5bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
2626e18.5bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
2627e18.5bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
2628e18.5bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxoglhostcrutil.dll'...
2629e18.5bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxoglhostcrutil.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxoglhostcrutil.dll' [rcNtRedir=0xc0150008]
2630e18.5bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLhostcrutil.dll
2631e18.5bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
2632e18.5bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
2633e18.5bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
2634e18.5bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
2635e18.5bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
2636e18.5bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
2637e18.5bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
2638e18.5bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
2639e18.5bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
2640e18.5bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
2641e18.5bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxoglhostcrutil.dll'...
2642e18.5bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxoglhostcrutil.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxoglhostcrutil.dll' [rcNtRedir=0xc0150008]
2643e18.5bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLhostcrutil.dll
2644e18.5bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
2645e18.5bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
2646e18.5bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
2647e18.5bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSharedCrOpenGL.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000004a17ab0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2648e18.5bc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedCrOpenGL.dll
2649e18.5bc: supR3HardenedDllNotificationCallback: load 000007fef0bc0000 LB 0x0012c000 C:\Program Files\Oracle\VirtualBox\VBoxSharedCrOpenGL.DLL [fFlags=0x0]
2650e18.5bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedCrOpenGL.dll
2651e18.5bc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLhostcrutil.dll
2652e18.5bc: supR3HardenedDllNotificationCallback: load 000007fef6b70000 LB 0x00034000 C:\Program Files\Oracle\VirtualBox\VBoxOGLhostcrutil.dll [fFlags=0x0]
2653e18.5bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLhostcrutil.dll
2654e18.5bc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLrenderspu.dll
2655e18.5bc: supR3HardenedDllNotificationCallback: load 000007fef6bc0000 LB 0x00028000 C:\Program Files\Oracle\VirtualBox\VBoxOGLrenderspu.dll [fFlags=0x0]
2656e18.5bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLrenderspu.dll
2657e18.5bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef0bc0000 'C:\Program Files\Oracle\VirtualBox\VBoxSharedCrOpenGL.DLL'
2658e18.5bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLrenderspu.dll
2659e18.5bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxOGLrenderspu.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000004a17ab0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2660e18.5bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef6bc0000 'C:\Program Files\Oracle\VirtualBox\VBoxOGLrenderspu.dll'
2661e18.5bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
2662e18.5bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxoglhostcrutil.dll'.
2663e18.5bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLhosterrorspu.dll) WinVerifyTrust
2664e18.5bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLhosterrorspu.dll
2665e18.5bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxoglhostcrutil.dll'...
2666e18.5bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxoglhostcrutil.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxoglhostcrutil.dll' [rcNtRedir=0xc0150008]
2667e18.5bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLhostcrutil.dll
2668e18.5bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
2669e18.5bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
2670e18.5bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxOGLhosterrorspu.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000004a17ab0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2671e18.5bc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLhosterrorspu.dll
2672e18.5bc: supR3HardenedDllNotificationCallback: load 000007fef8a60000 LB 0x0001a000 C:\Program Files\Oracle\VirtualBox\VBoxOGLhosterrorspu.dll [fFlags=0x0]
2673e18.5bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLhosterrorspu.dll
2674e18.5bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef8a60000 'C:\Program Files\Oracle\VirtualBox\VBoxOGLhosterrorspu.dll'
2675e18.5bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
2676e18.5bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32/opengl32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000004a17ab0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2677e18.5bc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
2678e18.5bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef3870000 'C:\Windows\system32/opengl32.dll'
2679e18.5bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
2680e18.5bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\OPENGL32.dll (Input=OPENGL32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000004a17ab0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2681e18.5bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef3870000 'C:\Windows\system32\OPENGL32.dll'
2682e18.5bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefee30000 'C:\Windows\system32\gdi32.dll'
2683e18.5bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefee30000 'C:\Windows\system32\gdi32.dll'
2684e18.5bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef3870000 'C:\Windows\system32\OPENGL32.dll'
2685e18.5bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef3870000 'C:\Windows\system32\OPENGL32.dll'
2686e18.5bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef3870000 'C:\Windows\system32\OPENGL32.dll'
2687e18.5bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef3870000 'C:\Windows\system32\OPENGL32.dll'
2688e18.5bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef3870000 'C:\Windows\system32\OPENGL32.dll'
2689e18.5bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef3870000 'C:\Windows\system32\OPENGL32.dll'
2690e18.efc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
2691e18.efc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
2692e18.efc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
2693e18.efc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll) WinVerifyTrust
2694e18.efc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll
2695e18.efc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
2696e18.efc: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
2697e18.efc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
2698e18.efc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
2699e18.efc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
2700e18.efc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
2701e18.efc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
2702e18.efc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000004a17fc0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2703e18.efc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll
2704e18.efc: supR3HardenedDllNotificationCallback: load 000007fef8a50000 LB 0x0000f000 C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL [fFlags=0x0]
2705e18.efc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll
2706e18.efc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef8a50000 'C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL'
2707e18.7e4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
2708e18.7e4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
2709e18.7e4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
2710e18.7e4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll) WinVerifyTrust
2711e18.7e4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll
2712e18.7e4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
2713e18.7e4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
2714e18.7e4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
2715e18.7e4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
2716e18.7e4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
2717e18.7e4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
2718e18.7e4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000004a17fc0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2719e18.7e4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll
2720e18.7e4: supR3HardenedDllNotificationCallback: load 000007fef8500000 LB 0x0000e000 C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL [fFlags=0x0]
2721e18.7e4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll
2722e18.7e4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef8500000 'C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL'
2723e18.ef4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdce0000 'C:\Windows\system32/Shell32.dll'
2724e18.ef4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefea90000 'C:\Windows\system32\ole32.dll'
2725e18.ef4: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000004a17fc0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2726e18.ef4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefede0000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
2727e18.ef4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\profapi.dll
2728e18.ef4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\profapi.dll (Input=profapi.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000004a17fc0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2729e18.ef4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd0c0000 'C:\Windows\system32\profapi.dll'
2730e18.ef4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
2731e18.ef4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
2732e18.ef4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
2733e18.ef4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vboxddu.dll'.
2734e18.ef4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'vboxdd2.dll'.
2735e18.ef4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
2736e18.ef4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'setupapi.dll'.
2737e18.ef4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'ws2_32.dll'.
2738e18.ef4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'ole32.dll'.
2739e18.ef4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'iphlpapi.dll'.
2740e18.ef4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD.dll) WinVerifyTrust
2741e18.ef4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD.dll
2742e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'iphlpapi.dll'...
2743e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: 'iphlpapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\iphlpapi.dll' [rcNtRedir=0xc0150008]
2744e18.ef4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000e20 pwszName=\Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL
2745e18.ef4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ca840
2746e18.ef4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
2747e18.ef4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=3BDC72529DA09BA841BE702C4C902C8AA1242642
2748e18.ef4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL'
2749e18.ef4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2750e18.ef4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
2751e18.ef4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'nsi.dll'.
2752e18.ef4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'winnsi.dll'.
2753e18.ef4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'rpcrt4.dll'.
2754e18.ef4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL) WinVerifyTrust
2755e18.ef4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL
2756e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
2757e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
2758e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
2759e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
2760e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
2761e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
2762e18.ef4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\setupapi.dll
2763e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
2764e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
2765e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxdd2.dll'...
2766e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxdd2.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxdd2.dll' [rcNtRedir=0xc0150008]
2767e18.ef4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
2768e18.ef4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
2769e18.ef4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
2770e18.ef4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD2.dll) WinVerifyTrust
2771e18.ef4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD2.dll
2772e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxddu.dll'...
2773e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxddu.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxddu.dll' [rcNtRedir=0xc0150008]
2774e18.ef4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
2775e18.ef4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
2776e18.ef4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
2777e18.ef4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'setupapi.dll'.
2778e18.ef4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'newdev.dll'.
2779e18.ef4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'advapi32.dll'.
2780e18.ef4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDDU.dll) WinVerifyTrust
2781e18.ef4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDDU.dll
2782e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
2783e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
2784e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
2785e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
2786e18.ef4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
2787e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
2788e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
2789e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
2790e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
2791e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'newdev.dll'...
2792e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: 'newdev.dll' -> '\Device\HarddiskVolume2\Windows\System32\newdev.dll' [rcNtRedir=0xc0150008]
2793e18.ef4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000e30 pwszName=\Device\HarddiskVolume2\Windows\System32\newdev.dll
2794e18.ef4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ca840
2795e18.ef4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
2796e18.ef4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2F4B2CF91DA6B4233E3BF5D2EC9677240BFF983C
2797e18.ef4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntph.cat'; file='\Device\HarddiskVolume2\Windows\System32\newdev.dll'
2798e18.ef4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2799e18.ef4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
2800e18.ef4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
2801e18.ef4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
2802e18.ef4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
2803e18.ef4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'uxtheme.dll'.
2804e18.ef4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'cfgmgr32.dll'.
2805e18.ef4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'setupapi.dll'.
2806e18.ef4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\newdev.dll) WinVerifyTrust
2807e18.ef4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\newdev.dll
2808e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
2809e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
2810e18.ef4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\setupapi.dll
2811e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
2812e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
2813e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
2814e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
2815e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
2816e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
2817e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
2818e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
2819e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
2820e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
2821e18.ef4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
2822e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
2823e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
2824e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
2825e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
2826e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winnsi.dll'...
2827e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: 'winnsi.dll' -> '\Device\HarddiskVolume2\Windows\System32\winnsi.dll' [rcNtRedir=0xc0150008]
2828e18.ef4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000e14 pwszName=\Device\HarddiskVolume2\Windows\System32\winnsi.dll
2829e18.ef4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ca840
2830e18.ef4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
2831e18.ef4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B28F3E0DF5586B9FB3AEAC48E4ECCA0AFB6ABD91
2832e18.ef4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\winnsi.dll'
2833e18.ef4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2834e18.ef4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
2835e18.ef4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'rpcrt4.dll'.
2836e18.ef4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'nsi.dll'.
2837e18.ef4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\winnsi.dll) WinVerifyTrust
2838e18.ef4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\winnsi.dll
2839e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
2840e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume2\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
2841e18.ef4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\nsi.dll
2842e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
2843e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
2844e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
2845e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume2\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
2846e18.ef4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\nsi.dll
2847e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
2848e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
2849e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
2850e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
2851e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
2852e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
2853e18.ef4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\setupapi.dll
2854e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
2855e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
2856e18.ef4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll
2857e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'uxtheme.dll'...
2858e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: 'uxtheme.dll' -> '\Device\HarddiskVolume2\Windows\System32\uxtheme.dll' [rcNtRedir=0xc0150008]
2859e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
2860e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
2861e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
2862e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
2863e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
2864e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
2865e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
2866e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
2867e18.ef4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox/VBoxDD.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000004a17fc0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2868e18.ef4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD.dll
2869e18.ef4: supR3HardenedDllNotificationCallback: load 000007feed590000 LB 0x008e3000 C:\Program Files\Oracle\VirtualBox\VBoxDD.DLL [fFlags=0x0]
2870e18.ef4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD.dll
2871e18.ef4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDDU.dll
2872e18.ef4: supR3HardenedDllNotificationCallback: load 000007fef1970000 LB 0x00061000 C:\Program Files\Oracle\VirtualBox\VBoxDDU.dll [fFlags=0x0]
2873e18.ef4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDDU.dll
2874e18.ef4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\newdev.dll
2875e18.ef4: supR3HardenedDllNotificationCallback: load 000007fef7040000 LB 0x00051000 C:\Windows\system32\newdev.dll [fFlags=0x0]
2876e18.ef4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\newdev.dll
2877e18.ef4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
2878e18.ef4: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\devrtl.dll)
2879e18.ef4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\devrtl.dll
2880e18.ef4: supR3HardenedDllNotificationCallback: load 000007fefc380000 LB 0x00012000 C:\Windows\system32\devrtl.DLL [fFlags=0x0]
2881e18.ef4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\devrtl.dll [avoiding WinVerifyTrust]
2882e18.ef4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD2.dll
2883e18.ef4: supR3HardenedDllNotificationCallback: load 000007fef5a30000 LB 0x00035000 C:\Program Files\Oracle\VirtualBox\VBoxDD2.dll [fFlags=0x0]
2884e18.ef4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD2.dll
2885e18.ef4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL
2886e18.ef4: supR3HardenedDllNotificationCallback: load 000007fefab60000 LB 0x00027000 C:\Windows\system32\IPHLPAPI.DLL [fFlags=0x0]
2887e18.ef4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL
2888e18.ef4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winnsi.dll
2889e18.ef4: supR3HardenedDllNotificationCallback: load 000007fefab50000 LB 0x0000b000 C:\Windows\system32\WINNSI.DLL [fFlags=0x0]
2890e18.ef4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winnsi.dll
2891e18.ef4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed590000 'C:\Program Files\Oracle\VirtualBox/VBoxDD.DLL'
2892e18.ef4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000e28 pwszName=\Device\HarddiskVolume2\Windows\System32\devrtl.dll
2893e18.ef4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ca840
2894e18.ef4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ca840
2895e18.ef4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=445E5B0E9F43B5D56A5B9C4BC3369E3D076ACA1A
2896e18.ef4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\devrtl.dll'
2897e18.ef4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2898e18.ef4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\devrtl.dll'
2899e18.ef4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxC.dll
2900e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
2901e18.ef4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
2902e18.ef4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox/VBoxC.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000004a17fc0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2903e18.ef4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxC.dll
2904e18.ef4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feef680000 'C:\Program Files\Oracle\VirtualBox/VBoxC.DLL'
2905e18.ef4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD2.dll
2906e18.ef4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox/VBoxDD2.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000004a17fc0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2907e18.ef4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD2.dll
2908e18.ef4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef5a30000 'C:\Program Files\Oracle\VirtualBox/VBoxDD2.DLL'
2909e18.600: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
2910e18.600: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
2911e18.600: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
2912e18.600: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll) WinVerifyTrust
2913e18.600: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll
2914e18.600: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
2915e18.600: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
2916e18.600: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
2917e18.600: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
2918e18.600: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
2919e18.600: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
2920e18.600: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
2921e18.600: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000004a17fc0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2922e18.600: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll
2923e18.600: supR3HardenedDllNotificationCallback: load 000007fef84f0000 LB 0x0000d000 C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL [fFlags=0x0]
2924e18.600: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll
2925e18.600: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef84f0000 'C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL'
2926e18.ef4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll
2927e18.ef4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32/kernel32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000004a17fc0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2928e18.ef4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll
2929e18.ef4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00000000771e0000 'C:\Windows\system32/kernel32.dll'
2930e18.5f4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefeea0000 'C:\Windows\system32\OLEAUT32.dll'
2931e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdce0000 'C:\Windows\system32\shell32.dll'
2932e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdce0000 'C:\Windows\system32\shell32.dll'
2933e18.c94: supR3HardenedDllNotificationCallback: Unload 000007fef6bf0000 LB 0x00048000 C:\Program Files (x86)\TeamViewer\tv_x64.dll [flags=0x0]
2934e18.d00: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files (x86)\TeamViewer\tv_x64.dll
2935e18.d00: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files (x86)\TeamViewer\tv_x64.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003288420:C:\Program Files (x86)\TeamViewer;C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2936e18.d00: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files (x86)\TeamViewer\tv_x64.dll
2937e18.d00: supR3HardenedDllNotificationCallback: load 000007fef6bf0000 LB 0x00048000 C:\Program Files (x86)\TeamViewer\tv_x64.dll [fFlags=0x0]
2938e18.d00: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files (x86)\TeamViewer\tv_x64.dll
2939e18.d00: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef6bf0000 'C:\Program Files (x86)\TeamViewer\tv_x64.dll'
2940e18.d00: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdb60000 'C:\Windows\system32\advapi32.dll'
2941e18.758: supR3HardenedDllNotificationCallback: Unload 000007fef6bf0000 LB 0x00048000 C:\Program Files (x86)\TeamViewer\tv_x64.dll [flags=0x0]
2942e18.d00: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files (x86)\TeamViewer\tv_x64.dll
2943e18.d00: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files (x86)\TeamViewer\tv_x64.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000004a0eaf0:C:\Program Files (x86)\TeamViewer;C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2944e18.d00: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files (x86)\TeamViewer\tv_x64.dll
2945e18.d00: supR3HardenedDllNotificationCallback: load 000007fef6bf0000 LB 0x00048000 C:\Program Files (x86)\TeamViewer\tv_x64.dll [fFlags=0x0]
2946e18.d00: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files (x86)\TeamViewer\tv_x64.dll
2947e18.d00: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef6bf0000 'C:\Program Files (x86)\TeamViewer\tv_x64.dll'
2948e18.d00: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdb60000 'C:\Windows\system32\advapi32.dll'
2949e18.758: supR3HardenedDllNotificationCallback: Unload 000007fef6bf0000 LB 0x00048000 C:\Program Files (x86)\TeamViewer\tv_x64.dll [flags=0x0]
2950e18.d00: supR3HardenedDllNotificationCallback: load 000007fef6bf0000 LB 0x00048000 C:\Program Files (x86)\TeamViewer\tv_x64.dll [fFlags=0x0]
2951e18.d00: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef6bf0000 'C:\Program Files (x86)\TeamViewer\tv_x64.dll'
2952e18.d00: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdb60000 'C:\Windows\system32\advapi32.dll'
2953e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00000000770e0000 'C:\Windows\system32\user32.dll'
2954e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00000000770e0000 'C:\Windows\system32\user32.dll'
2955e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00000000770e0000 'C:\Windows\system32\user32.dll'
2956e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00000000770e0000 'C:\Windows\system32\user32.dll'
2957e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00000000770e0000 'C:\Windows\system32\user32.dll'
2958e18.c94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00000000770e0000 'C:\Windows\system32\user32.dll'
2959e18.758: supR3HardenedDllNotificationCallback: Unload 000007fef6bf0000 LB 0x00048000 C:\Program Files (x86)\TeamViewer\tv_x64.dll [flags=0x0]
2960e18.d00: supR3HardenedDllNotificationCallback: load 000007fef6bf0000 LB 0x00048000 C:\Program Files (x86)\TeamViewer\tv_x64.dll [fFlags=0x0]
2961e18.d00: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef6bf0000 'C:\Program Files (x86)\TeamViewer\tv_x64.dll'
2962e18.d00: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdb60000 'C:\Windows\system32\advapi32.dll'
2963e18.c94: supR3HardenedDllNotificationCallback: Unload 000007fef6bf0000 LB 0x00048000 C:\Program Files (x86)\TeamViewer\tv_x64.dll [flags=0x0]
2964e18.d00: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files (x86)\TeamViewer\tv_x64.dll
2965e18.d00: supR3HardenedDllNotificationCallback: load 000007fef6bf0000 LB 0x00048000 C:\Program Files (x86)\TeamViewer\tv_x64.dll [fFlags=0x0]
2966e18.d00: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef6bf0000 'C:\Program Files (x86)\TeamViewer\tv_x64.dll'
2967e18.d00: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdb60000 'C:\Windows\system32\advapi32.dll'
2968e18.758: supR3HardenedDllNotificationCallback: Unload 000007fef6bf0000 LB 0x00048000 C:\Program Files (x86)\TeamViewer\tv_x64.dll [flags=0x0]
2969e18.d00: supR3HardenedDllNotificationCallback: load 000007fef6bf0000 LB 0x00048000 C:\Program Files (x86)\TeamViewer\tv_x64.dll [fFlags=0x0]
2970e18.d00: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef6bf0000 'C:\Program Files (x86)\TeamViewer\tv_x64.dll'
2971e18.d00: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdb60000 'C:\Windows\system32\advapi32.dll'
2972e18.758: supR3HardenedDllNotificationCallback: Unload 000007fef6bf0000 LB 0x00048000 C:\Program Files (x86)\TeamViewer\tv_x64.dll [flags=0x0]
2973e18.d00: supR3HardenedDllNotificationCallback: load 000007fef6bf0000 LB 0x00048000 C:\Program Files (x86)\TeamViewer\tv_x64.dll [fFlags=0x0]
2974e18.d00: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef6bf0000 'C:\Program Files (x86)\TeamViewer\tv_x64.dll'
2975e18.d00: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
2976e18.d00: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\advapi32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000004a41960:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
2977e18.d00: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdb60000 'C:\Windows\system32\advapi32.dll'
2978e18.758: supR3HardenedDllNotificationCallback: Unload 000007fef6bf0000 LB 0x00048000 C:\Program Files (x86)\TeamViewer\tv_x64.dll [flags=0x0]
2979e18.d00: supR3HardenedDllNotificationCallback: load 000007fef6bf0000 LB 0x00048000 C:\Program Files (x86)\TeamViewer\tv_x64.dll [fFlags=0x0]
2980e18.d00: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef6bf0000 'C:\Program Files (x86)\TeamViewer\tv_x64.dll'
2981e18.d00: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdb60000 'C:\Windows\system32\advapi32.dll'

© 2024 Oracle Support Privacy / Do Not Sell My Info Terms of Use Trademark Policy Automated Access Etiquette