VirtualBox

Ticket #15017: VBoxHardening.log

File VBoxHardening.log, 459.8 KB (added by SuperDiver, 9 years ago)
Line 
113fc.f84: Log file opened: 5.0.12r104815 g_hStartupLog=00000010 g_uNtVerCombined=0x611db110
213fc.f84: \SystemRoot\System32\ntdll.dll:
313fc.f84: CreationTime: 2015-11-11T01:40:25.748046800Z
413fc.f84: LastWriteTime: 2015-10-20T00:48:47.299796500Z
513fc.f84: ChangeTime: 2015-11-11T01:51:39.761718700Z
613fc.f84: FileAttributes: 0x20
713fc.f84: Size: 0x13f600
813fc.f84: NT Headers: 0xd0
913fc.f84: Timestamp: 0x56258dbb
1013fc.f84: Machine: 0x14c - i386
1113fc.f84: Timestamp: 0x56258dbb
1213fc.f84: Image Version: 6.1
1313fc.f84: SizeOfImage: 0x141000 (1314816)
1413fc.f84: Resource Dir: 0xe1000 LB 0x5a028
1513fc.f84: ProductName: Microsoft® Windows® Operating System
1613fc.f84: ProductVersion: 6.1.7601.19045
1713fc.f84: FileVersion: 6.1.7601.19045 (win7sp1_gdr.151019-1254)
1813fc.f84: FileDescription: NT Layer DLL
1913fc.f84: \SystemRoot\System32\kernel32.dll:
2013fc.f84: CreationTime: 2015-06-10T01:18:16.643554600Z
2113fc.f84: LastWriteTime: 2015-05-09T03:13:42.222000000Z
2213fc.f84: ChangeTime: 2015-06-11T00:25:36.694335900Z
2313fc.f84: FileAttributes: 0x20
2413fc.f84: Size: 0xd4000
2513fc.f84: NT Headers: 0xf0
2613fc.f84: Timestamp: 0x554d7aff
2713fc.f84: Machine: 0x14c - i386
2813fc.f84: Timestamp: 0x554d7aff
2913fc.f84: Image Version: 6.1
3013fc.f84: SizeOfImage: 0xd4000 (868352)
3113fc.f84: Resource Dir: 0xc7000 LB 0x528
3213fc.f84: ProductName: Microsoft® Windows® Operating System
3313fc.f84: ProductVersion: 6.1.7601.18847
3413fc.f84: FileVersion: 6.1.7601.18847 (win7sp1_gdr.150508-1512)
3513fc.f84: FileDescription: Windows NT BASE API Client DLL
3613fc.f84: \SystemRoot\System32\KernelBase.dll:
3713fc.f84: CreationTime: 2015-06-10T01:18:16.706054600Z
3813fc.f84: LastWriteTime: 2015-05-09T03:13:42.222000000Z
3913fc.f84: ChangeTime: 2015-06-11T00:25:36.764648400Z
4013fc.f84: FileAttributes: 0x20
4113fc.f84: Size: 0x47a00
4213fc.f84: NT Headers: 0xe0
4313fc.f84: Timestamp: 0x554d7b00
4413fc.f84: Machine: 0x14c - i386
4513fc.f84: Timestamp: 0x554d7b00
4613fc.f84: Image Version: 6.1
4713fc.f84: SizeOfImage: 0x4b000 (307200)
4813fc.f84: Resource Dir: 0x47000 LB 0x530
4913fc.f84: ProductName: Microsoft® Windows® Operating System
5013fc.f84: ProductVersion: 6.1.7601.18847
5113fc.f84: FileVersion: 6.1.7601.18847 (win7sp1_gdr.150508-1512)
5213fc.f84: FileDescription: Windows NT BASE API Client DLL
5313fc.f84: \SystemRoot\System32\apisetschema.dll:
5413fc.f84: CreationTime: 2015-11-11T01:40:23.794921800Z
5513fc.f84: LastWriteTime: 2015-10-20T00:35:03.776000000Z
5613fc.f84: ChangeTime: 2015-11-11T01:51:45.983398400Z
5713fc.f84: FileAttributes: 0x20
5813fc.f84: Size: 0x1a00
5913fc.f84: NT Headers: 0xc0
6013fc.f84: Timestamp: 0x56258c72
6113fc.f84: Machine: 0x14c - i386
6213fc.f84: Timestamp: 0x56258c72
6313fc.f84: Image Version: 6.1
6413fc.f84: SizeOfImage: 0x50000 (327680)
6513fc.f84: Resource Dir: 0x30000 LB 0x3f8
6613fc.f84: ProductName: Microsoft® Windows® Operating System
6713fc.f84: ProductVersion: 6.1.7601.19045
6813fc.f84: FileVersion: 6.1.7601.19045 (win7sp1_gdr.151019-1254)
6913fc.f84: FileDescription: ApiSet Schema DLL
7013fc.f84: supR3HardenedWinFindAdversaries: 0x0
7113fc.f84: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume1\Program Files\VirtualBox'
7213fc.f84: Calling main()
7313fc.f84: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
7413fc.f84: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume1\Program Files\VirtualBox'
7513fc.f84: SUPR3HardenedMain: Respawn #1
7613fc.f84: System32: \Device\HarddiskVolume1\Windows\System32
7713fc.f84: WinSxS: \Device\HarddiskVolume1\Windows\winsxs
7813fc.f84: KnownDllPath: C:\Windows\system32
7913fc.f84: '\Device\HarddiskVolume1\Program Files\VirtualBox\VirtualBox.exe' has no imports
8013fc.f84: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\VirtualBox\VirtualBox.exe)
8113fc.f84: supR3HardNtEnableThreadCreation:
8213fc.f84: supR3HardNtDisableThreadCreation: pvLdrInitThunk=77dc3911 pvNtTerminateThread=77da69c0
8313fc.f84: supR3HardenedWinDoReSpawn(1): New child d64.1424 [kernel32].
8413fc.f84: supR3HardNtChildGatherData: PebBaseAddress=7ffd9000 cbPeb=0x248
8513fc.f84: supR3HardNtPuChFindNtdll: uNtDllParentAddr=77d60000 uNtDllChildAddr=77d60000
8613fc.f84: supR3HardenedWinSetupChildInit: uLdrInitThunk=77dc3911
8713fc.f84: supR3HardenedWinSetupChildInit: Start child.
8813fc.f84: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 31 ms.
8913fc.f84: supR3HardNtChildPurify: Startup delay kludge #1/0: 264 ms, 0 sleeps
9013fc.f84: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
9113fc.f84: *00000000-fffeffff 0x0001/0x0000 0x0000000
9213fc.f84: *00010000-fffeffff 0x0004/0x0004 0x0020000
9313fc.f84: *00030000-0002bfff 0x0002/0x0002 0x0040000
9413fc.f84: 00034000-00027fff 0x0001/0x0000 0x0000000
9513fc.f84: *00040000-0003efff 0x0004/0x0004 0x0020000
9613fc.f84: 00041000-00031fff 0x0001/0x0000 0x0000000
9713fc.f84: *00050000-0004efff 0x0004/0x0004 0x0020000
9813fc.f84: 00051000-fffa1fff 0x0001/0x0000 0x0000000
9913fc.f84: *00100000-00002fff 0x0000/0x0004 0x0020000
10013fc.f84: 001fd000-001fafff 0x0104/0x0004 0x0020000
10113fc.f84: 001ff000-001fdfff 0x0004/0x0004 0x0020000
10213fc.f84: 00200000-ff20ffff 0x0001/0x0000 0x0000000
10313fc.f84: *011f0000-011f0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\VirtualBox\VirtualBox.exe
10413fc.f84: 011f1000-01267fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\VirtualBox\VirtualBox.exe
10513fc.f84: 01268000-01268fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\VirtualBox\VirtualBox.exe
10613fc.f84: 01269000-012a2fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\VirtualBox\VirtualBox.exe
10713fc.f84: 012a3000-012a3fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\VirtualBox\VirtualBox.exe
10813fc.f84: 012a4000-012a4fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\VirtualBox\VirtualBox.exe
10913fc.f84: 012a5000-012a5fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\VirtualBox\VirtualBox.exe
11013fc.f84: 012a6000-012a6fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\VirtualBox\VirtualBox.exe
11113fc.f84: 012a7000-012abfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\VirtualBox\VirtualBox.exe
11213fc.f84: 012ac000-012aefff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\VirtualBox\VirtualBox.exe
11313fc.f84: 012af000-012f2fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\VirtualBox\VirtualBox.exe
11413fc.f84: 012f3000-8a885fff 0x0001/0x0000 0x0000000
11513fc.f84: *77d60000-77d60fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
11613fc.f84: 77d61000-77e37fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
11713fc.f84: 77e38000-77e3dfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
11813fc.f84: 77e3e000-77e3efff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
11913fc.f84: 77e3f000-77e40fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
12013fc.f84: 77e41000-77ea0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
12113fc.f84: 77ea1000-77d81fff 0x0001/0x0000 0x0000000
12213fc.f84: *77fc0000-77fc0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\apisetschema.dll
12313fc.f84: 77fc1000-6ffe1fff 0x0001/0x0000 0x0000000
12413fc.f84: *7ffa0000-7ff6cfff 0x0002/0x0002 0x0040000
12513fc.f84: 7ffd3000-7ffccfff 0x0001/0x0000 0x0000000
12613fc.f84: *7ffd9000-7ffd7fff 0x0004/0x0004 0x0020000
12713fc.f84: 7ffda000-7ffd4fff 0x0001/0x0000 0x0000000
12813fc.f84: *7ffdf000-7ffddfff 0x0004/0x0004 0x0020000
12913fc.f84: *7ffe0000-7ffdefff 0x0002/0x0002 0x0020000
13013fc.f84: 7ffe1000-7ffd1fff 0x0001/0x0002 0x0020000
13113fc.f84: apisetschema.dll: timestamp 0x56258c72 (rc=VINF_SUCCESS)
13213fc.f84: VirtualBox.exe: timestamp 0x56743212 (rc=VINF_SUCCESS)
13313fc.f84: '\Device\HarddiskVolume1\Program Files\VirtualBox\VirtualBox.exe' has no imports
13413fc.f84: '\Device\HarddiskVolume1\Windows\System32\apisetschema.dll' has no imports
13513fc.f84: '\Device\HarddiskVolume1\Windows\System32\ntdll.dll' has no imports
13613fc.f84: supR3HardNtChildPurify: Done after 308 ms and 0 fixes (loop #0).
137d64.1424: Log file opened: 5.0.12r104815 g_hStartupLog=00000004 g_uNtVerCombined=0x611db110
138d64.1424: supR3HardenedVmProcessInit: uNtDllAddr=77d60000
139d64.1424: ntdll.dll: timestamp 0x56258dbb (rc=VINF_SUCCESS)
140d64.1424: New simple heap: #1 00300000 LB 0x400000 (for 1314816 allocation)
141d64.1424: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume1\Program Files\VirtualBox'
142d64.1424: System32: \Device\HarddiskVolume1\Windows\System32
143d64.1424: WinSxS: \Device\HarddiskVolume1\Windows\winsxs
144d64.1424: KnownDllPath: C:\Windows\system32
145d64.1424: supR3HardenedVmProcessInit: Opening vboxdrv stub...
14613fc.f84: supR3HardNtEnableThreadCreation:
147d64.1424: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
148d64.1424: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
149d64.1424: Registered Dll notification callback with NTDLL.
150d64.1424: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\kernel32.dll)
151d64.1424: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\kernel32.dll
152d64.1424: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=00000000:<flags> [calling]
153d64.1424: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
154d64.1424: supR3HardenedDllNotificationCallback: load 77c80000 LB 0x000d4000 C:\Windows\system32\kernel32.dll [fFlags=0x0]
155d64.1424: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
156d64.1424: supR3HardenedDllNotificationCallback: load 75f80000 LB 0x0004b000 C:\Windows\system32\KERNELBASE.dll [fFlags=0x0]
157d64.1424: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\KernelBase.dll)
158d64.1424: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\KernelBase.dll
159d64.1424: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77c80000 'C:\Windows\system32\kernel32.dll'
160d64.1424: supR3HardNtDisableThreadCreation: pvLdrInitThunk=77dc3911 pvNtTerminateThread=77da69c0
161d64.1424: \SystemRoot\System32\ntdll.dll:
162d64.1424: CreationTime: 2015-11-11T01:40:25.748046800Z
163d64.1424: LastWriteTime: 2015-10-20T00:48:47.299796500Z
164d64.1424: ChangeTime: 2015-11-11T01:51:39.761718700Z
165d64.1424: FileAttributes: 0x20
166d64.1424: Size: 0x13f600
167d64.1424: NT Headers: 0xd0
168d64.1424: Timestamp: 0x56258dbb
169d64.1424: Machine: 0x14c - i386
170d64.1424: Timestamp: 0x56258dbb
171d64.1424: Image Version: 6.1
172d64.1424: SizeOfImage: 0x141000 (1314816)
173d64.1424: Resource Dir: 0xe1000 LB 0x5a028
174d64.1424: ProductName: Microsoft® Windows® Operating System
175d64.1424: ProductVersion: 6.1.7601.19045
176d64.1424: FileVersion: 6.1.7601.19045 (win7sp1_gdr.151019-1254)
177d64.1424: FileDescription: NT Layer DLL
17813fc.f84: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 40 ms.
179d64.1424: \SystemRoot\System32\kernel32.dll:
180d64.1424: CreationTime: 2015-06-10T01:18:16.643554600Z
181d64.1424: LastWriteTime: 2015-05-09T03:13:42.222000000Z
182d64.1424: ChangeTime: 2015-06-11T00:25:36.694335900Z
183d64.1424: FileAttributes: 0x20
184d64.1424: Size: 0xd4000
185d64.1424: NT Headers: 0xf0
186d64.1424: Timestamp: 0x554d7aff
187d64.1424: Machine: 0x14c - i386
188d64.1424: Timestamp: 0x554d7aff
189d64.1424: Image Version: 6.1
190d64.1424: SizeOfImage: 0xd4000 (868352)
191d64.1424: Resource Dir: 0xc7000 LB 0x528
192d64.1424: ProductName: Microsoft® Windows® Operating System
193d64.1424: ProductVersion: 6.1.7601.18847
194d64.1424: FileVersion: 6.1.7601.18847 (win7sp1_gdr.150508-1512)
195d64.1424: FileDescription: Windows NT BASE API Client DLL
196d64.1424: \SystemRoot\System32\KernelBase.dll:
197d64.1424: CreationTime: 2015-06-10T01:18:16.706054600Z
198d64.1424: LastWriteTime: 2015-05-09T03:13:42.222000000Z
199d64.1424: ChangeTime: 2015-06-11T00:25:36.764648400Z
200d64.1424: FileAttributes: 0x20
201d64.1424: Size: 0x47a00
202d64.1424: NT Headers: 0xe0
203d64.1424: Timestamp: 0x554d7b00
204d64.1424: Machine: 0x14c - i386
205d64.1424: Timestamp: 0x554d7b00
206d64.1424: Image Version: 6.1
207d64.1424: SizeOfImage: 0x4b000 (307200)
208d64.1424: Resource Dir: 0x47000 LB 0x530
209d64.1424: ProductName: Microsoft® Windows® Operating System
210d64.1424: ProductVersion: 6.1.7601.18847
211d64.1424: FileVersion: 6.1.7601.18847 (win7sp1_gdr.150508-1512)
212d64.1424: FileDescription: Windows NT BASE API Client DLL
213d64.1424: \SystemRoot\System32\apisetschema.dll:
214d64.1424: CreationTime: 2015-11-11T01:40:23.794921800Z
215d64.1424: LastWriteTime: 2015-10-20T00:35:03.776000000Z
216d64.1424: ChangeTime: 2015-11-11T01:51:45.983398400Z
217d64.1424: FileAttributes: 0x20
218d64.1424: Size: 0x1a00
219d64.1424: NT Headers: 0xc0
220d64.1424: Timestamp: 0x56258c72
221d64.1424: Machine: 0x14c - i386
222d64.1424: Timestamp: 0x56258c72
223d64.1424: Image Version: 6.1
224d64.1424: SizeOfImage: 0x50000 (327680)
225d64.1424: Resource Dir: 0x30000 LB 0x3f8
226d64.1424: ProductName: Microsoft® Windows® Operating System
227d64.1424: ProductVersion: 6.1.7601.19045
228d64.1424: FileVersion: 6.1.7601.19045 (win7sp1_gdr.151019-1254)
229d64.1424: FileDescription: ApiSet Schema DLL
230d64.1424: supR3HardenedWinFindAdversaries: 0x0
231d64.1424: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume1\Program Files\VirtualBox'
232d64.1424: Calling main()
233d64.1424: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
234d64.1424: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume1\Program Files\VirtualBox'
235d64.1424: '\Device\HarddiskVolume1\Program Files\VirtualBox\VirtualBox.exe' has no imports
236d64.1424: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\VirtualBox\VirtualBox.exe)
237d64.1424: SUPR3HardenedMain: Respawn #2
238d64.1424: supR3HardNtEnableThreadCreation:
239d64.1424: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\embdtrst.dll)
240d64.1424: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\embdtrst.dll
241d64.1424: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\EmbdTrst.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=007d29f4:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
242d64.1424: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\embdtrst.dll [lacks WinVerifyTrust]
243d64.1424: supR3HardenedDllNotificationCallback: load 75aa0000 LB 0x00005000 C:\Windows\system32\EmbdTrst.DLL [fFlags=0x0]
244d64.1424: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\embdtrst.dll [lacks WinVerifyTrust]
245d64.1424: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=75aa0000 'C:\Windows\system32\EmbdTrst.DLL'
246d64.1424: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\apphelp.dll)
247d64.1424: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\apphelp.dll
248d64.1424: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\apphelp.dll (rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=00000000:<flags> [calling]
249d64.1424: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\apphelp.dll [lacks WinVerifyTrust]
250d64.1424: supR3HardenedDllNotificationCallback: load 759e0000 LB 0x0004c000 C:\Windows\system32\apphelp.dll [fFlags=0x0]
251d64.1424: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\apphelp.dll [lacks WinVerifyTrust]
252d64.1424: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=759e0000 'C:\Windows\system32\apphelp.dll'
253d64.1424: supR3HardNtDisableThreadCreation: pvLdrInitThunk=77dc3911 pvNtTerminateThread=77da69c0
254d64.1424: supR3HardenedWinDoReSpawn(2): New child 1478.1738 [kernel32].
255d64.1424: supR3HardNtChildGatherData: PebBaseAddress=7ffdf000 cbPeb=0x248
256d64.1424: supR3HardNtPuChFindNtdll: uNtDllParentAddr=77d60000 uNtDllChildAddr=77d60000
257d64.1424: supR3HardenedWinSetupChildInit: uLdrInitThunk=77dc3911
258d64.1424: supR3HardenedWinSetupChildInit: Start child.
259d64.1424: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 23 ms.
260d64.1424: supR3HardNtChildPurify: Startup delay kludge #1/0: 264 ms, 0 sleeps
261d64.1424: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
262d64.1424: *00000000-fffeffff 0x0001/0x0000 0x0000000
263d64.1424: *00010000-fffeffff 0x0004/0x0004 0x0020000
264d64.1424: *00030000-0002bfff 0x0002/0x0002 0x0040000
265d64.1424: 00034000-00027fff 0x0001/0x0000 0x0000000
266d64.1424: *00040000-0003efff 0x0004/0x0004 0x0020000
267d64.1424: 00041000-00031fff 0x0001/0x0000 0x0000000
268d64.1424: *00050000-fff52fff 0x0000/0x0004 0x0020000
269d64.1424: 0014d000-0014afff 0x0104/0x0004 0x0020000
270d64.1424: 0014f000-0014dfff 0x0004/0x0004 0x0020000
271d64.1424: *00150000-0014efff 0x0004/0x0004 0x0020000
272d64.1424: 00151000-ff0b1fff 0x0001/0x0000 0x0000000
273d64.1424: *011f0000-011f0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\VirtualBox\VirtualBox.exe
274d64.1424: 011f1000-01267fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\VirtualBox\VirtualBox.exe
275d64.1424: 01268000-01268fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\VirtualBox\VirtualBox.exe
276d64.1424: 01269000-012a2fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\VirtualBox\VirtualBox.exe
277d64.1424: 012a3000-012a3fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\VirtualBox\VirtualBox.exe
278d64.1424: 012a4000-012a4fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\VirtualBox\VirtualBox.exe
279d64.1424: 012a5000-012a5fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\VirtualBox\VirtualBox.exe
280d64.1424: 012a6000-012a6fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\VirtualBox\VirtualBox.exe
281d64.1424: 012a7000-012abfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\VirtualBox\VirtualBox.exe
282d64.1424: 012ac000-012aefff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\VirtualBox\VirtualBox.exe
283d64.1424: 012af000-012f2fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\VirtualBox\VirtualBox.exe
284d64.1424: 012f3000-8a885fff 0x0001/0x0000 0x0000000
285d64.1424: *77d60000-77d60fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
286d64.1424: 77d61000-77e37fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
287d64.1424: 77e38000-77e3dfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
288d64.1424: 77e3e000-77e3efff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
289d64.1424: 77e3f000-77e40fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
290d64.1424: 77e41000-77ea0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
291d64.1424: 77ea1000-77d81fff 0x0001/0x0000 0x0000000
292d64.1424: *77fc0000-77fc0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\apisetschema.dll
293d64.1424: 77fc1000-6ffe1fff 0x0001/0x0000 0x0000000
294d64.1424: *7ffa0000-7ff6cfff 0x0002/0x0002 0x0040000
295d64.1424: 7ffd3000-7ffc7fff 0x0001/0x0000 0x0000000
296d64.1424: *7ffde000-7ffdcfff 0x0004/0x0004 0x0020000
297d64.1424: *7ffdf000-7ffddfff 0x0004/0x0004 0x0020000
298d64.1424: *7ffe0000-7ffdefff 0x0002/0x0002 0x0020000
299d64.1424: 7ffe1000-7ffd1fff 0x0001/0x0002 0x0020000
300d64.1424: apisetschema.dll: timestamp 0x56258c72 (rc=VINF_SUCCESS)
301d64.1424: VirtualBox.exe: timestamp 0x56743212 (rc=VINF_SUCCESS)
302d64.1424: '\Device\HarddiskVolume1\Program Files\VirtualBox\VirtualBox.exe' has no imports
303d64.1424: '\Device\HarddiskVolume1\Windows\System32\apisetschema.dll' has no imports
304d64.1424: '\Device\HarddiskVolume1\Windows\System32\ntdll.dll' has no imports
305d64.1424: supR3HardNtChildPurify: Done after 308 ms and 0 fixes (loop #0).
3061478.1738: Log file opened: 5.0.12r104815 g_hStartupLog=00000004 g_uNtVerCombined=0x611db110
3071478.1738: supR3HardenedVmProcessInit: uNtDllAddr=77d60000
3081478.1738: ntdll.dll: timestamp 0x56258dbb (rc=VINF_SUCCESS)
3091478.1738: New simple heap: #1 00260000 LB 0x400000 (for 1314816 allocation)
310d64.1424: supR3HardenedEarlyCompact: Removed heap 1 (0x300000 LB 0x400000)
311d64.1424: supR3HardNtEnableThreadCreation:
3121478.1738: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume1\Program Files\VirtualBox'
3131478.1738: System32: \Device\HarddiskVolume1\Windows\System32
3141478.1738: WinSxS: \Device\HarddiskVolume1\Windows\winsxs
3151478.1738: KnownDllPath: C:\Windows\system32
3161478.1738: supR3HardenedVmProcessInit: Opening vboxdrv...
3171478.1738: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
3181478.1738: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
3191478.1738: Registered Dll notification callback with NTDLL.
3201478.1738: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\kernel32.dll)
3211478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\kernel32.dll
3221478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=00000000:<flags> [calling]
3231478.1738: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
3241478.1738: supR3HardenedDllNotificationCallback: load 77c80000 LB 0x000d4000 C:\Windows\system32\kernel32.dll [fFlags=0x0]
3251478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
3261478.1738: supR3HardenedDllNotificationCallback: load 75f80000 LB 0x0004b000 C:\Windows\system32\KERNELBASE.dll [fFlags=0x0]
3271478.1738: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\KernelBase.dll)
3281478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\KernelBase.dll
3291478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77c80000 'C:\Windows\system32\kernel32.dll'
3301478.1738: supR3HardNtDisableThreadCreation: pvLdrInitThunk=77dc3911 pvNtTerminateThread=77da69c0
331d64.1424: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 64 ms.
3321478.1738: \SystemRoot\System32\ntdll.dll:
3331478.1738: CreationTime: 2015-11-11T01:40:25.748046800Z
3341478.1738: LastWriteTime: 2015-10-20T00:48:47.299796500Z
3351478.1738: ChangeTime: 2015-11-11T01:51:39.761718700Z
3361478.1738: FileAttributes: 0x20
3371478.1738: Size: 0x13f600
3381478.1738: NT Headers: 0xd0
3391478.1738: Timestamp: 0x56258dbb
3401478.1738: Machine: 0x14c - i386
3411478.1738: Timestamp: 0x56258dbb
3421478.1738: Image Version: 6.1
3431478.1738: SizeOfImage: 0x141000 (1314816)
3441478.1738: Resource Dir: 0xe1000 LB 0x5a028
3451478.1738: ProductName: Microsoft® Windows® Operating System
3461478.1738: ProductVersion: 6.1.7601.19045
3471478.1738: FileVersion: 6.1.7601.19045 (win7sp1_gdr.151019-1254)
3481478.1738: FileDescription: NT Layer DLL
3491478.1738: \SystemRoot\System32\kernel32.dll:
3501478.1738: CreationTime: 2015-06-10T01:18:16.643554600Z
3511478.1738: LastWriteTime: 2015-05-09T03:13:42.222000000Z
3521478.1738: ChangeTime: 2015-06-11T00:25:36.694335900Z
3531478.1738: FileAttributes: 0x20
3541478.1738: Size: 0xd4000
3551478.1738: NT Headers: 0xf0
3561478.1738: Timestamp: 0x554d7aff
3571478.1738: Machine: 0x14c - i386
3581478.1738: Timestamp: 0x554d7aff
3591478.1738: Image Version: 6.1
3601478.1738: SizeOfImage: 0xd4000 (868352)
3611478.1738: Resource Dir: 0xc7000 LB 0x528
3621478.1738: ProductName: Microsoft® Windows® Operating System
3631478.1738: ProductVersion: 6.1.7601.18847
3641478.1738: FileVersion: 6.1.7601.18847 (win7sp1_gdr.150508-1512)
3651478.1738: FileDescription: Windows NT BASE API Client DLL
3661478.1738: \SystemRoot\System32\KernelBase.dll:
3671478.1738: CreationTime: 2015-06-10T01:18:16.706054600Z
3681478.1738: LastWriteTime: 2015-05-09T03:13:42.222000000Z
3691478.1738: ChangeTime: 2015-06-11T00:25:36.764648400Z
3701478.1738: FileAttributes: 0x20
3711478.1738: Size: 0x47a00
3721478.1738: NT Headers: 0xe0
3731478.1738: Timestamp: 0x554d7b00
3741478.1738: Machine: 0x14c - i386
3751478.1738: Timestamp: 0x554d7b00
3761478.1738: Image Version: 6.1
3771478.1738: SizeOfImage: 0x4b000 (307200)
3781478.1738: Resource Dir: 0x47000 LB 0x530
3791478.1738: ProductName: Microsoft® Windows® Operating System
3801478.1738: ProductVersion: 6.1.7601.18847
3811478.1738: FileVersion: 6.1.7601.18847 (win7sp1_gdr.150508-1512)
3821478.1738: FileDescription: Windows NT BASE API Client DLL
3831478.1738: \SystemRoot\System32\apisetschema.dll:
3841478.1738: CreationTime: 2015-11-11T01:40:23.794921800Z
3851478.1738: LastWriteTime: 2015-10-20T00:35:03.776000000Z
3861478.1738: ChangeTime: 2015-11-11T01:51:45.983398400Z
3871478.1738: FileAttributes: 0x20
3881478.1738: Size: 0x1a00
3891478.1738: NT Headers: 0xc0
3901478.1738: Timestamp: 0x56258c72
3911478.1738: Machine: 0x14c - i386
3921478.1738: Timestamp: 0x56258c72
3931478.1738: Image Version: 6.1
3941478.1738: SizeOfImage: 0x50000 (327680)
3951478.1738: Resource Dir: 0x30000 LB 0x3f8
3961478.1738: ProductName: Microsoft® Windows® Operating System
3971478.1738: ProductVersion: 6.1.7601.19045
3981478.1738: FileVersion: 6.1.7601.19045 (win7sp1_gdr.151019-1254)
3991478.1738: FileDescription: ApiSet Schema DLL
4001478.1738: supR3HardenedWinFindAdversaries: 0x0
4011478.1738: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume1\Program Files\VirtualBox'
4021478.1738: Calling main()
4031478.1738: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
4041478.1738: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume1\Program Files\VirtualBox'
4051478.1738: '\Device\HarddiskVolume1\Program Files\VirtualBox\VirtualBox.exe' has no imports
4061478.1738: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\VirtualBox\VirtualBox.exe)
4071478.1738: SUPR3HardenedMain: Final process, opening VBoxDrv...
4081478.1738: supR3HardenedEarlyCompact: Removed heap 1 (0x260000 LB 0x400000)
4091478.1738: supR3HardNtEnableThreadCreation:
4101478.1738: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\VirtualBox\VBoxSupLib.dll)
4111478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxSupLib.dll
4121478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=007d24c4:C:\Windows\system32 [calling]
4131478.1738: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
4141478.1738: supR3HardenedDllNotificationCallback: load 74a90000 LB 0x00005000 C:\Program Files\VirtualBox\VBoxSupLib.DLL [fFlags=0x0]
4151478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
4161478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
4171478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
4181478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=74a90000 'C:\Program Files\VirtualBox\VBoxSupLib.DLL'
4191478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
4201478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
4211478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=74a90000 'C:\Program Files\VirtualBox\VBoxSupLib.DLL'
4221478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=74a90000 'C:\Program Files\VirtualBox\VBoxSupLib.DLL'
4231478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
4241478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'crypt32.dll'.
4251478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msasn1.dll'.
4261478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
4271478.1738: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\wintrust.dll)
4281478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\wintrust.dll
4291478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
4301478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
4311478.1738: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll)
4321478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\rpcrt4.dll
4331478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
4341478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume1\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
4351478.1738: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\msasn1.dll)
4361478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\msasn1.dll
4371478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
4381478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume1\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
4391478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
4401478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msasn1.dll'.
4411478.1738: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\crypt32.dll)
4421478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\crypt32.dll
4431478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
4441478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
4451478.1738: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\msvcrt.dll)
4461478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\msvcrt.dll
4471478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
4481478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume1\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
4491478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
4501478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
4511478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
4521478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
4531478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=007d24c4:C:\Windows\system32 [calling]
4541478.1738: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
4551478.1738: supR3HardenedDllNotificationCallback: load 75f10000 LB 0x0002f000 C:\Windows\system32\Wintrust.dll [fFlags=0x0]
4561478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
4571478.1738: supR3HardenedDllNotificationCallback: load 770e0000 LB 0x000ac000 C:\Windows\system32\msvcrt.dll [fFlags=0x0]
4581478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
4591478.1738: supR3HardenedDllNotificationCallback: load 75d90000 LB 0x00121000 C:\Windows\system32\CRYPT32.dll [fFlags=0x0]
4601478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
4611478.1738: supR3HardenedDllNotificationCallback: load 75d50000 LB 0x0000c000 C:\Windows\system32\MSASN1.dll [fFlags=0x0]
4621478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
4631478.1738: supR3HardenedDllNotificationCallback: load 77260000 LB 0x000a2000 C:\Windows\system32\RPCRT4.dll [fFlags=0x0]
4641478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
4651478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=75f10000 'C:\Windows\system32\Wintrust.dll'
4661478.1738: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\bcrypt.dll)
4671478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\bcrypt.dll
4681478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcrypt.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=007d24c4:C:\Windows\system32 [calling]
4691478.1738: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
4701478.1738: supR3HardenedDllNotificationCallback: load 75710000 LB 0x00017000 C:\Windows\system32\bcrypt.dll [fFlags=0x0]
4711478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
4721478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=75710000 'C:\Windows\system32\bcrypt.dll'
4731478.1738: bcrypt.dll loaded at 75710000, BCryptOpenAlgorithmProvider at 75712cda, preloading providers:
4741478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
4751478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'bcrypt.dll'.
4761478.1738: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\bcryptprimitives.dll)
4771478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\bcryptprimitives.dll
4781478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
4791478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume1\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
4801478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
4811478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
4821478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
4831478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
4841478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'rpcrt4.dll'.
4851478.1738: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\advapi32.dll)
4861478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\advapi32.dll
4871478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
4881478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
4891478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
4901478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
4911478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
4921478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
4931478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcryptprimitives.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
4941478.1738: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
4951478.1738: supR3HardenedDllNotificationCallback: load 75280000 LB 0x0003d000 C:\Windows\system32\bcryptprimitives.dll [fFlags=0x0]
4961478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
4971478.1738: supR3HardenedDllNotificationCallback: load 77820000 LB 0x000a0000 C:\Windows\system32\ADVAPI32.dll [fFlags=0x0]
4981478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
4991478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcrt.dll'.
5001478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #15 'rpcrt4.dll'.
5011478.1738: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\sechost.dll)
5021478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\sechost.dll
5031478.1738: supR3HardenedDllNotificationCallback: load 77eb0000 LB 0x00019000 C:\Windows\SYSTEM32\sechost.dll [fFlags=0x0]
5041478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\sechost.dll [lacks WinVerifyTrust]
5051478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=75280000 'C:\Windows\system32\bcryptprimitives.dll'
5061478.1738: BCryptOpenAlgorithmProvider(,'MD2',0,0) -> 0x0 (hAlgo=007effe0)
5071478.1738: BCryptOpenAlgorithmProvider(,'MD4',0,0) -> 0x0 (hAlgo=007f0630)
5081478.1738: BCryptOpenAlgorithmProvider(,'MD5',0,0) -> 0x0 (hAlgo=007f13e8)
5091478.1738: BCryptOpenAlgorithmProvider(,'SHA1',0,0) -> 0x0 (hAlgo=007eff38)
5101478.1738: BCryptOpenAlgorithmProvider(,'SHA256',0,0) -> 0x0 (hAlgo=007f1538)
5111478.1738: BCryptOpenAlgorithmProvider(,'SHA512',0,0) -> 0x0 (hAlgo=007f15d8)
5121478.1738: BCryptOpenAlgorithmProvider(,'RSA',0,0) -> 0x0 (hAlgo=007f1488)
5131478.1738: BCryptOpenAlgorithmProvider(,'DSA',0,0) -> 0x0 (hAlgo=007f1748)
5141478.1738: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\cryptsp.dll)
5151478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\cryptsp.dll
5161478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
5171478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
5181478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
5191478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
5201478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
5211478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
5221478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTSP.dll (Input=CRYPTSP.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
5231478.1738: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
5241478.1738: supR3HardenedDllNotificationCallback: load 75590000 LB 0x00017000 C:\Windows\system32\CRYPTSP.dll [fFlags=0x0]
5251478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
5261478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=75590000 'C:\Windows\system32\CRYPTSP.dll'
5271478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
5281478.1738: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\rsaenh.dll)
5291478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\rsaenh.dll
5301478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
5311478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
5321478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
5331478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
5341478.1738: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
5351478.1738: supR3HardenedDllNotificationCallback: load 75340000 LB 0x0003b000 C:\Windows\system32\rsaenh.dll [fFlags=0x0]
5361478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
5371478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=75340000 'C:\Windows\system32\rsaenh.dll'
5381478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
5391478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ADVAPI32.dll (Input=ADVAPI32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
5401478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77820000 'C:\Windows\system32\ADVAPI32.dll'
5411478.1738: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\cryptbase.dll)
5421478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\cryptbase.dll
5431478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTBASE.dll (Input=CRYPTBASE.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
5441478.1738: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptbase.dll [lacks WinVerifyTrust]
5451478.1738: supR3HardenedDllNotificationCallback: load 75a30000 LB 0x0000c000 C:\Windows\system32\CRYPTBASE.dll [fFlags=0x0]
5461478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptbase.dll [lacks WinVerifyTrust]
5471478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=75a30000 'C:\Windows\system32\CRYPTBASE.dll'
5481478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
5491478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
5501478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77c80000 'C:\Windows\system32\kernel32.dll'
5511478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
5521478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\WINTRUST.DLL (Input=WINTRUST.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
5531478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=75f10000 'C:\Windows\system32\WINTRUST.DLL'
5541478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
5551478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPT32.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
5561478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=75d90000 'C:\Windows\system32\CRYPT32.dll'
5571478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
5581478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'advapi32.dll'.
5591478.1738: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\imagehlp.dll)
5601478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\imagehlp.dll
5611478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
5621478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
5631478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
5641478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
5651478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
5661478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
5671478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\imagehlp.dll (Input=imagehlp.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
5681478.1738: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\imagehlp.dll [lacks WinVerifyTrust]
5691478.1738: supR3HardenedDllNotificationCallback: load 76070000 LB 0x0002b000 C:\Windows\system32\imagehlp.dll [fFlags=0x0]
5701478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\imagehlp.dll [lacks WinVerifyTrust]
5711478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=76070000 'C:\Windows\system32\imagehlp.dll'
5721478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
5731478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTSP.dll (Input=CRYPTSP.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
5741478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=75590000 'C:\Windows\system32\CRYPTSP.dll'
5751478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
5761478.1738: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\user32.dll)
5771478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\user32.dll
5781478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
5791478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
5801478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
5811478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'lpk.dll'.
5821478.1738: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\gdi32.dll)
5831478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\gdi32.dll
5841478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'lpk.dll'...
5851478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'lpk.dll' -> '\Device\HarddiskVolume1\Windows\System32\lpk.dll' [rcNtRedir=0xc0150008]
5861478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'gdi32.dll'.
5871478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'user32.dll'.
5881478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'usp10.dll'.
5891478.1738: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\lpk.dll)
5901478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\lpk.dll
5911478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
5921478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
5931478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\user32.dll [lacks WinVerifyTrust]
5941478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'usp10.dll'...
5951478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'usp10.dll' -> '\Device\HarddiskVolume1\Windows\System32\usp10.dll' [rcNtRedir=0xc0150008]
5961478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
5971478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
5981478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'gdi32.dll'.
5991478.1738: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\usp10.dll)
6001478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\usp10.dll
6011478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
6021478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
6031478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\user32.dll [lacks WinVerifyTrust]
6041478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
6051478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
6061478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
6071478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
6081478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
6091478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
6101478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
6111478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
6121478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\user32.dll [lacks WinVerifyTrust]
6131478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
6141478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
6151478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
6161478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\USER32.dll (Input=USER32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
6171478.1738: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\user32.dll [lacks WinVerifyTrust]
6181478.1738: supR3HardenedDllNotificationCallback: load 77190000 LB 0x000c9000 C:\Windows\system32\USER32.dll [fFlags=0x0]
6191478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\user32.dll [lacks WinVerifyTrust]
6201478.1738: supR3HardenedDllNotificationCallback: load 77bd0000 LB 0x0004e000 C:\Windows\system32\GDI32.dll [fFlags=0x0]
6211478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
6221478.1738: supR3HardenedDllNotificationCallback: load 77ef0000 LB 0x0000a000 C:\Windows\system32\LPK.dll [fFlags=0x0]
6231478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\lpk.dll [lacks WinVerifyTrust]
6241478.1738: supR3HardenedDllNotificationCallback: load 77530000 LB 0x0009d000 C:\Windows\system32\USP10.dll [fFlags=0x0]
6251478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\usp10.dll [lacks WinVerifyTrust]
6261478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
6271478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\gdi32.dll (Input=gdi32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
6281478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77bd0000 'C:\Windows\system32\gdi32.dll'
6291478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'user32.dll'.
6301478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
6311478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msctf.dll'.
6321478.1738: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\imm32.dll)
6331478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\imm32.dll
6341478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msctf.dll'...
6351478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msctf.dll' -> '\Device\HarddiskVolume1\Windows\System32\msctf.dll' [rcNtRedir=0xc0150008]
6361478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
6371478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
6381478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'gdi32.dll'.
6391478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'imm32.dll'.
6401478.1738: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\msctf.dll)
6411478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\msctf.dll
6421478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
6431478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
6441478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
6451478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
6461478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
6471478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\user32.dll [lacks WinVerifyTrust]
6481478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
6491478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume1\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
6501478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\imm32.dll [lacks WinVerifyTrust]
6511478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
6521478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
6531478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
6541478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
6551478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
6561478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\user32.dll [lacks WinVerifyTrust]
6571478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
6581478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
6591478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
6601478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\IMM32.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
6611478.1738: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\imm32.dll [lacks WinVerifyTrust]
6621478.1738: supR3HardenedDllNotificationCallback: load 77ed0000 LB 0x0001f000 C:\Windows\system32\IMM32.DLL [fFlags=0x0]
6631478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\imm32.dll [lacks WinVerifyTrust]
6641478.1738: supR3HardenedDllNotificationCallback: load 77460000 LB 0x000cc000 C:\Windows\system32\MSCTF.dll [fFlags=0x0]
6651478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msctf.dll [lacks WinVerifyTrust]
6661478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77ed0000 'C:\Windows\system32\IMM32.DLL'
6671478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77190000 'C:\Windows\system32\USER32.dll'
6681478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'bcrypt.dll'.
6691478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
6701478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msasn1.dll'.
6711478.1738: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\ncrypt.dll)
6721478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\ncrypt.dll
6731478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
6741478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume1\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
6751478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
6761478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
6771478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
6781478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
6791478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
6801478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume1\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
6811478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
6821478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ncrypt.dll (Input=ncrypt.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
6831478.1738: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\ncrypt.dll [lacks WinVerifyTrust]
6841478.1738: supR3HardenedDllNotificationCallback: load 75730000 LB 0x00039000 C:\Windows\system32\ncrypt.dll [fFlags=0x0]
6851478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\ncrypt.dll [lacks WinVerifyTrust]
6861478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=75730000 'C:\Windows\system32\ncrypt.dll'
6871478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
6881478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcrypt.dll (Input=bcrypt.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
6891478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=75710000 'C:\Windows\system32\bcrypt.dll'
6901478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'crypt32.dll'.
6911478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
6921478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcp71.dll'.
6931478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msvcr71.dll'.
6941478.1738: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\aetsprov.dll)
6951478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\aetsprov.dll
6961478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr71.dll'...
6971478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr71.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcr71.dll' [rcNtRedir=0xc0150008]
6981478.1738: \Device\HarddiskVolume1\Windows\System32\msvcr71.dll: Owner is administrators group.
6991478.1738: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\msvcr71.dll)
7001478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\msvcr71.dll
7011478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp71.dll'...
7021478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp71.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcp71.dll' [rcNtRedir=0xc0150008]
7031478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr71.dll'.
7041478.1738: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\msvcp71.dll)
7051478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\msvcp71.dll
7061478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
7071478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
7081478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
7091478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
7101478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume1\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
7111478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
7121478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr71.dll'...
7131478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr71.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcr71.dll' [rcNtRedir=0xc0150008]
7141478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcr71.dll [lacks WinVerifyTrust]
7151478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\aetsprov.dll (Input=aetsprov.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
7161478.1738: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\aetsprov.dll [lacks WinVerifyTrust]
7171478.1738: supR3HardenedDllNotificationCallback: load 10000000 LB 0x00012000 C:\Windows\system32\aetsprov.dll [fFlags=0x0]
7181478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\aetsprov.dll [lacks WinVerifyTrust]
7191478.1738: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcp71.dll [lacks WinVerifyTrust]
7201478.1738: supR3HardenedDllNotificationCallback: load 7c3a0000 LB 0x0007b000 C:\Windows\system32\MSVCP71.dll [fFlags=0x0]
7211478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcp71.dll [lacks WinVerifyTrust]
7221478.1738: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcr71.dll [lacks WinVerifyTrust]
7231478.1738: supR3HardenedDllNotificationCallback: load 7c340000 LB 0x00056000 C:\Windows\system32\MSVCR71.dll [fFlags=0x0]
7241478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcr71.dll [lacks WinVerifyTrust]
7251478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=10000000 'C:\Windows\system32\aetsprov.dll'
7261478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'hid.dll'.
7271478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'setupapi.dll'.
7281478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'winscard.dll'.
7291478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
7301478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
7311478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ole32.dll'.
7321478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'msvcrt.dll'.
7331478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'advapi32.dll'.
7341478.1738: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\aetpkss1.dll)
7351478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\aetpkss1.dll
7361478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
7371478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
7381478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
7391478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
7401478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
7411478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
7421478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
7431478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
7441478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
7451478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
7461478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'user32.dll'.
7471478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'rpcrt4.dll'.
7481478.1738: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\ole32.dll)
7491478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\ole32.dll
7501478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
7511478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
7521478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
7531478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
7541478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
7551478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\user32.dll [lacks WinVerifyTrust]
7561478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winscard.dll'...
7571478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'winscard.dll' -> '\Device\HarddiskVolume1\Windows\System32\winscard.dll' [rcNtRedir=0xc0150008]
7581478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
7591478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #15 'rpcrt4.dll'.
7601478.1738: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\WinSCard.dll)
7611478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\WinSCard.dll
7621478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
7631478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume1\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
7641478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'cfgmgr32.dll'.
7651478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcrt.dll'.
7661478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'gdi32.dll'.
7671478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
7681478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'user32.dll'.
7691478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'oleaut32.dll'.
7701478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'devobj.dll'.
7711478.1738: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\setupapi.dll)
7721478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\setupapi.dll
7731478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'hid.dll'...
7741478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'hid.dll' -> '\Device\HarddiskVolume1\Windows\System32\hid.dll' [rcNtRedir=0xc0150008]
7751478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
7761478.1738: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\hid.dll)
7771478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\hid.dll
7781478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
7791478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
7801478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
7811478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'devobj.dll'...
7821478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'devobj.dll' -> '\Device\HarddiskVolume1\Windows\System32\devobj.dll' [rcNtRedir=0xc0150008]
7831478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
7841478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'cfgmgr32.dll'.
7851478.1738: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\devobj.dll)
7861478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\devobj.dll
7871478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
7881478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume1\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
7891478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ole32.dll'.
7901478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
7911478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'rpcrt4.dll'.
7921478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'user32.dll'.
7931478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'gdi32.dll'.
7941478.1738: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\oleaut32.dll)
7951478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\oleaut32.dll
7961478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
7971478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
7981478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\user32.dll [lacks WinVerifyTrust]
7991478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
8001478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
8011478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
8021478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
8031478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
8041478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
8051478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
8061478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
8071478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
8081478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
8091478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume1\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
8101478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
8111478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'rpcrt4.dll'.
8121478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
8131478.1738: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\cfgmgr32.dll)
8141478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\cfgmgr32.dll
8151478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
8161478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
8171478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
8181478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
8191478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
8201478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
8211478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
8221478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
8231478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
8241478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
8251478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
8261478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\user32.dll [lacks WinVerifyTrust]
8271478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
8281478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
8291478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
8301478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
8311478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
8321478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
8331478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
8341478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
8351478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
8361478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
8371478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
8381478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
8391478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
8401478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
8411478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
8421478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
8431478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
8441478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
8451478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
8461478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
8471478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\user32.dll [lacks WinVerifyTrust]
8481478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
8491478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
8501478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
8511478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
8521478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
8531478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
8541478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
8551478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
8561478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\ole32.dll [lacks WinVerifyTrust]
8571478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
8581478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume1\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
8591478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cfgmgr32.dll [lacks WinVerifyTrust]
8601478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
8611478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
8621478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
8631478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\aetpkss1.dll (Input=aetpkss1.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
8641478.1738: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\aetpkss1.dll [lacks WinVerifyTrust]
8651478.1738: supR3HardenedDllNotificationCallback: load 008d0000 LB 0x000c0000 C:\Windows\system32\aetpkss1.dll [fFlags=0x0]
8661478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\aetpkss1.dll [lacks WinVerifyTrust]
8671478.1738: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\hid.dll [lacks WinVerifyTrust]
8681478.1738: supR3HardenedDllNotificationCallback: load 74630000 LB 0x00009000 C:\Windows\system32\HID.DLL [fFlags=0x0]
8691478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\hid.dll [lacks WinVerifyTrust]
8701478.1738: supR3HardenedDllNotificationCallback: load 77a30000 LB 0x0019d000 C:\Windows\system32\SETUPAPI.dll [fFlags=0x0]
8711478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\setupapi.dll [lacks WinVerifyTrust]
8721478.1738: supR3HardenedDllNotificationCallback: load 75d60000 LB 0x00027000 C:\Windows\system32\CFGMGR32.dll [fFlags=0x0]
8731478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cfgmgr32.dll [lacks WinVerifyTrust]
8741478.1738: supR3HardenedDllNotificationCallback: load 760a0000 LB 0x0008f000 C:\Windows\system32\OLEAUT32.dll [fFlags=0x0]
8751478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\oleaut32.dll [lacks WinVerifyTrust]
8761478.1738: supR3HardenedDllNotificationCallback: load 778c0000 LB 0x0015c000 C:\Windows\system32\ole32.dll [fFlags=0x0]
8771478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\ole32.dll [lacks WinVerifyTrust]
8781478.1738: supR3HardenedDllNotificationCallback: load 75ef0000 LB 0x00012000 C:\Windows\system32\DEVOBJ.dll [fFlags=0x0]
8791478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\devobj.dll [lacks WinVerifyTrust]
8801478.1738: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\WinSCard.dll [lacks WinVerifyTrust]
8811478.1738: supR3HardenedDllNotificationCallback: load 6b850000 LB 0x00023000 C:\Windows\system32\WinSCard.dll [fFlags=0x0]
8821478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\WinSCard.dll [lacks WinVerifyTrust]
8831478.1738: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Core-LocalRegistry-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
8841478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77c80000 'API-MS-Win-Core-LocalRegistry-L1-1-0.dll'
8851478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=008d0000 'C:\Windows\system32\aetpkss1.dll'
8861478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\WinSCard.dll [lacks WinVerifyTrust]
8871478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\winscard.dll (Input=winscard.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
8881478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6b850000 'C:\Windows\system32\winscard.dll'
8891478.1738: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-Management-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
8901478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77eb0000 'API-MS-WIN-Service-Management-L1-1-0.dll'
8911478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
8921478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77260000 'C:\Windows\system32\rpcrt4.dll'
8931478.1738: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-Management-L2-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
8941478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77eb0000 'API-MS-WIN-Service-Management-L2-1-0.dll'
8951478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
8961478.1738: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\winsta.dll)
8971478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\winsta.dll
8981478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
8991478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
9001478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
9011478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\WINSTA.dll (Input=WINSTA.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
9021478.1738: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\winsta.dll [lacks WinVerifyTrust]
9031478.1738: supR3HardenedDllNotificationCallback: load 75220000 LB 0x00029000 C:\Windows\system32\WINSTA.dll [fFlags=0x0]
9041478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\winsta.dll [lacks WinVerifyTrust]
9051478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=75220000 'C:\Windows\system32\WINSTA.dll'
9061478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
9071478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ADVAPI32.dll (Input=ADVAPI32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
9081478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77820000 'C:\Windows\system32\ADVAPI32.dll'
9091478.1738: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-LSALookup-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
9101478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77eb0000 'API-MS-Win-Security-LSALookup-L1-1-0.dll'
9111478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
9121478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77260000 'C:\Windows\system32\RPCRT4.dll'
9131478.1738: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-LSALookup-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
9141478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77eb0000 'API-MS-Win-Security-LSALookup-L1-1-0.dll'
9151478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
9161478.1738: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\wtsapi32.dll)
9171478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\wtsapi32.dll
9181478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
9191478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
9201478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
9211478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\WTSAPI32.dll (Input=WTSAPI32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
9221478.1738: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\wtsapi32.dll [lacks WinVerifyTrust]
9231478.1738: supR3HardenedDllNotificationCallback: load 741d0000 LB 0x0000d000 C:\Windows\system32\WTSAPI32.dll [fFlags=0x0]
9241478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\wtsapi32.dll [lacks WinVerifyTrust]
9251478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=741d0000 'C:\Windows\system32\WTSAPI32.dll'
9261478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\winsta.dll [lacks WinVerifyTrust]
9271478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\WINSTA.dll (Input=WINSTA.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
9281478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=75220000 'C:\Windows\system32\WINSTA.dll'
9291478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptbase.dll [lacks WinVerifyTrust]
9301478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTBASE.dll (Input=CRYPTBASE.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
9311478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=75a30000 'C:\Windows\system32\CRYPTBASE.dll'
9321478.1738: supR3HardenedMonitor_LdrLoadDll: error opening 'C:\Windows\system32\aetcmgr.dll': 0 (NtPath=\??\C:\Windows\system32\aetcmgr.dll; Input=aetcmgr.dll; rcNtGetDll=0xc0000135
9331478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\aetcmgr.dll (Input=aetcmgr.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
9341478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000135 'C:\Windows\system32\aetcmgr.dll'
9351478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
9361478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\WINTRUST.dll (Input=WINTRUST.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
9371478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=75f10000 'C:\Windows\system32\WINTRUST.dll'
9381478.9e8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\aetpkss1.dll [lacks WinVerifyTrust]
9391478.9e8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\aetpkss1.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
9401478.9e8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=008d0000 'C:\Windows\system32\aetpkss1.dll'
9411478.123c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\aetpkss1.dll [lacks WinVerifyTrust]
9421478.123c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\aetpkss1.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
9431478.123c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=008d0000 'C:\Windows\system32\aetpkss1.dll'
9441478.123c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cfgmgr32.dll [lacks WinVerifyTrust]
9451478.123c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CFGMGR32.dll (Input=CFGMGR32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
9461478.123c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=75d60000 'C:\Windows\system32\CFGMGR32.dll'
9471478.1738: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
9481478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77eb0000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
9491478.1738: supR3HardenedDllNotificationCallback: Unload 008d0000 LB 0x000c0000 C:\Windows\system32\aetpkss1.dll [flags=0x0]
9501478.1738: supR3HardenedDllNotificationCallback: Unload 6b850000 LB 0x00023000 C:\Windows\system32\WinSCard.dll [flags=0x0]
9511478.1738: supR3HardenedDllNotificationCallback: Unload 77a30000 LB 0x0019d000 C:\Windows\system32\SETUPAPI.dll [flags=0x0]
9521478.1738: supR3HardenedDllNotificationCallback: Unload 75ef0000 LB 0x00012000 C:\Windows\system32\DEVOBJ.dll [flags=0x0]
9531478.1738: supR3HardenedDllNotificationCallback: Unload 760a0000 LB 0x0008f000 C:\Windows\system32\OLEAUT32.dll [flags=0x0]
9541478.1738: supR3HardenedDllNotificationCallback: Unload 778c0000 LB 0x0015c000 C:\Windows\system32\ole32.dll [flags=0x0]
9551478.1738: supR3HardenedDllNotificationCallback: Unload 74630000 LB 0x00009000 C:\Windows\system32\HID.DLL [flags=0x0]
9561478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
9571478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'rpcrt4.dll'.
9581478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #19 'profapi.dll'.
9591478.1738: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\userenv.dll)
9601478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\userenv.dll
9611478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'profapi.dll'...
9621478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'profapi.dll' -> '\Device\HarddiskVolume1\Windows\System32\profapi.dll' [rcNtRedir=0xc0150008]
9631478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
9641478.1738: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\profapi.dll)
9651478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\profapi.dll
9661478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
9671478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
9681478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
9691478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
9701478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
9711478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
9721478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
9731478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
9741478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
9751478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\USERENV.dll (Input=USERENV.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
9761478.1738: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\userenv.dll [lacks WinVerifyTrust]
9771478.1738: supR3HardenedDllNotificationCallback: load 75f50000 LB 0x00017000 C:\Windows\system32\USERENV.dll [fFlags=0x0]
9781478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\userenv.dll [lacks WinVerifyTrust]
9791478.1738: supR3HardenedDllNotificationCallback: load 75d40000 LB 0x0000b000 C:\Windows\system32\profapi.dll [fFlags=0x0]
9801478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\profapi.dll [lacks WinVerifyTrust]
9811478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=75f50000 'C:\Windows\system32\USERENV.dll'
9821478.1738: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
9831478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77eb0000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
9841478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
9851478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'rpcrt4.dll'.
9861478.1738: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\gpapi.dll)
9871478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\gpapi.dll
9881478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
9891478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
9901478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
9911478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
9921478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
9931478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
9941478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\GPAPI.dll (Input=GPAPI.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
9951478.1738: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\gpapi.dll [lacks WinVerifyTrust]
9961478.1738: supR3HardenedDllNotificationCallback: load 75160000 LB 0x00016000 C:\Windows\system32\GPAPI.dll [fFlags=0x0]
9971478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\gpapi.dll [lacks WinVerifyTrust]
9981478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=75160000 'C:\Windows\system32\GPAPI.dll'
9991478.1738: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-Management-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
10001478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77eb0000 'API-MS-WIN-Service-Management-L1-1-0.dll'
10011478.1738: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-Management-L2-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
10021478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77eb0000 'API-MS-WIN-Service-Management-L2-1-0.dll'
10031478.1738: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
10041478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77eb0000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
10051478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
10061478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
10071478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'crypt32.dll'.
10081478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'wldap32.dll'.
10091478.1738: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\cryptnet.dll)
10101478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\cryptnet.dll
10111478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wldap32.dll'...
10121478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'wldap32.dll' -> '\Device\HarddiskVolume1\Windows\System32\wldap32.dll' [rcNtRedir=0xc0150008]
10131478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
10141478.1738: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\Wldap32.dll)
10151478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\Wldap32.dll
10161478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
10171478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume1\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
10181478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
10191478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
10201478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
10211478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
10221478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
10231478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
10241478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
10251478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
10261478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
10271478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
10281478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (Input=cryptnet.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
10291478.1738: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
10301478.1738: supR3HardenedDllNotificationCallback: load 74310000 LB 0x0001c000 C:\Windows\system32\cryptnet.dll [fFlags=0x0]
10311478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
10321478.1738: supR3HardenedDllNotificationCallback: load 77f60000 LB 0x00045000 C:\Windows\system32\WLDAP32.dll [fFlags=0x0]
10331478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\Wldap32.dll [lacks WinVerifyTrust]
10341478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
10351478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
10361478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=74310000 'C:\Windows\system32\cryptnet.dll'
10371478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
10381478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
10391478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=74310000 'C:\Windows\system32\cryptnet.dll'
10401478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
10411478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
10421478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=74310000 'C:\Windows\system32\cryptnet.dll'
10431478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
10441478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
10451478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=74310000 'C:\Windows\system32\cryptnet.dll'
10461478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
10471478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
10481478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=74310000 'C:\Windows\system32\cryptnet.dll'
10491478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
10501478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
10511478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=74310000 'C:\Windows\system32\cryptnet.dll'
10521478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
10531478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=74310000 'C:\Windows\system32\cryptnet.dll'
10541478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
10551478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=74310000 'C:\Windows\system32\cryptnet.dll'
10561478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
10571478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=74310000 'C:\Windows\system32\cryptnet.dll'
10581478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
10591478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=74310000 'C:\Windows\system32\cryptnet.dll'
10601478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
10611478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=74310000 'C:\Windows\system32\cryptnet.dll'
10621478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=74310000 'C:\Windows\system32\cryptnet.dll'
10631478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
10641478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=74310000 'C:\Windows\system32\cryptnet.dll'
10651478.1738: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
10661478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77eb0000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
10671478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\profapi.dll [lacks WinVerifyTrust]
10681478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\profapi.dll (Input=profapi.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
10691478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=75d40000 'C:\Windows\system32\profapi.dll'
10701478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
10711478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
10721478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msvcrt.dll'.
10731478.1738: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\shlwapi.dll)
10741478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\shlwapi.dll
10751478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
10761478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
10771478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
10781478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
10791478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
10801478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\user32.dll [lacks WinVerifyTrust]
10811478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
10821478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
10831478.1738: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
10841478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\SHLWAPI.dll (Input=SHLWAPI.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
10851478.1738: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\shlwapi.dll [lacks WinVerifyTrust]
10861478.1738: supR3HardenedDllNotificationCallback: load 77f00000 LB 0x00057000 C:\Windows\system32\SHLWAPI.dll [fFlags=0x0]
10871478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\shlwapi.dll [lacks WinVerifyTrust]
10881478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77f00000 'C:\Windows\system32\SHLWAPI.dll'
10891478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000 pwszName=\SystemRoot\System32\ntdll.dll
10901478.1738: supR3HardNtViCallWinVerifyTrustCatFile: New context 00826fb8
10911478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
10921478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B4DF452093FDAA7DA713F106AEAB7D31AAA8BD52
10931478.1738: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
10941478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77eb0000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
10951478.1738: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-Management-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
10961478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77eb0000 'API-MS-WIN-Service-Management-L1-1-0.dll'
10971478.1738: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-winsvc-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
10981478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77eb0000 'API-MS-WIN-Service-winsvc-L1-1-0.dll'
10991478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
11001478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77820000 'C:\Windows\system32\ADVAPI32.dll'
11011478.1738: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_76_for_KB3101746~31bf3856ad364e35~x86~~6.1.1.1.cat'; file='\SystemRoot\System32\ntdll.dll'
11021478.1738: g_pfnWinVerifyTrust=75f1273a
11031478.1738: supR3HardenedScreenImage/preload: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\crypt32.dll [redoing WinVerifyTrust]
11041478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000e4 pwszName=\Device\HarddiskVolume1\Windows\System32\crypt32.dll
11051478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
11061478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
11071478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=5899593484521EBF43C3FBEF1689EAD74AD8ED7D
11081478.1738: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_212_for_KB3033929~31bf3856ad364e35~x86~~6.1.1.1.cat'; file='\Device\HarddiskVolume1\Windows\System32\crypt32.dll'
11091478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
11101478.1738: supR3HardenedScreenImage/preload: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\crypt32.dll'
11111478.1738: supR3HardenedScreenImage/preload: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\wintrust.dll [redoing WinVerifyTrust]
11121478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000d8 pwszName=\Device\HarddiskVolume1\Windows\System32\wintrust.dll
11131478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
11141478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
11151478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=AD400B10391BF763CC5DFDE600010DE093424AAC
11161478.1738: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_113_for_KB3033929~31bf3856ad364e35~x86~~6.1.1.1.cat'; file='\Device\HarddiskVolume1\Windows\System32\wintrust.dll'
11171478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
11181478.1738: supR3HardenedScreenImage/preload: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\wintrust.dll'
11191478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000003d8 pwszName=\Device\HarddiskVolume1\Windows\System32\shlwapi.dll
11201478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
11211478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
11221478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=5A97620B38393821964747185BD0CFB4FF244F0A
11231478.1738: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-EmbeddedCore-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\shlwapi.dll'
11241478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
11251478.1738: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\shlwapi.dll'
11261478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000003d0 pwszName=\Device\HarddiskVolume1\Windows\System32\Wldap32.dll
11271478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
11281478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
11291478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=4274E678F4A09F0955B304F45CFA0547B0F86BC7
11301478.1738: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-EmbeddedCore-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\Wldap32.dll'
11311478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
11321478.1738: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\Wldap32.dll'
11331478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000003cc pwszName=\Device\HarddiskVolume1\Windows\System32\cryptnet.dll
11341478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
11351478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
11361478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=89E77407A345B2D82F06806B31C1CEFF03A91A6A
11371478.1738: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_113_for_KB3033929~31bf3856ad364e35~x86~~6.1.1.1.cat'; file='\Device\HarddiskVolume1\Windows\System32\cryptnet.dll'
11381478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
11391478.1738: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\cryptnet.dll'
11401478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000002c4 pwszName=\Device\HarddiskVolume1\Windows\System32\gpapi.dll
11411478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
11421478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
11431478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=BD66D8D7C0A43466AD80C34E81C083C3C69E195B
11441478.1738: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-EmbeddedCore-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\gpapi.dll'
11451478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
11461478.1738: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\gpapi.dll'
11471478.1738: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\profapi.dll'
11481478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000001f4 pwszName=\Device\HarddiskVolume1\Windows\System32\userenv.dll
11491478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
11501478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
11511478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=21925C895DA97CB66CCC5FBA910D9ABD265AA276
11521478.1738: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-EmbeddedCore-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\userenv.dll'
11531478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
11541478.1738: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\userenv.dll'
11551478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000002a8 pwszName=\Device\HarddiskVolume1\Windows\System32\wtsapi32.dll
11561478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
11571478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
11581478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=9F4CA8ED9971898A1354BAFA77A2B8F365EA3253
11591478.1738: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-EmbeddedCore-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\wtsapi32.dll'
11601478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
11611478.1738: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\wtsapi32.dll'
11621478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000288 pwszName=\Device\HarddiskVolume1\Windows\System32\winsta.dll
11631478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
11641478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
11651478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=29D5C8F591FC6F7EE578C50BD6A00D7CA9D895EA
11661478.1738: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_78_for_KB2984972~31bf3856ad364e35~x86~~6.1.1.4.cat'; file='\Device\HarddiskVolume1\Windows\System32\winsta.dll'
11671478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
11681478.1738: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\winsta.dll'
11691478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000001ec pwszName=\Device\HarddiskVolume1\Windows\System32\cfgmgr32.dll
11701478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
11711478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
11721478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=A2D26C675A9F5FB0ABA919E9F71726151CB174F1
11731478.1738: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-EmbeddedCore-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\cfgmgr32.dll'
11741478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
11751478.1738: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\cfgmgr32.dll'
11761478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000001e8 pwszName=\Device\HarddiskVolume1\Windows\System32\oleaut32.dll
11771478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
11781478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
11791478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=BCE31FDB944BBD2B4E378704B95BEA36085E5ADA
11801478.1738: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3020338~31bf3856ad364e35~x86~~6.1.1.1.cat'; file='\Device\HarddiskVolume1\Windows\System32\oleaut32.dll'
11811478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
11821478.1738: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\oleaut32.dll'
11831478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000001e4 pwszName=\Device\HarddiskVolume1\Windows\System32\devobj.dll
11841478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
11851478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
11861478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=EE1631BE6E86D9131380E981EC05320E6DF3FD3A
11871478.1738: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-EmbeddedCore-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\devobj.dll'
11881478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
11891478.1738: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\devobj.dll'
11901478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000001e0 pwszName=\Device\HarddiskVolume1\Windows\System32\hid.dll
11911478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
11921478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
11931478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=6E5F4235484C3FBCB2819A1A717B284770C4D931
11941478.1738: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume1\Windows\System32\hid.dll'
11951478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
11961478.1738: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\hid.dll'
11971478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000001dc pwszName=\Device\HarddiskVolume1\Windows\System32\setupapi.dll
11981478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
11991478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
12001478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=07B90F6FCFF3E079727E8F6884115307C6E5BA41
12011478.1738: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-EmbeddedCore-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\setupapi.dll'
12021478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
12031478.1738: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\setupapi.dll'
12041478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000001d8 pwszName=\Device\HarddiskVolume1\Windows\System32\WinSCard.dll
12051478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
12061478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
12071478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=234ADBB040FD0895FB9B779EBA3E8643B2DFF5B7
12081478.1738: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-EmbeddedCore-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\WinSCard.dll'
12091478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
12101478.1738: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\WinSCard.dll'
12111478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000001d4 pwszName=\Device\HarddiskVolume1\Windows\System32\ole32.dll
12121478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
12131478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
12141478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=FAF1DA7C8C4B3B49A52A2B8999865DEDC4F50EC6
12151478.1738: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3072633~31bf3856ad364e35~x86~~6.1.1.1.cat'; file='\Device\HarddiskVolume1\Windows\System32\ole32.dll'
12161478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
12171478.1738: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\ole32.dll'
12181478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000001d0 pwszName=\Device\HarddiskVolume1\Windows\System32\aetpkss1.dll
12191478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
12201478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
12211478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2E4A97B7FEC668CD1161913B473698DEFA1139F5
12221478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Retrying with fresh context (CryptCATAdminEnumCatalogFromHash -> 1168; iCat=0x0)
12231478.1738: supR3HardNtViCallWinVerifyTrustCatFile: New context 00826fb8
12241478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
12251478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2E4A97B7FEC668CD1161913B473698DEFA1139F5
12261478.1738: supR3HardNtViCallWinVerifyTrustCatFile: CryptCATAdminEnumCatalogFromHash failed ERRROR_NOT_FOUND (1168)
12271478.1738: supR3HardNtViCallWinVerifyTrustCatFile: New context 008274c8
12281478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=008274c8
12291478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=32 wszDigest=F98FC8B1EC7D4CC5EF5396839AF33D5720C4307F2EADAF3BA49A58419D3014C8
12301478.1738: supR3HardNtViCallWinVerifyTrustCatFile: CryptCATAdminEnumCatalogFromHash failed ERRROR_NOT_FOUND (1168)
12311478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> -22900 (org 22900)
12321478.1738: supR3HardenedWinVerifyCacheProcessWvtTodos: -22900 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\aetpkss1.dll'
12331478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000001c8 pwszName=\Device\HarddiskVolume1\Windows\System32\msvcp71.dll
12341478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
12351478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
12361478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=1F112F40980D4083D8E1244470CB24FAA67EF349
12371478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Retrying with fresh context (CryptCATAdminEnumCatalogFromHash -> 1168; iCat=0x0)
12381478.1738: supR3HardNtViCallWinVerifyTrustCatFile: New context 00826fb8
12391478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
12401478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=1F112F40980D4083D8E1244470CB24FAA67EF349
12411478.1738: supR3HardNtViCallWinVerifyTrustCatFile: CryptCATAdminEnumCatalogFromHash failed ERRROR_NOT_FOUND (1168)
12421478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 008274c8
12431478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=008274c8
12441478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=32 wszDigest=07083DEBB1416EAFE1C4F60AE2C95AFCCEA06F4A652D0304A881BC400A26BAB9
12451478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Retrying with fresh context (CryptCATAdminEnumCatalogFromHash -> 1168; iCat=0x0)
12461478.1738: supR3HardNtViCallWinVerifyTrustCatFile: New context 008274c8
12471478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=008274c8
12481478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=32 wszDigest=07083DEBB1416EAFE1C4F60AE2C95AFCCEA06F4A652D0304A881BC400A26BAB9
12491478.1738: supR3HardNtViCallWinVerifyTrustCatFile: CryptCATAdminEnumCatalogFromHash failed ERRROR_NOT_FOUND (1168)
12501478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> -22900 (org 22900)
12511478.1738: supR3HardenedWinVerifyCacheProcessWvtTodos: -22900 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\msvcp71.dll'
12521478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000001c4 pwszName=\Device\HarddiskVolume1\Windows\System32\msvcr71.dll
12531478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
12541478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
12551478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=33BBCCF6326276B413A1ECED1BF7842A6D1DDA07
12561478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Retrying with fresh context (CryptCATAdminEnumCatalogFromHash -> 1168; iCat=0x0)
12571478.1738: supR3HardNtViCallWinVerifyTrustCatFile: New context 00826fb8
12581478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
12591478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=33BBCCF6326276B413A1ECED1BF7842A6D1DDA07
12601478.1738: supR3HardNtViCallWinVerifyTrustCatFile: CryptCATAdminEnumCatalogFromHash failed ERRROR_NOT_FOUND (1168)
12611478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 008274c8
12621478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=008274c8
12631478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=32 wszDigest=C510B9C6EDE702F876D857BE2D8BB17EE4839324D54DF7F2150B70445F0055D9
12641478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Retrying with fresh context (CryptCATAdminEnumCatalogFromHash -> 1168; iCat=0x0)
12651478.1738: supR3HardNtViCallWinVerifyTrustCatFile: New context 008274c8
12661478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=008274c8
12671478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=32 wszDigest=C510B9C6EDE702F876D857BE2D8BB17EE4839324D54DF7F2150B70445F0055D9
12681478.1738: supR3HardNtViCallWinVerifyTrustCatFile: CryptCATAdminEnumCatalogFromHash failed ERRROR_NOT_FOUND (1168)
12691478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> -22900 (org 22900)
12701478.1738: supR3HardenedWinVerifyCacheProcessWvtTodos: -22900 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\msvcr71.dll'
12711478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000001c0 pwszName=\Device\HarddiskVolume1\Windows\System32\aetsprov.dll
12721478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
12731478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
12741478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=DDA33A939001F972AE6BDDC723C7C9D8436B5B85
12751478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Retrying with fresh context (CryptCATAdminEnumCatalogFromHash -> 1168; iCat=0x0)
12761478.1738: supR3HardNtViCallWinVerifyTrustCatFile: New context 00826fb8
12771478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
12781478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=DDA33A939001F972AE6BDDC723C7C9D8436B5B85
12791478.1738: supR3HardNtViCallWinVerifyTrustCatFile: CryptCATAdminEnumCatalogFromHash failed ERRROR_NOT_FOUND (1168)
12801478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 008274c8
12811478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=008274c8
12821478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=32 wszDigest=FADD9A489CC3C31A2E920F2B6548749CB7C7A5BE7FEB4ECC1C9503D67CCD1D58
12831478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Retrying with fresh context (CryptCATAdminEnumCatalogFromHash -> 1168; iCat=0x0)
12841478.1738: supR3HardNtViCallWinVerifyTrustCatFile: New context 008274c8
12851478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=008274c8
12861478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=32 wszDigest=FADD9A489CC3C31A2E920F2B6548749CB7C7A5BE7FEB4ECC1C9503D67CCD1D58
12871478.1738: supR3HardNtViCallWinVerifyTrustCatFile: CryptCATAdminEnumCatalogFromHash failed ERRROR_NOT_FOUND (1168)
12881478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> -22900 (org 22900)
12891478.1738: supR3HardenedWinVerifyCacheProcessWvtTodos: -22900 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\aetsprov.dll'
12901478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000001ac pwszName=\Device\HarddiskVolume1\Windows\System32\ncrypt.dll
12911478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
12921478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
12931478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=D56F0B10DF0BBC071EC3118E6BF4B9C85E433C99
12941478.1738: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_76_for_KB3101746~31bf3856ad364e35~x86~~6.1.1.1.cat'; file='\Device\HarddiskVolume1\Windows\System32\ncrypt.dll'
12951478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
12961478.1738: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\ncrypt.dll'
12971478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000190 pwszName=\Device\HarddiskVolume1\Windows\System32\msctf.dll
12981478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
12991478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
13001478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=21CC868DE3508F5C6F6D348B324C1E8AB2969CC6
13011478.1738: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3033889~31bf3856ad364e35~x86~~6.1.1.0.cat'; file='\Device\HarddiskVolume1\Windows\System32\msctf.dll'
13021478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
13031478.1738: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\msctf.dll'
13041478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000018c pwszName=\Device\HarddiskVolume1\Windows\System32\imm32.dll
13051478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
13061478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
13071478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=CB8862BB29C3F539B9BF3A9E49EBC509A515AC5C
13081478.1738: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-EmbeddedCore-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\imm32.dll'
13091478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
13101478.1738: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\imm32.dll'
13111478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000188 pwszName=\Device\HarddiskVolume1\Windows\System32\usp10.dll
13121478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
13131478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
13141478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=620B58DF939ECB4E691974D32E1363C8F89396C3
13151478.1738: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3108670~31bf3856ad364e35~x86~~6.1.1.0.cat'; file='\Device\HarddiskVolume1\Windows\System32\usp10.dll'
13161478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
13171478.1738: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\usp10.dll'
13181478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000184 pwszName=\Device\HarddiskVolume1\Windows\System32\lpk.dll
13191478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
13201478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
13211478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=5B69BB5E518E30563D5F105F9F5A9A0774CF902E
13221478.1738: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3087039~31bf3856ad364e35~x86~~6.1.1.4.cat'; file='\Device\HarddiskVolume1\Windows\System32\lpk.dll'
13231478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
13241478.1738: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\lpk.dll'
13251478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000180 pwszName=\Device\HarddiskVolume1\Windows\System32\gdi32.dll
13261478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
13271478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
13281478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F22A2FC845420DBD44B017133D50DFF33EE6D03F
13291478.1738: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3069392~31bf3856ad364e35~x86~~6.1.1.1.cat'; file='\Device\HarddiskVolume1\Windows\System32\gdi32.dll'
13301478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
13311478.1738: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\gdi32.dll'
13321478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000017c pwszName=\Device\HarddiskVolume1\Windows\System32\user32.dll
13331478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
13341478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
13351478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=44098F3B14959897BB848F81A735A1BE83CB369F
13361478.1738: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_4_for_KB3109094~31bf3856ad364e35~x86~~6.1.1.1.cat'; file='\Device\HarddiskVolume1\Windows\System32\user32.dll'
13371478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
13381478.1738: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\user32.dll'
13391478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000178 pwszName=\Device\HarddiskVolume1\Windows\System32\imagehlp.dll
13401478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
13411478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
13421478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=D59F877FD4F27652A01B1936874AFAF3A55572A8
13431478.1738: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB2893294~31bf3856ad364e35~x86~~6.1.1.1.cat'; file='\Device\HarddiskVolume1\Windows\System32\imagehlp.dll'
13441478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
13451478.1738: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\imagehlp.dll'
13461478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000134 pwszName=\Device\HarddiskVolume1\Windows\System32\cryptbase.dll
13471478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
13481478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
13491478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=685A12871B04F122C1C6F2AA1E429C19211FCD8F
13501478.1738: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_76_for_KB3101746~31bf3856ad364e35~x86~~6.1.1.1.cat'; file='\Device\HarddiskVolume1\Windows\System32\cryptbase.dll'
13511478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
13521478.1738: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\cryptbase.dll'
13531478.1738: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\rsaenh.dll'
13541478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000130 pwszName=\Device\HarddiskVolume1\Windows\System32\cryptsp.dll
13551478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
13561478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
13571478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=EFE6B29BE955FB2D869F3B57909DF90693FBBCEB
13581478.1738: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_113_for_KB3033929~31bf3856ad364e35~x86~~6.1.1.1.cat'; file='\Device\HarddiskVolume1\Windows\System32\cryptsp.dll'
13591478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
13601478.1738: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\cryptsp.dll'
13611478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000124 pwszName=\Device\HarddiskVolume1\Windows\System32\sechost.dll
13621478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
13631478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
13641478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=78E9ABD813B4175EBA8EBD16ACB465E0E2FBF7F8
13651478.1738: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume1\Windows\System32\sechost.dll'
13661478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
13671478.1738: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\sechost.dll'
13681478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000120 pwszName=\Device\HarddiskVolume1\Windows\System32\advapi32.dll
13691478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
13701478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
13711478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=0126923AE273E77D7677F69E1B331A63871D998A
13721478.1738: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB2882822~31bf3856ad364e35~x86~~6.1.1.2.cat'; file='\Device\HarddiskVolume1\Windows\System32\advapi32.dll'
13731478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
13741478.1738: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\advapi32.dll'
13751478.1738: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\bcryptprimitives.dll'
13761478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000108 pwszName=\Device\HarddiskVolume1\Windows\System32\bcrypt.dll
13771478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
13781478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
13791478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F0BAB1EFD5C685AC53B020519B5A6984B19E5071
13801478.1738: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume1\Windows\System32\bcrypt.dll'
13811478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
13821478.1738: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\bcrypt.dll'
13831478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000e8 pwszName=\Device\HarddiskVolume1\Windows\System32\msvcrt.dll
13841478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
13851478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
13861478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=50B466D5DDEDD2D1A524F20B8873F187B62AA69F
13871478.1738: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB2654428~31bf3856ad364e35~x86~~6.1.1.0.cat'; file='\Device\HarddiskVolume1\Windows\System32\msvcrt.dll'
13881478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
13891478.1738: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll'
13901478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000e0 pwszName=\Device\HarddiskVolume1\Windows\System32\msasn1.dll
13911478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
13921478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
13931478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=7068F2E1634BBD478D1FBCF4C463626913EA7285
13941478.1738: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-EmbeddedCore-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\msasn1.dll'
13951478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
13961478.1738: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\msasn1.dll'
13971478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000dc pwszName=\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll
13981478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
13991478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
14001478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=75EC13F04473FD191A7C44AD9A7C2B28A625D383
14011478.1738: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_76_for_KB3101746~31bf3856ad364e35~x86~~6.1.1.1.cat'; file='\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll'
14021478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
14031478.1738: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll'
14041478.1738: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Program Files\VirtualBox\VBoxSupLib.dll'
14051478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000024 pwszName=\Device\HarddiskVolume1\Windows\System32\KernelBase.dll
14061478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
14071478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
14081478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=992AF4E9EBEC265515EC875F6F2F14055D1D491D
14091478.1738: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_4_for_KB3063858~31bf3856ad364e35~x86~~6.1.1.0.cat'; file='\Device\HarddiskVolume1\Windows\System32\KernelBase.dll'
14101478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
14111478.1738: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\KernelBase.dll'
14121478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000001c pwszName=\Device\HarddiskVolume1\Windows\System32\kernel32.dll
14131478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
14141478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
14151478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=84623A9DB7C87F822F9F509ECBD6D4DC753E6405
14161478.1738: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_4_for_KB3063858~31bf3856ad364e35~x86~~6.1.1.0.cat'; file='\Device\HarddiskVolume1\Windows\System32\kernel32.dll'
14171478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
14181478.1738: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\kernel32.dll'
14191478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\crypt32.dll
14201478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\crypt32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0087393c:C:\Windows\system32 [calling]
14211478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=75d90000 'C:\Windows\system32\crypt32.dll'
14221478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0x61a3a33f81aace00 C=US, ST=UT, L=Salt Lake City, O=The USERTRUST Network, OU=http://www.usertrust.com, CN=UTN-USERFirst-Object
14231478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0x292d758d85f9d800 C=CN, O=OSCCA, CN=ROOTCA
14241478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0x7a39c7396be7e200 C=CN, ST=Internet, L=Cernet, O=GoAgent, OU=GoAgent Root, CN=GoAgent XX-Net
14251478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0x5ad46780fa5df300 DC=com, DC=microsoft, CN=Microsoft Root Certificate Authority
14261478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0xea5386456178582b C=ZA, ST=Western Cape, L=Durbanville, O=Thawte, OU=Thawte Certification, CN=Thawte Timestamping CA
14271478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0x6cfe8a8d674bca10 O=Alibaba.com Corporation, OU=CA Center, CN=Alibaba.com Corporation Root CA
14281478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0x3be670c1bd02a900 OU=Copyright (c) 1997 Microsoft Corp., OU=Microsoft Corporation, CN=Microsoft Root Authority
14291478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0xcadc32c7ca6ffcfc CN=IcbcCA, O=icbc.com.cn
14301478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0xe20485f3b396a400 C=CN, ST=Internet, L=Cernet, O=GoAgent, OU=GoAgent, CN=GoAgent
14311478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0x4d3835aa4180b200 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2011
14321478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0xa7d940d543089e00 C=CN, ST=Internet, L=Cernet, O=GoAgent, OU=GoAgent Root, CN=GoAgent XX-Net
14331478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0x646e3fe3ba08df00 C=US, O=MSFT, CN=Microsoft Authenticode(tm) Root Authority
14341478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0x4f482c5d9443c000 C=CN, O=Alipay.com Co.,Ltd, OU=www.alipay.com, CN=ALIPAY_ROOT
14351478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0xe7bda57c0ecbb00 CN=ICBC Root CA, O=Industrial and Commercial Bank of China
14361478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0x357a29080824af00 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2006 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G5
14371478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0xece4e4289e08b900 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010
14381478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0x34ccc8a2de87f407 C=CN, O=CFCA Root CA
14391478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0x90d31b5ab79e90f8 CN=Personal ICBC CA, O=personal.icbc.com.cn
14401478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0x43a9cc371ff5385a O=Microsoft Trust Network, OU=Microsoft Corporation, OU=Microsoft Time Stamping Service Root, OU=Copyright (c) 1997 Microsoft Corp.
14411478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0x2e2d2c7c68f0202e O=VeriSign Trust Network, OU=VeriSign, Inc., OU=VeriSign Time Stamping Service Root, OU=NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.
14421478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0x17662ec1a961d300 C=CN, ST=Internet, L=Cernet, O=GoAgent, OU=GoAgent Root, CN=GoAgent XX-Net
14431478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0xd8dbfb2c27bfb200 C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2008 thawte, Inc. - For authorized use only, CN=thawte Primary Root CA - G3
14441478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0x61a3a33f81aace00 C=US, ST=UT, L=Salt Lake City, O=The USERTRUST Network, OU=http://www.usertrust.com, CN=UTN-USERFirst-Object
14451478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0xf4fd306318ccda00 C=US, O=GeoTrust Inc., CN=GeoTrust Global CA
14461478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0x83085097e9afdf00 O=Digital Signature Trust Co., CN=DST Root CA X3
14471478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0xe248b7eeee4af00 C=CH, O=SwissSign AG, CN=SwissSign Gold CA - G2
14481478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0x780679907625cc00 OU=GlobalSign Root CA - R3, O=GlobalSign, CN=GlobalSign
14491478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0x3d98ab22bb04a300 C=IE, O=Baltimore, OU=CyberTrust, CN=Baltimore CyberTrust Root
14501478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0xa0ee62086758b15d C=US, O=Equifax, OU=Equifax Secure Certificate Authority
14511478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0xd944bca189a00 C=BM, O=QuoVadis Limited, CN=QuoVadis Root CA 2
14521478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0x1591b8ac8dcabd00 C=CN, O=WoSign CA Limited, CN=Certification Authority of WoSign
14531478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0x8ff6fc03c1edbd00 C=US, ST=Arizona, L=Scottsdale, O=Starfield Technologies, Inc., CN=Starfield Root Certificate Authority - G2
14541478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0xc6fa4243b695b600 C=US, O=Entrust, Inc., OU=www.entrust.net/CPS is incorporated by reference, OU=(c) 2006 Entrust, Inc., CN=Entrust Root Certification Authority
14551478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0xa3ce8d99e60eda00 C=BE, O=GlobalSign nv-sa, OU=Root CA, CN=GlobalSign Root CA
14561478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0xa671e9fec832b700 C=US, O=Starfield Technologies, Inc., OU=Starfield Class 2 Certification Authority
14571478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0xa8de7211e13be200 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root CA
14581478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0xc48cebc8db05b000 C=TW, O=TAIWAN-CA, OU=Root CA, CN=TWCA Global Root CA
14591478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0x7ae89c50f0b6a00f C=US, O=GTE Corporation, OU=GTE CyberTrust Solutions, Inc., CN=GTE CyberTrust Global Root
14601478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0xd45980fbf0a0ac00 C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2006 thawte, Inc. - For authorized use only, CN=thawte Primary Root CA
14611478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0x4d3835aa4180b200 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2011
14621478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0xc9edb72b684ba00 C=US, O=Entrust, Inc., OU=See www.entrust.net/legal-terms, OU=(c) 2009 Entrust, Inc. - for authorized use only, CN=Entrust Root Certification Authority - G2
14631478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0xf5cd95e581a4ab00 C=US, O=SecureTrust Corporation, CN=SecureTrust CA
14641478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0x298be035a30bab00 C=DE, O=Deutsche Telekom AG, OU=T-TeleSec Trust Center, CN=Deutsche Telekom Root CA 2
14651478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0xabd0695c5d11d15e C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority - G2, OU=(c) 1998 VeriSign, Inc. - For authorized use only, OU=VeriSign Trust Network
14661478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0x6f2ebe0e24cfa600 OU=GlobalSign Root CA - R2, O=GlobalSign, CN=GlobalSign
14671478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0x14018a1bf29e595c C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority
14681478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0x35f812d09650dc00 C=FR, O=Certplus, CN=Class 2 Primary CA
14691478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0x9e5bc2d78b6a3636 C=ZA, ST=Western Cape, L=Cape Town, O=Thawte Consulting cc, OU=Certification Services Division, CN=Thawte Premium Server CA, [email protected]
14701478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0x7c4fd32ec1b1ce00 C=PL, O=Unizeto Sp. z o.o., CN=Certum CA
14711478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0xd4fbe673e5ccc600 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA
14721478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0xb28612a94b4dad00 O=Entrust.net, OU=www.entrust.net/CPS_2048 incorp. by ref. (limits liab.), OU=(c) 1999 Entrust.net Limited, CN=Entrust.net Certification Authority (2048)
14731478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0x357a29080824af00 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2006 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G5
14741478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0x59faf1086271bf00 C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com, Inc., CN=Go Daddy Root Certificate Authority - G2
14751478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0x466cbc09db88c100 C=IL, O=StartCom Ltd., OU=Secure Digital Certificate Signing, CN=StartCom Certification Authority
14761478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0xb16dd37ffeb3b300 C=JP, O=SECOM Trust.net, OU=Security Communication RootCA1
14771478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0x3401b15e3761c700 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2008 VeriSign, Inc. - For authorized use only, CN=VeriSign Universal Root Certification Authority
14781478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0x7cd4ff7b15b8be00 C=US, O=GeoTrust Inc., CN=GeoTrust Primary Certification Authority
14791478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0x20b7075b3689b600 C=IL, O=StartCom Ltd., CN=StartCom Certification Authority G2
14801478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0x491857ead79dde00 C=US, O=The Go Daddy Group, Inc., OU=Go Daddy Class 2 Certification Authority
14811478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0x1f78fc529cbacb00 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 1999 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G3
14821478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0x8043e4ce150ead00 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID Root CA
14831478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0xa8b43f38c3f7b100 C=US, ST=UT, L=Salt Lake City, O=The USERTRUST Network, OU=http://www.usertrust.com, CN=UTN-USERFirst-Hardware
14841478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0x331d58625ee2dc00 C=US, O=GeoTrust Inc., OU=(c) 2008 GeoTrust Inc. - For authorized use only, CN=GeoTrust Primary Certification Authority - G3
14851478.1738: supR3HardenedWinIsDesiredRootCA: Adding 0xf2e6331af7b700 C=SE, O=AddTrust AB, OU=AddTrust External TTP Network, CN=AddTrust External CA Root
14861478.1738: supR3HardenedWinRetrieveTrustedRootCAs: cAdded=64
14871478.1738: SUPR3HardenedMain: Load Runtime...
14881478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
14891478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
14901478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ws2_32.dll'.
14911478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'rpcrt4.dll'.
14921478.1738: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\VirtualBox\VBoxRT.dll) WinVerifyTrust
14931478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxRT.dll
14941478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
14951478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
14961478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
14971478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
14981478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000450 pwszName=\Device\HarddiskVolume1\Windows\System32\ws2_32.dll
14991478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
15001478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
15011478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2535224DB54945234E1A0C452639FCBB02F5F364
15021478.1738: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-EmbeddedCore-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\ws2_32.dll'
15031478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
15041478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
15051478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'rpcrt4.dll'.
15061478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'nsi.dll'.
15071478.1738: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\ws2_32.dll) WinVerifyTrust
15081478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\ws2_32.dll
15091478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
15101478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
15111478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
15121478.1738: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\VirtualBox\msvcp100.dll) WinVerifyTrust
15131478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\VirtualBox\msvcp100.dll
15141478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
15151478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
15161478.1738: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\VirtualBox\msvcr100.dll) WinVerifyTrust
15171478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\VirtualBox\msvcr100.dll
15181478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
15191478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
15201478.1738: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\msvcr100.dll
15211478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
15221478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume1\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
15231478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000484 pwszName=\Device\HarddiskVolume1\Windows\System32\nsi.dll
15241478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
15251478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
15261478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B5C25EDD170A1CAACC3D49C508AB6F58BD6DE6E2
15271478.1738: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume1\Windows\System32\nsi.dll'
15281478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
15291478.1738: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\nsi.dll) WinVerifyTrust
15301478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\nsi.dll
15311478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
15321478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
15331478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
15341478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
15351478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008bfebc:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
15361478.1738: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxRT.dll
15371478.1738: supR3HardenedDllNotificationCallback: load 6d470000 LB 0x00441000 C:\Program Files\VirtualBox\VBoxRT.dll [fFlags=0x0]
15381478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxRT.dll
15391478.1738: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\msvcr100.dll
15401478.1738: supR3HardenedDllNotificationCallback: load 6e7c0000 LB 0x000bf000 C:\Program Files\VirtualBox\MSVCR100.dll [fFlags=0x0]
15411478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\msvcr100.dll
15421478.1738: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\msvcp100.dll
15431478.1738: supR3HardenedDllNotificationCallback: load 6ebe0000 LB 0x00069000 C:\Program Files\VirtualBox\MSVCP100.dll [fFlags=0x0]
15441478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\msvcp100.dll
15451478.1738: supR3HardenedDllNotificationCallback: load 775e0000 LB 0x00035000 C:\Windows\system32\WS2_32.dll [fFlags=0x0]
15461478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ws2_32.dll
15471478.1738: supR3HardenedDllNotificationCallback: load 775d0000 LB 0x00006000 C:\Windows\system32\NSI.dll [fFlags=0x0]
15481478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\nsi.dll
15491478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxRT.dll
15501478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
15511478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6d470000 'C:\Program Files\VirtualBox\VBoxRT.dll'
15521478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxRT.dll
15531478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
15541478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6d470000 'C:\Program Files\VirtualBox\VBoxRT.dll'
15551478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxRT.dll
15561478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
15571478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6d470000 'C:\Program Files\VirtualBox\VBoxRT.dll'
15581478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxRT.dll
15591478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
15601478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6d470000 'C:\Program Files\VirtualBox\VBoxRT.dll'
15611478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxRT.dll
15621478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
15631478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6d470000 'C:\Program Files\VirtualBox\VBoxRT.dll'
15641478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxRT.dll
15651478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
15661478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6d470000 'C:\Program Files\VirtualBox\VBoxRT.dll'
15671478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6d470000 'C:\Program Files\VirtualBox\VBoxRT.dll'
15681478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6d470000 'C:\Program Files\VirtualBox\VBoxRT.dll'
15691478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6d470000 'C:\Program Files\VirtualBox\VBoxRT.dll'
15701478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6d470000 'C:\Program Files\VirtualBox\VBoxRT.dll'
15711478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6d470000 'C:\Program Files\VirtualBox\VBoxRT.dll'
15721478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6d470000 'C:\Program Files\VirtualBox\VBoxRT.dll'
15731478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6d470000 'C:\Program Files\VirtualBox\VBoxRT.dll'
15741478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxRT.dll
15751478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
15761478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6d470000 'C:\Program Files\VirtualBox\VBoxRT.dll'
15771478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6d470000 'C:\Program Files\VirtualBox\VBoxRT.dll'
15781478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6d470000 'C:\Program Files\VirtualBox\VBoxRT.dll'
15791478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6d470000 'C:\Program Files\VirtualBox\VBoxRT.dll'
15801478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6d470000 'C:\Program Files\VirtualBox\VBoxRT.dll'
15811478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6d470000 'C:\Program Files\VirtualBox\VBoxRT.dll'
15821478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6d470000 'C:\Program Files\VirtualBox\VBoxRT.dll'
15831478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6d470000 'C:\Program Files\VirtualBox\VBoxRT.dll'
15841478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6d470000 'C:\Program Files\VirtualBox\VBoxRT.dll'
15851478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6d470000 'C:\Program Files\VirtualBox\VBoxRT.dll'
15861478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6d470000 'C:\Program Files\VirtualBox\VBoxRT.dll'
15871478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6d470000 'C:\Program Files\VirtualBox\VBoxRT.dll'
15881478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6d470000 'C:\Program Files\VirtualBox\VBoxRT.dll'
15891478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6d470000 'C:\Program Files\VirtualBox\VBoxRT.dll'
15901478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6d470000 'C:\Program Files\VirtualBox\VBoxRT.dll'
15911478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6d470000 'C:\Program Files\VirtualBox\VBoxRT.dll'
15921478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxRT.dll
15931478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=007d280c:C:\Program Files\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Python\;C:\Program Files\Python\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem [calling]
15941478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6d470000 'C:\Program Files\VirtualBox\VBoxRT.dll'
15951478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6d470000 'C:\Program Files\VirtualBox\VBoxRT.dll'
15961478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6d470000 'C:\Program Files\VirtualBox\VBoxRT.dll'
15971478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6d470000 'C:\Program Files\VirtualBox\VBoxRT.dll'
15981478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\wintrust.dll
15991478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008739fc:C:\Windows\system32 [calling]
16001478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=75f10000 'C:\Windows\system32\Wintrust.dll'
16011478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\crypt32.dll
16021478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\crypt32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008739fc:C:\Windows\system32 [calling]
16031478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=75d90000 'C:\Windows\system32\crypt32.dll'
16041478.1738: SUPR3HardenedMain: Load TrustedMain...
16051478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'opengl32.dll'.
16061478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
16071478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxvmm.dll'.
16081478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcp100.dll'.
16091478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msvcr100.dll'.
16101478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'qtcorevbox4.dll'.
16111478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'qtguivbox4.dll'.
16121478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'qtopenglvbox4.dll'.
16131478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'user32.dll'.
16141478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'gdi32.dll'.
16151478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'advapi32.dll'.
16161478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'shell32.dll'.
16171478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'ole32.dll'.
16181478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'oleaut32.dll'.
16191478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #15 'comdlg32.dll'.
16201478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'winmm.dll'.
16211478.1738: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\VirtualBox\VirtualBox.dll) WinVerifyTrust
16221478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\VirtualBox\VirtualBox.dll
16231478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
16241478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume1\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
16251478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000004bc pwszName=\Device\HarddiskVolume1\Windows\System32\winmm.dll
16261478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
16271478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
16281478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=0907A64D7756C59C69C1DFBD06460EC89D3A8FBD
16291478.1738: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-EmbeddedCore-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\winmm.dll'
16301478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
16311478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
16321478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
16331478.1738: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\winmm.dll) WinVerifyTrust
16341478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\winmm.dll
16351478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comdlg32.dll'...
16361478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'comdlg32.dll' -> '\Device\HarddiskVolume1\Windows\System32\comdlg32.dll' [rcNtRedir=0xc0150008]
16371478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000004a8 pwszName=\Device\HarddiskVolume1\Windows\System32\comdlg32.dll
16381478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
16391478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
16401478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=1C456ACB19416C5E733133B4582891146F151614
16411478.1738: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-EmbeddedCore-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\comdlg32.dll'
16421478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
16431478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
16441478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'shlwapi.dll'.
16451478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
16461478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'gdi32.dll'.
16471478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'comctl32.dll'.
16481478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'shell32.dll'.
16491478.1738: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\comdlg32.dll) WinVerifyTrust
16501478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\comdlg32.dll
16511478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
16521478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume1\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
16531478.1738: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\oleaut32.dll
16541478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
16551478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
16561478.1738: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ole32.dll
16571478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
16581478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume1\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
16591478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000004c8 pwszName=\Device\HarddiskVolume1\Windows\System32\shell32.dll
16601478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
16611478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
16621478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=7E0E9506F317BDB184E9D79C726FEC46DD5C742F
16631478.1738: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3080446~31bf3856ad364e35~x86~~6.1.1.2.cat'; file='\Device\HarddiskVolume1\Windows\System32\shell32.dll'
16641478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
16651478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
16661478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #21 'shlwapi.dll'.
16671478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'user32.dll'.
16681478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #24 'gdi32.dll'.
16691478.1738: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\shell32.dll) WinVerifyTrust
16701478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\shell32.dll
16711478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
16721478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
16731478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
16741478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
16751478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
16761478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
16771478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtopenglvbox4.dll'...
16781478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtopenglvbox4.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\qtopenglvbox4.dll' [rcNtRedir=0xc0150008]
16791478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'opengl32.dll'.
16801478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
16811478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
16821478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qtguivbox4.dll'.
16831478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qtcorevbox4.dll'.
16841478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcr100.dll'.
16851478.1738: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\VirtualBox\QtOpenGLVBox4.dll) WinVerifyTrust
16861478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\VirtualBox\QtOpenGLVBox4.dll
16871478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtguivbox4.dll'...
16881478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtguivbox4.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\qtguivbox4.dll' [rcNtRedir=0xc0150008]
16891478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
16901478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'comdlg32.dll'.
16911478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'oleaut32.dll'.
16921478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'imm32.dll'.
16931478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'winmm.dll'.
16941478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'winspool.drv'.
16951478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ole32.dll'.
16961478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'user32.dll'.
16971478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'advapi32.dll'.
16981478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'shell32.dll'.
16991478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'qtcorevbox4.dll'.
17001478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'msvcp100.dll'.
17011478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'msvcr100.dll'.
17021478.1738: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\VirtualBox\QtGuiVBox4.dll) WinVerifyTrust
17031478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\VirtualBox\QtGuiVBox4.dll
17041478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtcorevbox4.dll'...
17051478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtcorevbox4.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\qtcorevbox4.dll' [rcNtRedir=0xc0150008]
17061478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
17071478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'ole32.dll'.
17081478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
17091478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ws2_32.dll'.
17101478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcp100.dll'.
17111478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcr100.dll'.
17121478.1738: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\VirtualBox\QtCoreVBox4.dll) WinVerifyTrust
17131478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\VirtualBox\QtCoreVBox4.dll
17141478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
17151478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
17161478.1738: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\msvcr100.dll
17171478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
17181478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
17191478.1738: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\msvcp100.dll
17201478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
17211478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
17221478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
17231478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrem.dll'.
17241478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
17251478.1738: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\VirtualBox\VBoxVMM.dll) WinVerifyTrust
17261478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxVMM.dll
17271478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
17281478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
17291478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
17301478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume1\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
17311478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000004f8 pwszName=\Device\HarddiskVolume1\Windows\System32\opengl32.dll
17321478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
17331478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
17341478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=4C7570E385B8CF66CB40344231F3E0AA4189574F
17351478.1738: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\WinEmb-Graphics-Platform~31bf3856ad364e35~x86~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\opengl32.dll'
17361478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
17371478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
17381478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
17391478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'gdi32.dll'.
17401478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'glu32.dll'.
17411478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ddraw.dll'.
17421478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'user32.dll'.
17431478.1738: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\opengl32.dll) WinVerifyTrust
17441478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\opengl32.dll
17451478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
17461478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
17471478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ddraw.dll'...
17481478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'ddraw.dll' -> '\Device\HarddiskVolume1\Windows\System32\ddraw.dll' [rcNtRedir=0xc0150008]
17491478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000004fc pwszName=\Device\HarddiskVolume1\Windows\System32\ddraw.dll
17501478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
17511478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
17521478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=6D0AC3B30C2D6C734EBBA3E99BF60B93FDF28E33
17531478.1738: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\WinEmb-Graphics-Platform~31bf3856ad364e35~x86~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\ddraw.dll'
17541478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
17551478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
17561478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
17571478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'dciman32.dll'.
17581478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
17591478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'setupapi.dll'.
17601478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'dwmapi.dll'.
17611478.1738: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\ddraw.dll) WinVerifyTrust
17621478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\ddraw.dll
17631478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'glu32.dll'...
17641478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'glu32.dll' -> '\Device\HarddiskVolume1\Windows\System32\glu32.dll' [rcNtRedir=0xc0150008]
17651478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000504 pwszName=\Device\HarddiskVolume1\Windows\System32\glu32.dll
17661478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
17671478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
17681478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=8AAE7D02045ADA954DBE714C716FEAB98D1A54F0
17691478.1738: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\WinEmb-Graphics-Platform~31bf3856ad364e35~x86~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\glu32.dll'
17701478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
17711478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
17721478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'opengl32.dll'.
17731478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
17741478.1738: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\glu32.dll) WinVerifyTrust
17751478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\glu32.dll
17761478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
17771478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
17781478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
17791478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
17801478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
17811478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
17821478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
17831478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
17841478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrem.dll'...
17851478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrem.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\vboxrem.dll' [rcNtRedir=0xc0150008]
17861478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
17871478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
17881478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxvmm.dll'.
17891478.1738: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\VirtualBox\VBoxREM.dll) WinVerifyTrust
17901478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxREM.dll
17911478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
17921478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
17931478.1738: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\msvcr100.dll
17941478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
17951478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
17961478.1738: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\msvcr100.dll
17971478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
17981478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
17991478.1738: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\msvcp100.dll
18001478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
18011478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
18021478.1738: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ws2_32.dll
18031478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
18041478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
18051478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
18061478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
18071478.1738: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ole32.dll
18081478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
18091478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
18101478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
18111478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
18121478.1738: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\msvcr100.dll
18131478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
18141478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
18151478.1738: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\msvcp100.dll
18161478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtcorevbox4.dll'...
18171478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtcorevbox4.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\qtcorevbox4.dll' [rcNtRedir=0xc0150008]
18181478.1738: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\QtCoreVBox4.dll
18191478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
18201478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume1\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
18211478.1738: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\shell32.dll
18221478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
18231478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
18241478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
18251478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
18261478.1738: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\user32.dll
18271478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
18281478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
18291478.1738: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ole32.dll
18301478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winspool.drv'...
18311478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'winspool.drv' -> '\Device\HarddiskVolume1\Windows\System32\winspool.drv' [rcNtRedir=0xc0150008]
18321478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000518 pwszName=\Device\HarddiskVolume1\Windows\System32\winspool.drv
18331478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
18341478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
18351478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B39657B6044CE5C98BB9FC443679CBDE0E6BE222
18361478.1738: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-EmbeddedCore-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\winspool.drv'
18371478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
18381478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
18391478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
18401478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
18411478.1738: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\winspool.drv) WinVerifyTrust
18421478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\winspool.drv
18431478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
18441478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume1\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
18451478.1738: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\winmm.dll
18461478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
18471478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume1\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
18481478.1738: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\imm32.dll
18491478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
18501478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume1\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
18511478.1738: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\oleaut32.dll
18521478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comdlg32.dll'...
18531478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'comdlg32.dll' -> '\Device\HarddiskVolume1\Windows\System32\comdlg32.dll' [rcNtRedir=0xc0150008]
18541478.1738: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\comdlg32.dll
18551478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
18561478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
18571478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
18581478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
18591478.1738: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\msvcr100.dll
18601478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtcorevbox4.dll'...
18611478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtcorevbox4.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\qtcorevbox4.dll' [rcNtRedir=0xc0150008]
18621478.1738: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\QtCoreVBox4.dll
18631478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtguivbox4.dll'...
18641478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtguivbox4.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\qtguivbox4.dll' [rcNtRedir=0xc0150008]
18651478.1738: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\QtGuiVBox4.dll
18661478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
18671478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
18681478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
18691478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
18701478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
18711478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume1\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
18721478.1738: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\opengl32.dll
18731478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
18741478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
18751478.1738: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\gdi32.dll
18761478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
18771478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
18781478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
18791478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume1\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
18801478.1738: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\shlwapi.dll
18811478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
18821478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
18831478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
18841478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume1\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
18851478.1738: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\shell32.dll
18861478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comctl32.dll'...
18871478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'comctl32.dll' -> '\Device\HarddiskVolume1\Windows\System32\comctl32.dll' [rcNtRedir=0x0]
18881478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000510 pwszName=\Device\HarddiskVolume1\Windows\System32\comctl32.dll
18891478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
18901478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
18911478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=6F6BC11030E34EE31C1BFA1892BB38C959ED836D
18921478.1738: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3059317~31bf3856ad364e35~x86~~6.1.1.0.cat'; file='\Device\HarddiskVolume1\Windows\System32\comctl32.dll'
18931478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
18941478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'advapi32.dll'.
18951478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
18961478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
18971478.1738: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\comctl32.dll) WinVerifyTrust
18981478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\comctl32.dll
18991478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
19001478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
19011478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
19021478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
19031478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
19041478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume1\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
19051478.1738: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\shlwapi.dll
19061478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
19071478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
19081478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
19091478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
19101478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
19111478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
19121478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
19131478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
19141478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
19151478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
19161478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
19171478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
19181478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
19191478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
19201478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
19211478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
19221478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
19231478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
19241478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
19251478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
19261478.1738: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxVMM.dll
19271478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
19281478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
19291478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
19301478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
19311478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
19321478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
19331478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
19341478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume1\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
19351478.1738: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\opengl32.dll
19361478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
19371478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
19381478.1738: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll
19391478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dwmapi.dll'...
19401478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'dwmapi.dll' -> '\Device\HarddiskVolume1\Windows\System32\dwmapi.dll' [rcNtRedir=0xc0150008]
19411478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000004d0 pwszName=\Device\HarddiskVolume1\Windows\System32\dwmapi.dll
19421478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
19431478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
19441478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2DD0519DFAD1ED741C9324879C92EC15A9FFB8D0
19451478.1738: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-EmbeddedCore-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\dwmapi.dll'
19461478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
19471478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
19481478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
19491478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
19501478.1738: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\dwmapi.dll) WinVerifyTrust
19511478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\dwmapi.dll
19521478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
19531478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume1\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
19541478.1738: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\setupapi.dll
19551478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
19561478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
19571478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dciman32.dll'...
19581478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'dciman32.dll' -> '\Device\HarddiskVolume1\Windows\System32\dciman32.dll' [rcNtRedir=0xc0150008]
19591478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000524 pwszName=\Device\HarddiskVolume1\Windows\System32\dciman32.dll
19601478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
19611478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
19621478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=0121BFD26E8D5A165F8B76EDF84833D970DB8D96
19631478.1738: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3087039~31bf3856ad364e35~x86~~6.1.1.4.cat'; file='\Device\HarddiskVolume1\Windows\System32\dciman32.dll'
19641478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
19651478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
19661478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
19671478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
19681478.1738: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\dciman32.dll) WinVerifyTrust
19691478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\dciman32.dll
19701478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
19711478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
19721478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
19731478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
19741478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
19751478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
19761478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
19771478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
19781478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
19791478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
19801478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
19811478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
19821478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
19831478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
19841478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
19851478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
19861478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\VirtualBox\VirtualBox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008bfebc:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
19871478.1738: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VirtualBox.dll
19881478.1738: supR3HardenedDllNotificationCallback: load 6baf0000 LB 0x009ae000 C:\Program Files\VirtualBox\VirtualBox.dll [fFlags=0x0]
19891478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VirtualBox.dll
19901478.1738: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\opengl32.dll
19911478.1738: supR3HardenedDllNotificationCallback: load 6e6f0000 LB 0x000c8000 C:\Windows\system32\OPENGL32.dll [fFlags=0x0]
19921478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\opengl32.dll
19931478.1738: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\glu32.dll
19941478.1738: supR3HardenedDllNotificationCallback: load 710c0000 LB 0x00022000 C:\Windows\system32\GLU32.dll [fFlags=0x0]
19951478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\glu32.dll
19961478.1738: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ddraw.dll
19971478.1738: supR3HardenedDllNotificationCallback: load 6e600000 LB 0x000e7000 C:\Windows\system32\DDRAW.dll [fFlags=0x0]
19981478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ddraw.dll
19991478.1738: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\dciman32.dll
20001478.1738: supR3HardenedDllNotificationCallback: load 72f40000 LB 0x00006000 C:\Windows\system32\DCIMAN32.dll [fFlags=0x0]
20011478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\dciman32.dll
20021478.1738: supR3HardenedDllNotificationCallback: load 77a30000 LB 0x0019d000 C:\Windows\system32\SETUPAPI.dll [fFlags=0x0]
20031478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\setupapi.dll
20041478.1738: supR3HardenedDllNotificationCallback: load 760a0000 LB 0x0008f000 C:\Windows\system32\OLEAUT32.dll [fFlags=0x0]
20051478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\oleaut32.dll
20061478.1738: supR3HardenedDllNotificationCallback: load 778c0000 LB 0x0015c000 C:\Windows\system32\ole32.dll [fFlags=0x0]
20071478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ole32.dll
20081478.1738: supR3HardenedDllNotificationCallback: load 75ef0000 LB 0x00012000 C:\Windows\system32\DEVOBJ.dll [fFlags=0x0]
20091478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\devobj.dll
20101478.1738: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\dwmapi.dll
20111478.1738: supR3HardenedDllNotificationCallback: load 74510000 LB 0x00013000 C:\Windows\system32\dwmapi.dll [fFlags=0x0]
20121478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\dwmapi.dll
20131478.1738: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxVMM.dll
20141478.1738: supR3HardenedDllNotificationCallback: load 6e3d0000 LB 0x00229000 C:\Program Files\VirtualBox\VBoxVMM.dll [fFlags=0x0]
20151478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxVMM.dll
20161478.1738: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxREM.dll
20171478.1738: supR3HardenedDllNotificationCallback: load 72dc0000 LB 0x00007000 C:\Program Files\VirtualBox\VBoxREM.dll [fFlags=0x0]
20181478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxREM.dll
20191478.1738: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\QtCoreVBox4.dll
20201478.1738: supR3HardenedDllNotificationCallback: load 6dd00000 LB 0x00274000 C:\Program Files\VirtualBox\QtCoreVBox4.dll [fFlags=0x0]
20211478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\QtCoreVBox4.dll
20221478.1738: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\QtGuiVBox4.dll
20231478.1738: supR3HardenedDllNotificationCallback: load 6a170000 LB 0x00810000 C:\Program Files\VirtualBox\QtGuiVBox4.dll [fFlags=0x0]
20241478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\QtGuiVBox4.dll
20251478.1738: supR3HardenedDllNotificationCallback: load 76130000 LB 0x0007b000 C:\Windows\system32\COMDLG32.dll [fFlags=0x0]
20261478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\comdlg32.dll
20271478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'advapi32.dll'.
20281478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
20291478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
20301478.1738: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll)
20311478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll
20321478.1738: supR3HardenedDllNotificationCallback: load 71250000 LB 0x00084000 C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\COMCTL32.dll [fFlags=0x0]
20331478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll [avoiding WinVerifyTrust]
20341478.1738: supR3HardenedDllNotificationCallback: load 761b0000 LB 0x00c4b000 C:\Windows\system32\SHELL32.dll [fFlags=0x0]
20351478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\shell32.dll
20361478.1738: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\winmm.dll
20371478.1738: supR3HardenedDllNotificationCallback: load 72eb0000 LB 0x00032000 C:\Windows\system32\WINMM.dll [fFlags=0x0]
20381478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\winmm.dll
20391478.1738: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\winspool.drv
20401478.1738: supR3HardenedDllNotificationCallback: load 72520000 LB 0x00051000 C:\Windows\system32\WINSPOOL.DRV [fFlags=0x0]
20411478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\winspool.drv
20421478.1738: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\QtOpenGLVBox4.dll
20431478.1738: supR3HardenedDllNotificationCallback: load 6e300000 LB 0x000c1000 C:\Program Files\VirtualBox\QtOpenGLVBox4.dll [fFlags=0x0]
20441478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\QtOpenGLVBox4.dll
20451478.1738: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume1\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll'.
20461478.1738: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume1\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll' [rescheduled]
20471478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\imm32.dll
20481478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
20491478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
20501478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
20511478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
20521478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
20531478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
20541478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\imm32.dll (Input=imm32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c02f4:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
20551478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77ed0000 'C:\Windows\system32\imm32.dll'
20561478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6baf0000 'C:\Program Files\VirtualBox\VirtualBox.dll'
20571478.1738: SUPR3HardenedMain: Calling TrustedMain (6baf10f0)...
20581478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\winmm.dll
20591478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\winmm.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008bfebc:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
20601478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=72eb0000 'C:\Windows\system32\winmm.dll'
20611478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\shell32.dll
20621478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008bfebc:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
20631478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=761b0000 'C:\Windows\system32\shell32.dll'
20641478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\kernel32.dll
20651478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008bfebc:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
20661478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77c80000 'C:\Windows\system32\kernel32.dll'
20671478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000005d0 pwszName=\Device\HarddiskVolume1\Windows\System32\uxtheme.dll
20681478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
20691478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
20701478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=BCFB3B3EDEC8C54A3B95DACAFC19DCB9EA6969BD
20711478.1738: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume1\Windows\System32\uxtheme.dll'
20721478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
20731478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
20741478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
20751478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'gdi32.dll'.
20761478.1738: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\uxtheme.dll) WinVerifyTrust
20771478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\uxtheme.dll
20781478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
20791478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
20801478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
20811478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
20821478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
20831478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
20841478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008bfebc:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
20851478.1738: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\uxtheme.dll
20861478.1738: supR3HardenedDllNotificationCallback: load 74a50000 LB 0x00040000 C:\Windows\system32\uxtheme.dll [fFlags=0x0]
20871478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\uxtheme.dll
20881478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=74a50000 'C:\Windows\system32\uxtheme.dll'
20891478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\uxtheme.dll
20901478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008bfebc:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
20911478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=74a50000 'C:\Windows\system32\uxtheme.dll'
20921478.1738: supR3HardenedMonitor_LdrLoadDll: error opening 'C:\Windows\system32\wintab32.dll': 0 (NtPath=\??\C:\Windows\system32\wintab32.dll; Input=C:\Windows\system32\wintab32.dll; rcNtGetDll=0x0
20931478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wintab32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008bfebc:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
20941478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000135 'C:\Windows\system32\wintab32.dll'
20951478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77190000 'C:\Windows\system32\user32.dll'
20961478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\uxtheme.dll
20971478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008bfebc:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
20981478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=74a50000 'C:\Windows\system32\uxtheme.dll'
20991478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77190000 'C:\Windows\system32\user32.dll'
21001478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\advapi32.dll
21011478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\advapi32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008bfebc:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
21021478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77820000 'C:\Windows\system32\advapi32.dll'
21031478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\userenv.dll
21041478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\userenv.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008bfebc:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
21051478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=75f50000 'C:\Windows\system32\userenv.dll'
21061478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\kernel32.dll
21071478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008bfebc:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
21081478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77c80000 'C:\Windows\system32\kernel32.dll'
21091478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000614 pwszName=\Device\HarddiskVolume1\Windows\System32\clbcatq.dll
21101478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
21111478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
21121478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B560B8A95D275325C41DE5897E348BE60192127E
21131478.1738: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\WinEmb-AppSupport-ComPlus~31bf3856ad364e35~x86~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\clbcatq.dll'
21141478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
21151478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
21161478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'ole32.dll'.
21171478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
21181478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
21191478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
21201478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'rpcrt4.dll'.
21211478.1738: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\clbcatq.dll) WinVerifyTrust
21221478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\clbcatq.dll
21231478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
21241478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
21251478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
21261478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume1\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
21271478.1738: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\oleaut32.dll
21281478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
21291478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
21301478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
21311478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
21321478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
21331478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
21341478.1738: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ole32.dll
21351478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
21361478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
21371478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CLBCatQ.DLL (Input=CLBCatQ.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008bfebc:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
21381478.1738: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\clbcatq.dll
21391478.1738: supR3HardenedDllNotificationCallback: load 77040000 LB 0x00083000 C:\Windows\system32\CLBCatQ.DLL [fFlags=0x0]
21401478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\clbcatq.dll
21411478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77040000 'C:\Windows\system32\CLBCatQ.DLL'
21421478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77820000 'C:\Windows\system32\ADVAPI32.dll'
21431478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\cryptsp.dll
21441478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTSP.dll (Input=CRYPTSP.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008bfebc:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
21451478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=75590000 'C:\Windows\system32\CRYPTSP.dll'
21461478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000063c pwszName=\Device\HarddiskVolume1\Windows\System32\RpcRtRemote.dll
21471478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
21481478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
21491478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=A397FD418538BAA1CB6D18B348447E74938F66EA
21501478.1738: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-EmbeddedCore-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\RpcRtRemote.dll'
21511478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
21521478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'rpcrt4.dll'.
21531478.1738: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\RpcRtRemote.dll) WinVerifyTrust
21541478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\RpcRtRemote.dll
21551478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
21561478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
21571478.1738: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\rpcrt4.dll
21581478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\RpcRtRemote.dll (Input=RpcRtRemote.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008bfebc:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
21591478.1738: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\RpcRtRemote.dll
21601478.1738: supR3HardenedDllNotificationCallback: load 75ab0000 LB 0x0000e000 C:\Windows\system32\RpcRtRemote.dll [fFlags=0x0]
21611478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\RpcRtRemote.dll
21621478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=75ab0000 'C:\Windows\system32\RpcRtRemote.dll'
21631478.5b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
21641478.5b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
21651478.5b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'psapi.dll'.
21661478.5b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vboxvmm.dll'.
21671478.5b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'vboxrt.dll'.
21681478.5b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'advapi32.dll'.
21691478.5b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'version.dll'.
21701478.5b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'ws2_32.dll'.
21711478.5b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'ole32.dll'.
21721478.5b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'oleaut32.dll'.
21731478.5b0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\VirtualBox\VBoxC.dll) WinVerifyTrust
21741478.5b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxC.dll
21751478.5b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
21761478.5b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume1\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
21771478.5b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\oleaut32.dll
21781478.5b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
21791478.5b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
21801478.5b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ole32.dll
21811478.5b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
21821478.5b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
21831478.5b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ws2_32.dll
21841478.5b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'version.dll'...
21851478.5b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'version.dll' -> '\Device\HarddiskVolume1\Windows\System32\version.dll' [rcNtRedir=0xc0150008]
21861478.5b0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000680 pwszName=\Device\HarddiskVolume1\Windows\System32\version.dll
21871478.5b0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
21881478.5b0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
21891478.5b0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=87F58E3B93CDFEB987BC8B5880D3F0366E3D8203
21901478.5b0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume1\Windows\System32\version.dll'
21911478.5b0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
21921478.5b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
21931478.5b0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\version.dll) WinVerifyTrust
21941478.5b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\version.dll
21951478.5b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
21961478.5b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
21971478.5b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
21981478.5b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
21991478.5b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
22001478.5b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
22011478.5b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxVMM.dll
22021478.5b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'psapi.dll'...
22031478.5b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'psapi.dll' -> '\Device\HarddiskVolume1\Windows\System32\psapi.dll' [rcNtRedir=0xc0150008]
22041478.5b0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000690 pwszName=\Device\HarddiskVolume1\Windows\System32\psapi.dll
22051478.5b0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
22061478.5b0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
22071478.5b0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B8C4B546A3AFC4BE73BF28FF4C3BEDCA0C703EA7
22081478.5b0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume1\Windows\System32\psapi.dll'
22091478.5b0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
22101478.5b0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\psapi.dll) WinVerifyTrust
22111478.5b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\psapi.dll
22121478.5b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
22131478.5b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
22141478.5b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\msvcp100.dll
22151478.5b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
22161478.5b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
22171478.5b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
22181478.5b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
22191478.5b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\VirtualBox\VBoxC.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=024a558c:C:\Program Files\VirtualBox;C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
22201478.5b0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxC.dll
22211478.5b0: supR3HardenedDllNotificationCallback: load 6cf70000 LB 0x004f4000 C:\Program Files\VirtualBox\VBoxC.dll [fFlags=0x0]
22221478.5b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxC.dll
22231478.5b0: supR3HardenedDllNotificationCallback: load 77a20000 LB 0x00005000 C:\Windows\system32\PSAPI.DLL [fFlags=0x0]
22241478.5b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\psapi.dll
22251478.5b0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\version.dll
22261478.5b0: supR3HardenedDllNotificationCallback: load 75020000 LB 0x00009000 C:\Windows\system32\VERSION.dll [fFlags=0x0]
22271478.5b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\version.dll
22281478.5b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6cf70000 'C:\Program Files\VirtualBox\VBoxC.dll'
22291478.5b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\oleaut32.dll
22301478.5b0: supR3HardenedMonitor_LdrLoadDll: pName=c:\Windows\system32\oleaut32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008b5f4c:c:\Windows\system32;C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
22311478.5b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=760a0000 'c:\Windows\system32\oleaut32.dll'
22321478.5b0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000684 pwszName=\Device\HarddiskVolume1\Windows\System32\sxs.dll
22331478.5b0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
22341478.5b0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
22351478.5b0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=79CE8A02BDEAE624679BB2A7290B3C61ADC51853
22361478.5b0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-EmbeddedCore-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\sxs.dll'
22371478.5b0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
22381478.5b0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\sxs.dll) WinVerifyTrust
22391478.5b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\sxs.dll
22401478.5b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\SXS.DLL (Input=SXS.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008bfebc:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
22411478.5b0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\sxs.dll
22421478.5b0: supR3HardenedDllNotificationCallback: load 75a40000 LB 0x0005f000 C:\Windows\system32\SXS.DLL [fFlags=0x0]
22431478.5b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\sxs.dll
22441478.5b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=75a40000 'C:\Windows\system32\SXS.DLL'
22451478.5b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77820000 'C:\Windows\system32\ADVAPI32.dll'
22461478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\oleaut32.dll
22471478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\OLEAUT32.dll (Input=OLEAUT32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c04d4:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
22481478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=760a0000 'C:\Windows\system32\OLEAUT32.dll'
22491478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77bd0000 'C:\Windows\system32\gdi32.dll'
22501478.12ec: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
22511478.12ec: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
22521478.12ec: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
22531478.12ec: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.x86\VBoxPuelMain.dll) WinVerifyTrust
22541478.12ec: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.x86\VBoxPuelMain.dll
22551478.12ec: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
22561478.12ec: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
22571478.12ec: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
22581478.12ec: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
22591478.12ec: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxVMM.dll
22601478.12ec: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
22611478.12ec: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
22621478.12ec: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.x86/VBoxPuelMain.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c0024:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
22631478.12ec: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.x86\VBoxPuelMain.dll
22641478.12ec: supR3HardenedDllNotificationCallback: load 71f20000 LB 0x00006000 C:\Program Files\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.x86\VBoxPuelMain.DLL [fFlags=0x0]
22651478.12ec: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.x86\VBoxPuelMain.dll
22661478.12ec: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=71f20000 'C:\Program Files\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.x86/VBoxPuelMain.DLL'
22671478.1738: supR3HardenedMonitor_LdrLoadDll: error opening 'C:\Windows\system32\wintab32.dll': 0 (NtPath=\??\C:\Windows\system32\wintab32.dll; Input=C:\Windows\system32\wintab32.dll; rcNtGetDll=0x0
22681478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wintab32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c036c:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
22691478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000135 'C:\Windows\system32\wintab32.dll'
22701478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\user32.dll
22711478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\user32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c036c:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
22721478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77190000 'C:\Windows\system32\user32.dll'
22731478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\shell32.dll
22741478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c036c:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
22751478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=761b0000 'C:\Windows\system32\shell32.dll'
22761478.1738: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\embdtrst.dll) WinVerifyTrust
22771478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\embdtrst.dll
22781478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\EmbdTrst.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c036c:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
22791478.1738: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\embdtrst.dll
22801478.1738: supR3HardenedDllNotificationCallback: load 75aa0000 LB 0x00005000 C:\Windows\system32\EmbdTrst.DLL [fFlags=0x0]
22811478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\embdtrst.dll
22821478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=75aa0000 'C:\Windows\system32\EmbdTrst.DLL'
22831478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000a94 pwszName=\Device\HarddiskVolume1\Windows\System32\apphelp.dll
22841478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
22851478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
22861478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=308EF32EE8A807D1479CBD7E70222AD12B53DBAC
22871478.1738: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-EmbeddedCore-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\apphelp.dll'
22881478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
22891478.1738: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\apphelp.dll) WinVerifyTrust
22901478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\apphelp.dll
22911478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\apphelp.dll (rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=00000000:<flags> [calling]
22921478.1738: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\apphelp.dll
22931478.1738: supR3HardenedDllNotificationCallback: load 759e0000 LB 0x0004c000 C:\Windows\system32\apphelp.dll [fFlags=0x0]
22941478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\apphelp.dll
22951478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=759e0000 'C:\Windows\system32\apphelp.dll'
22961478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=778c0000 'C:\Windows\system32\ole32.dll'
22971478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\msctf.dll
22981478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\MSCTF.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008b5eac:C:\Windows\system32;C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
22991478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77460000 'C:\Windows\system32\MSCTF.dll'
23001478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=778c0000 'C:\Windows\system32\ole32.dll'
23011478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=760a0000 'C:\Windows\system32\OLEAUT32.dll'
23021478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000ac4 pwszName=\Device\HarddiskVolume1\Windows\System32\wbem\wbemprox.dll
23031478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
23041478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
23051478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=DFAE9B283A50E4A3D49C9E7E37A89888A2B4A44D
23061478.1738: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-EmbeddedCore-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\wbem\wbemprox.dll'
23071478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
23081478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
23091478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'wbemcomn.dll'.
23101478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
23111478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
23121478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ole32.dll'.
23131478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'ws2_32.dll'.
23141478.1738: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\wbem\wbemprox.dll) WinVerifyTrust
23151478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\wbem\wbemprox.dll
23161478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
23171478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
23181478.1738: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ws2_32.dll
23191478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
23201478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
23211478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
23221478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume1\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
23231478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
23241478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
23251478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wbemcomn.dll'...
23261478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'wbemcomn.dll' -> '\Device\HarddiskVolume1\Windows\System32\wbemcomn.dll' [rcNtRedir=0xc0150008]
23271478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000acc pwszName=\Device\HarddiskVolume1\Windows\System32\wbemcomn.dll
23281478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
23291478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
23301478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=E79947DA232978EB549EB8D34A29D88973B71D91
23311478.1738: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-EmbeddedCore-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\wbemcomn.dll'
23321478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
23331478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
23341478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'oleaut32.dll'.
23351478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'ole32.dll'.
23361478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
23371478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ws2_32.dll'.
23381478.1738: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\wbemcomn.dll) WinVerifyTrust
23391478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\wbemcomn.dll
23401478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
23411478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
23421478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
23431478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
23441478.1738: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ws2_32.dll
23451478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
23461478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
23471478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
23481478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
23491478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
23501478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume1\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
23511478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
23521478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
23531478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wbem\wbemprox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=02521be4:C:\Windows\system32\wbem;C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
23541478.1738: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\wbem\wbemprox.dll
23551478.1738: supR3HardenedDllNotificationCallback: load 72990000 LB 0x0000a000 C:\Windows\system32\wbem\wbemprox.dll [fFlags=0x0]
23561478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\wbem\wbemprox.dll
23571478.1738: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\wbemcomn.dll
23581478.1738: supR3HardenedDllNotificationCallback: load 70f60000 LB 0x0005c000 C:\Windows\system32\wbemcomn.dll [fFlags=0x0]
23591478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\wbemcomn.dll
23601478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=72990000 'C:\Windows\system32\wbem\wbemprox.dll'
23611478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000af4 pwszName=\Device\HarddiskVolume1\Windows\System32\wbem\wbemsvc.dll
23621478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
23631478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
23641478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=3338693857D113001E407F1B201A10C276605B11
23651478.1738: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-EmbeddedCore-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\wbem\wbemsvc.dll'
23661478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
23671478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
23681478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'rpcrt4.dll'.
23691478.1738: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\wbem\wbemsvc.dll) WinVerifyTrust
23701478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\wbem\wbemsvc.dll
23711478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
23721478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
23731478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
23741478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
23751478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wbem\wbemsvc.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=02521be4:C:\Windows\system32\wbem;C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
23761478.1738: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\wbem\wbemsvc.dll
23771478.1738: supR3HardenedDllNotificationCallback: load 6fe80000 LB 0x0000f000 C:\Windows\system32\wbem\wbemsvc.dll [fFlags=0x0]
23781478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\wbem\wbemsvc.dll
23791478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6fe80000 'C:\Windows\system32\wbem\wbemsvc.dll'
23801478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000ae8 pwszName=\Device\HarddiskVolume1\Windows\System32\wbem\fastprox.dll
23811478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
23821478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
23831478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=8BC82FF6EDA44F553393099F53D4AED926C6283B
23841478.1738: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-EmbeddedCore-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\wbem\fastprox.dll'
23851478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
23861478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
23871478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'wbemcomn.dll'.
23881478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
23891478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'oleaut32.dll'.
23901478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ole32.dll'.
23911478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ntdsapi.dll'.
23921478.1738: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\wbem\fastprox.dll) WinVerifyTrust
23931478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\wbem\fastprox.dll
23941478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntdsapi.dll'...
23951478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntdsapi.dll' -> '\Device\HarddiskVolume1\Windows\System32\ntdsapi.dll' [rcNtRedir=0xc0150008]
23961478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000af8 pwszName=\Device\HarddiskVolume1\Windows\System32\ntdsapi.dll
23971478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
23981478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
23991478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=BD41341CF1BA6E0043138C5705ABB177F2ED6AAD
24001478.1738: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume1\Windows\System32\ntdsapi.dll'
24011478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
24021478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
24031478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'rpcrt4.dll'.
24041478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'ws2_32.dll'.
24051478.1738: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\ntdsapi.dll) WinVerifyTrust
24061478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\ntdsapi.dll
24071478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
24081478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
24091478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
24101478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume1\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
24111478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
24121478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
24131478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wbemcomn.dll'...
24141478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'wbemcomn.dll' -> '\Device\HarddiskVolume1\Windows\System32\wbemcomn.dll' [rcNtRedir=0xc0150008]
24151478.1738: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\wbemcomn.dll
24161478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
24171478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
24181478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
24191478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
24201478.1738: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ws2_32.dll
24211478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
24221478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
24231478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
24241478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
24251478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wbem\fastprox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=02521be4:C:\Windows\system32\wbem;C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
24261478.1738: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\wbem\fastprox.dll
24271478.1738: supR3HardenedDllNotificationCallback: load 701e0000 LB 0x00096000 C:\Windows\system32\wbem\fastprox.dll [fFlags=0x0]
24281478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\wbem\fastprox.dll
24291478.1738: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ntdsapi.dll
24301478.1738: supR3HardenedDllNotificationCallback: load 701c0000 LB 0x00018000 C:\Windows\system32\NTDSAPI.dll [fFlags=0x0]
24311478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ntdsapi.dll
24321478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=701e0000 'C:\Windows\system32\wbem\fastprox.dll'
24331478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=760a0000 'C:\Windows\system32\OLEAUT32.dll'
24341478.1738: supR3HardenedMonitor_LdrLoadDll: 'C:\Windows\system32\comctl32.dll' -> 'C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll' [redir]
24351478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll [redoing WinVerifyTrust]
24361478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000528 pwszName=\Device\HarddiskVolume1\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll
24371478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
24381478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
24391478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=6F6BC11030E34EE31C1BFA1892BB38C959ED836D
24401478.1738: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3059317~31bf3856ad364e35~x86~~6.1.1.0.cat'; file='\Device\HarddiskVolume1\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll'
24411478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
24421478.1738: supR3HardenedScreenImage/LdrLoadDll: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll'
24431478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll (Input=C:\Windows\system32\comctl32.dll, rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=008c0984:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
24441478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=71250000 'C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll'
24451478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=760a0000 'C:\Windows\system32\OLEAUT32.DLL'
24461478.12f8: \Device\HarddiskVolume1\Windows\System32\drivers\VBoxNetAdp6.sys: Owner is administrators group.
24471478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
24481478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'ndis.sys'.
24491478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'hal.dll'.
24501478.12f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\drivers\VBoxNetAdp6.sys)
24511478.12f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\drivers\VBoxNetAdp6.sys
24521478.12f8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\drivers\VBoxNetAdp6.sys [avoiding WinVerifyTrust]
24531478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
24541478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'hal.dll'.
24551478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'ndis.sys'.
24561478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'netio.sys'.
24571478.12f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\drivers\VBoxNetLwf.sys)
24581478.12f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\drivers\VBoxNetLwf.sys
24591478.12f8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\drivers\VBoxNetLwf.sys [avoiding WinVerifyTrust]
24601478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
24611478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'hal.dll'.
24621478.12f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\drivers\VBoxUSBMon.sys)
24631478.12f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\drivers\VBoxUSBMon.sys
24641478.12f8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\drivers\VBoxUSBMon.sys [avoiding WinVerifyTrust]
24651478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
24661478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'hal.dll'.
24671478.12f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\drivers\VBoxDrv.sys)
24681478.12f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\drivers\VBoxDrv.sys
24691478.12f8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\drivers\VBoxDrv.sys [avoiding WinVerifyTrust]
24701478.12f8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\drivers\VBoxDrv.sys'
24711478.12f8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\drivers\VBoxUSBMon.sys'
24721478.12f8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\drivers\VBoxNetLwf.sys'
24731478.12f8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\drivers\VBoxNetAdp6.sys'
24741478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000ba0 pwszName=\Device\HarddiskVolume1\Windows\System32\netcfgx.dll
24751478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
24761478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
24771478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=EEE76D5DBE9352B9FB1F4A2B953AA4EDA6294F66
24781478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-EmbeddedCore-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\netcfgx.dll'
24791478.12f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
24801478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'shlwapi.dll'.
24811478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
24821478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'gdi32.dll'.
24831478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ole32.dll'.
24841478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'oleaut32.dll'.
24851478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'user32.dll'.
24861478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'slc.dll'.
24871478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'nsi.dll'.
24881478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'iphlpapi.dll'.
24891478.12f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\netcfgx.dll) WinVerifyTrust
24901478.12f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\netcfgx.dll
24911478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'iphlpapi.dll'...
24921478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'iphlpapi.dll' -> '\Device\HarddiskVolume1\Windows\System32\iphlpapi.dll' [rcNtRedir=0xc0150008]
24931478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000bb8 pwszName=\Device\HarddiskVolume1\Windows\System32\IPHLPAPI.DLL
24941478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
24951478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
24961478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=FAD8C6B06A9984F1082FA7D63E0B3AAABCA210F6
24971478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-EmbeddedCore-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\IPHLPAPI.DLL'
24981478.12f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
24991478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
25001478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'nsi.dll'.
25011478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'winnsi.dll'.
25021478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'rpcrt4.dll'.
25031478.12f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\IPHLPAPI.DLL) WinVerifyTrust
25041478.12f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\IPHLPAPI.DLL
25051478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
25061478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume1\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
25071478.12f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\nsi.dll
25081478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'slc.dll'...
25091478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'slc.dll' -> '\Device\HarddiskVolume1\Windows\System32\slc.dll' [rcNtRedir=0xc0150008]
25101478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
25111478.12f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\slc.dll) WinVerifyTrust
25121478.12f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\slc.dll
25131478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
25141478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
25151478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
25161478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume1\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
25171478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
25181478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
25191478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
25201478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
25211478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
25221478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
25231478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
25241478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume1\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
25251478.12f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\shlwapi.dll
25261478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'hal.dll'...
25271478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'hal.dll' -> '\Device\HarddiskVolume1\Windows\System32\hal.dll' [rcNtRedir=0xc0150008]
25281478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
25291478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'kdcom.dll'.
25301478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'pshed.dll'.
25311478.12f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\hal.dll) WinVerifyTrust
25321478.12f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\hal.dll
25331478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
25341478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume1\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
25351478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'pshed.dll'.
25361478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'hal.dll'.
25371478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'bootvid.dll'.
25381478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'kdcom.dll'.
25391478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'clfs.sys'.
25401478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ci.dll'.
25411478.12f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\ntoskrnl.exe) WinVerifyTrust
25421478.12f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\ntoskrnl.exe
25431478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'hal.dll'...
25441478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'hal.dll' -> '\Device\HarddiskVolume1\Windows\System32\hal.dll' [rcNtRedir=0xc0150008]
25451478.12f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\hal.dll
25461478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
25471478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume1\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
25481478.12f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ntoskrnl.exe
25491478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'netio.sys'...
25501478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'netio.sys' -> '\Device\HarddiskVolume1\Windows\System32\drivers\netio.sys' [rcNtRedir=0xc0150008]
25511478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
25521478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'hal.dll'.
25531478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'ndis.sys'.
25541478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msrpc.sys'.
25551478.12f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\drivers\netio.sys) WinVerifyTrust
25561478.12f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\drivers\netio.sys
25571478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ndis.sys'...
25581478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ndis.sys' -> '\Device\HarddiskVolume1\Windows\System32\drivers\ndis.sys' [rcNtRedir=0xc0150008]
25591478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
25601478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'hal.dll'.
25611478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'netio.sys'.
25621478.12f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\drivers\ndis.sys) WinVerifyTrust
25631478.12f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\drivers\ndis.sys
25641478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'hal.dll'...
25651478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'hal.dll' -> '\Device\HarddiskVolume1\Windows\System32\hal.dll' [rcNtRedir=0xc0150008]
25661478.12f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\hal.dll
25671478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
25681478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume1\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
25691478.12f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ntoskrnl.exe
25701478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'hal.dll'...
25711478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'hal.dll' -> '\Device\HarddiskVolume1\Windows\System32\hal.dll' [rcNtRedir=0xc0150008]
25721478.12f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\hal.dll
25731478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ndis.sys'...
25741478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ndis.sys' -> '\Device\HarddiskVolume1\Windows\System32\drivers\ndis.sys' [rcNtRedir=0xc0150008]
25751478.12f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\drivers\ndis.sys
25761478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
25771478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume1\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
25781478.12f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ntoskrnl.exe
25791478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'netio.sys'...
25801478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'netio.sys' -> '\Device\HarddiskVolume1\Windows\System32\drivers\netio.sys' [rcNtRedir=0xc0150008]
25811478.12f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\drivers\netio.sys
25821478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'hal.dll'...
25831478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'hal.dll' -> '\Device\HarddiskVolume1\Windows\System32\hal.dll' [rcNtRedir=0xc0150008]
25841478.12f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\hal.dll
25851478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
25861478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume1\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
25871478.12f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ntoskrnl.exe
25881478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msrpc.sys'...
25891478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msrpc.sys' -> '\Device\HarddiskVolume1\Windows\System32\drivers\msrpc.sys' [rcNtRedir=0xc0150008]
25901478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\shell32.dll
25911478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c07a4:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
25921478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=761b0000 'C:\Windows\system32\shell32.dll'
25931478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77190000 'C:\Windows\system32\user32.dll'
25941478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\winmm.dll
25951478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\WINMM.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c07a4:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
25961478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=72eb0000 'C:\Windows\system32\WINMM.dll'
25971478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
25981478.12f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\drivers\msrpc.sys) WinVerifyTrust
25991478.12f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\drivers\msrpc.sys
26001478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ndis.sys'...
26011478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ndis.sys' -> '\Device\HarddiskVolume1\Windows\System32\drivers\ndis.sys' [rcNtRedir=0xc0150008]
26021478.12f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\drivers\ndis.sys
26031478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'hal.dll'...
26041478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'hal.dll' -> '\Device\HarddiskVolume1\Windows\System32\hal.dll' [rcNtRedir=0xc0150008]
26051478.12f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\hal.dll
26061478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
26071478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume1\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
26081478.12f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ntoskrnl.exe
26091478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ci.dll'...
26101478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ci.dll' -> '\Device\HarddiskVolume1\Windows\System32\ci.dll' [rcNtRedir=0xc0150008]
26111478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
26121478.12f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\ci.dll) WinVerifyTrust
26131478.12f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\ci.dll
26141478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'clfs.sys'...
26151478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'clfs.sys' -> '\Device\HarddiskVolume1\Windows\System32\clfs.sys' [rcNtRedir=0xc0150008]
26161478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
26171478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'hal.dll'.
26181478.12f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\clfs.sys) WinVerifyTrust
26191478.12f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\clfs.sys
26201478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'kdcom.dll'...
26211478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'kdcom.dll' -> '\Device\HarddiskVolume1\Windows\System32\kdcom.dll' [rcNtRedir=0xc0150008]
26221478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
26231478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'hal.dll'.
26241478.12f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\kdcom.dll) WinVerifyTrust
26251478.12f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\kdcom.dll
26261478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bootvid.dll'...
26271478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'bootvid.dll' -> '\Device\HarddiskVolume1\Windows\System32\bootvid.dll' [rcNtRedir=0xc0150008]
26281478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
26291478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'hal.dll'.
26301478.12f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\BOOTVID.DLL) WinVerifyTrust
26311478.12f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\BOOTVID.DLL
26321478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'hal.dll'...
26331478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'hal.dll' -> '\Device\HarddiskVolume1\Windows\System32\hal.dll' [rcNtRedir=0xc0150008]
26341478.12f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\hal.dll
26351478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'pshed.dll'...
26361478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'pshed.dll' -> '\Device\HarddiskVolume1\Windows\System32\pshed.dll' [rcNtRedir=0xc0150008]
26371478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
26381478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'hal.dll'.
26391478.12f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\PSHED.DLL) WinVerifyTrust
26401478.12f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\PSHED.DLL
26411478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'pshed.dll'...
26421478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'pshed.dll' -> '\Device\HarddiskVolume1\Windows\System32\pshed.dll' [rcNtRedir=0xc0150008]
26431478.12f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\PSHED.DLL
26441478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'kdcom.dll'...
26451478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'kdcom.dll' -> '\Device\HarddiskVolume1\Windows\System32\kdcom.dll' [rcNtRedir=0xc0150008]
26461478.12f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\kdcom.dll
26471478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
26481478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume1\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
26491478.12f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ntoskrnl.exe
26501478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
26511478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
26521478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
26531478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
26541478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winnsi.dll'...
26551478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'winnsi.dll' -> '\Device\HarddiskVolume1\Windows\System32\winnsi.dll' [rcNtRedir=0xc0150008]
26561478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000bd8 pwszName=\Device\HarddiskVolume1\Windows\System32\winnsi.dll
26571478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
26581478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
26591478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=83FA279A149B092654B141C0063E129F0A8FF628
26601478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume1\Windows\System32\winnsi.dll'
26611478.12f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
26621478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
26631478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'rpcrt4.dll'.
26641478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'nsi.dll'.
26651478.12f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\winnsi.dll) WinVerifyTrust
26661478.12f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\winnsi.dll
26671478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
26681478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume1\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
26691478.12f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\nsi.dll
26701478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
26711478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
26721478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
26731478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume1\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
26741478.12f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\nsi.dll
26751478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
26761478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
26771478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
26781478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
26791478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'hal.dll'...
26801478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'hal.dll' -> '\Device\HarddiskVolume1\Windows\System32\hal.dll' [rcNtRedir=0xc0150008]
26811478.12f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\hal.dll
26821478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
26831478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume1\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
26841478.12f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ntoskrnl.exe
26851478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'hal.dll'...
26861478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'hal.dll' -> '\Device\HarddiskVolume1\Windows\System32\hal.dll' [rcNtRedir=0xc0150008]
26871478.12f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\hal.dll
26881478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
26891478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume1\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
26901478.12f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ntoskrnl.exe
26911478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'hal.dll'...
26921478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'hal.dll' -> '\Device\HarddiskVolume1\Windows\System32\hal.dll' [rcNtRedir=0xc0150008]
26931478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
26941478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume1\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
26951478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'hal.dll'...
26961478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'hal.dll' -> '\Device\HarddiskVolume1\Windows\System32\hal.dll' [rcNtRedir=0xc0150008]
26971478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
26981478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume1\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
26991478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
27001478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume1\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
27011478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
27021478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume1\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
27031478.12f8: supR3HardenedMonitor_LdrLoadDll: pName=c:\Windows\system32\netcfgx.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008b5f4c:c:\Windows\system32;C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
27041478.12f8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\netcfgx.dll
27051478.12f8: supR3HardenedDllNotificationCallback: load 70040000 LB 0x00067000 c:\Windows\system32\netcfgx.dll [fFlags=0x0]
27061478.12f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\netcfgx.dll
27071478.12f8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\slc.dll
27081478.12f8: supR3HardenedDllNotificationCallback: load 75ac0000 LB 0x0000a000 c:\Windows\system32\slc.dll [fFlags=0x0]
27091478.12f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\slc.dll
27101478.12f8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\IPHLPAPI.DLL
27111478.12f8: supR3HardenedDllNotificationCallback: load 75ae0000 LB 0x0001c000 c:\Windows\system32\IPHLPAPI.DLL [fFlags=0x0]
27121478.12f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\IPHLPAPI.DLL
27131478.12f8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\winnsi.dll
27141478.12f8: supR3HardenedDllNotificationCallback: load 75ad0000 LB 0x00007000 c:\Windows\system32\WINNSI.DLL [fFlags=0x0]
27151478.12f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\winnsi.dll
27161478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=70040000 'c:\Windows\system32\netcfgx.dll'
27171478.12f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\setupapi.dll
27181478.12f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\SETUPAPI.dll (Input=SETUPAPI.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c045c:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
27191478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77a30000 'C:\Windows\system32\SETUPAPI.dll'
27201478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
27211478.12f8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\devrtl.dll)
27221478.12f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\devrtl.dll
27231478.12f8: supR3HardenedDllNotificationCallback: load 752f0000 LB 0x0000e000 C:\Windows\system32\devrtl.DLL [fFlags=0x0]
27241478.12f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\devrtl.dll [avoiding WinVerifyTrust]
27251478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000bf4 pwszName=\Device\HarddiskVolume1\Windows\System32\devrtl.dll
27261478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
27271478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
27281478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=CD89866352298A7134AB5603177CD257C074D584
27291478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-EmbeddedCore-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\devrtl.dll'
27301478.12f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
27311478.12f8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\devrtl.dll'
27321478.12f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\wintrust.dll
27331478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
27341478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
27351478.12f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\WINTRUST.dll (Input=WINTRUST.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c045c:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
27361478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=75f10000 'C:\Windows\system32\WINTRUST.dll'
27371478.1374: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
27381478.1374: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
27391478.1374: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
27401478.1374: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
27411478.1374: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\VirtualBox\VBoxSharedClipboard.dll) WinVerifyTrust
27421478.1374: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxSharedClipboard.dll
27431478.1374: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
27441478.1374: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
27451478.1374: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
27461478.1374: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
27471478.1374: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
27481478.1374: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
27491478.1374: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxVMM.dll
27501478.1374: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
27511478.1374: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
27521478.1374: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\VirtualBox\VBoxSharedClipboard.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c0984:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
27531478.1374: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxSharedClipboard.dll
27541478.1374: supR3HardenedDllNotificationCallback: load 71ef0000 LB 0x00009000 C:\Program Files\VirtualBox\VBoxSharedClipboard.DLL [fFlags=0x0]
27551478.1374: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxSharedClipboard.dll
27561478.1374: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=71ef0000 'C:\Program Files\VirtualBox\VBoxSharedClipboard.DLL'
27571478.14ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
27581478.14ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
27591478.14ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
27601478.14ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\VirtualBox\VBoxDragAndDropSvc.dll) WinVerifyTrust
27611478.14ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxDragAndDropSvc.dll
27621478.14ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
27631478.14ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
27641478.14ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
27651478.14ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
27661478.14ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\msvcp100.dll
27671478.14ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
27681478.14ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
27691478.14ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\VirtualBox\VBoxDragAndDropSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c0984:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
27701478.14ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxDragAndDropSvc.dll
27711478.14ac: supR3HardenedDllNotificationCallback: load 71cc0000 LB 0x0000c000 C:\Program Files\VirtualBox\VBoxDragAndDropSvc.DLL [fFlags=0x0]
27721478.14ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxDragAndDropSvc.dll
27731478.14ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=71cc0000 'C:\Program Files\VirtualBox\VBoxDragAndDropSvc.DLL'
27741478.9c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
27751478.9c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxoglhostcrutil.dll'.
27761478.9c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
27771478.9c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vboxvmm.dll'.
27781478.9c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'vboxoglrenderspu.dll'.
27791478.9c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'advapi32.dll'.
27801478.9c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'ole32.dll'.
27811478.9c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'oleaut32.dll'.
27821478.9c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\VirtualBox\VBoxSharedCrOpenGL.dll) WinVerifyTrust
27831478.9c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxSharedCrOpenGL.dll
27841478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
27851478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume1\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
27861478.9c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\oleaut32.dll
27871478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
27881478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
27891478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
27901478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
27911478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxoglrenderspu.dll'...
27921478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxoglrenderspu.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\vboxoglrenderspu.dll' [rcNtRedir=0xc0150008]
27931478.9c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
27941478.9c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxoglhostcrutil.dll'.
27951478.9c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
27961478.9c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
27971478.9c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
27981478.9c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'advapi32.dll'.
27991478.9c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\VirtualBox\VBoxOGLrenderspu.dll) WinVerifyTrust
28001478.9c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxOGLrenderspu.dll
28011478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
28021478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
28031478.9c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxVMM.dll
28041478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
28051478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
28061478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxoglhostcrutil.dll'...
28071478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxoglhostcrutil.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\vboxoglhostcrutil.dll' [rcNtRedir=0xc0150008]
28081478.9c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
28091478.9c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
28101478.9c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'shlwapi.dll'.
28111478.9c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ws2_32.dll'.
28121478.9c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\VirtualBox\VBoxOGLhostcrutil.dll) WinVerifyTrust
28131478.9c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxOGLhostcrutil.dll
28141478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
28151478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
28161478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
28171478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
28181478.9c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ws2_32.dll
28191478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
28201478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume1\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
28211478.9c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\shlwapi.dll
28221478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
28231478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
28241478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
28251478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
28261478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
28271478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
28281478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
28291478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
28301478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
28311478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
28321478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
28331478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
28341478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxoglhostcrutil.dll'...
28351478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxoglhostcrutil.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\vboxoglhostcrutil.dll' [rcNtRedir=0xc0150008]
28361478.9c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxOGLhostcrutil.dll
28371478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
28381478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
28391478.9c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\msvcr100.dll
28401478.9c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\VirtualBox\VBoxSharedCrOpenGL.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c0984:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
28411478.9c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxSharedCrOpenGL.dll
28421478.9c8: supR3HardenedDllNotificationCallback: load 6ce70000 LB 0x000f5000 C:\Program Files\VirtualBox\VBoxSharedCrOpenGL.DLL [fFlags=0x0]
28431478.9c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxSharedCrOpenGL.dll
28441478.9c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxOGLhostcrutil.dll
28451478.9c8: supR3HardenedDllNotificationCallback: load 6fa70000 LB 0x00028000 C:\Program Files\VirtualBox\VBoxOGLhostcrutil.dll [fFlags=0x0]
28461478.9c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxOGLhostcrutil.dll
28471478.9c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxOGLrenderspu.dll
28481478.9c8: supR3HardenedDllNotificationCallback: load 705a0000 LB 0x00020000 C:\Program Files\VirtualBox\VBoxOGLrenderspu.dll [fFlags=0x0]
28491478.9c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxOGLrenderspu.dll
28501478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6ce70000 'C:\Program Files\VirtualBox\VBoxSharedCrOpenGL.DLL'
28511478.9c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxOGLrenderspu.dll
28521478.9c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\VirtualBox\VBoxOGLrenderspu.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c0984:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
28531478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=705a0000 'C:\Program Files\VirtualBox\VBoxOGLrenderspu.dll'
28541478.9c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
28551478.9c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxoglhostcrutil.dll'.
28561478.9c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\VirtualBox\VBoxOGLhosterrorspu.dll) WinVerifyTrust
28571478.9c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxOGLhosterrorspu.dll
28581478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxoglhostcrutil.dll'...
28591478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxoglhostcrutil.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\vboxoglhostcrutil.dll' [rcNtRedir=0xc0150008]
28601478.9c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxOGLhostcrutil.dll
28611478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
28621478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
28631478.9c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\VirtualBox\VBoxOGLhosterrorspu.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c0984:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
28641478.9c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxOGLhosterrorspu.dll
28651478.9c8: supR3HardenedDllNotificationCallback: load 6e2e0000 LB 0x00018000 C:\Program Files\VirtualBox\VBoxOGLhosterrorspu.dll [fFlags=0x0]
28661478.9c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxOGLhosterrorspu.dll
28671478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6e2e0000 'C:\Program Files\VirtualBox\VBoxOGLhosterrorspu.dll'
28681478.9c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\opengl32.dll
28691478.9c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32/opengl32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c0984:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
28701478.9c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\opengl32.dll
28711478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6e6f0000 'C:\Windows\system32/opengl32.dll'
28721478.9c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\opengl32.dll
28731478.9c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\OPENGL32.dll (Input=OPENGL32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c0984:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
28741478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6e6f0000 'C:\Windows\system32\OPENGL32.dll'
28751478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77bd0000 'C:\Windows\system32\gdi32.dll'
28761478.9c8: \Device\HarddiskVolume1\Windows\System32\atiglpxx.dll: Owner is administrators group.
28771478.9c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000ce4 pwszName=\Device\HarddiskVolume1\Windows\System32\atiglpxx.dll
28781478.9c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
28791478.9c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
28801478.9c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=03769D8751BBC06AB5619759077C96B60ED5A5AE
28811478.9c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x47f; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem2.CAT'; file='\Device\HarddiskVolume1\Windows\System32\atiglpxx.dll'
28821478.9c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
28831478.9c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
28841478.9c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
28851478.9c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcrt.dll'.
28861478.9c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
28871478.9c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\atiglpxx.dll) WinVerifyTrust
28881478.9c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\atiglpxx.dll
28891478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
28901478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
28911478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
28921478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
28931478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
28941478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
28951478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
28961478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
28971478.9c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\atiglpxx.dll (Input=atiglpxx.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c0984:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
28981478.9c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\atiglpxx.dll
28991478.9c8: supR3HardenedDllNotificationCallback: load 71900000 LB 0x00007000 C:\Windows\system32\atiglpxx.dll [fFlags=0x0]
29001478.9c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\atiglpxx.dll
29011478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=71900000 'C:\Windows\system32\atiglpxx.dll'
29021478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77bd0000 'C:\Windows\system32\gdi32.dll'
29031478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77bd0000 'C:\Windows\system32\gdi32.dll'
29041478.9c8: \Device\HarddiskVolume1\Windows\System32\atioglxx.dll: Owner is administrators group.
29051478.9c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000cf4 pwszName=\Device\HarddiskVolume1\Windows\System32\atioglxx.dll
29061478.9c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
29071478.9c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
29081478.9c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=9985F26015F75CEB4B1FFEF19AD43BD3AF321EAF
29091478.9c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x47f; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem2.CAT'; file='\Device\HarddiskVolume1\Windows\System32\atioglxx.dll'
29101478.9c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
29111478.9c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
29121478.9c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
29131478.9c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'version.dll'.
29141478.9c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
29151478.9c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'setupapi.dll'.
29161478.9c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\atioglxx.dll) WinVerifyTrust
29171478.9c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\atioglxx.dll
29181478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
29191478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume1\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
29201478.9c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\setupapi.dll
29211478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
29221478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
29231478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'version.dll'...
29241478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'version.dll' -> '\Device\HarddiskVolume1\Windows\System32\version.dll' [rcNtRedir=0xc0150008]
29251478.9c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\version.dll
29261478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
29271478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
29281478.9c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\gdi32.dll
29291478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
29301478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
29311478.9c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\atioglxx.dll (Input=atioglxx.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c0984:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
29321478.9c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\atioglxx.dll
29331478.9c8: supR3HardenedDllNotificationCallback: load 05220000 LB 0x01325000 C:\Windows\system32\atioglxx.dll [fFlags=0x0]
29341478.9c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\atioglxx.dll
29351478.9c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\dwmapi.dll
29361478.9c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\dwmapi.dll (Input=dwmapi.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c03e4:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
29371478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=74510000 'C:\Windows\system32\dwmapi.dll'
29381478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=05220000 'C:\Windows\system32\atioglxx.dll'
29391478.9c8: \Device\HarddiskVolume1\Windows\System32\atiadlxx.dll: Owner is administrators group.
29401478.9c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000cfc pwszName=\Device\HarddiskVolume1\Windows\System32\atiadlxx.dll
29411478.9c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
29421478.9c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
29431478.9c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=7C59BE65C08685C3D59A5BF216A68FA08E32B741
29441478.9c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x47f; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem2.CAT'; file='\Device\HarddiskVolume1\Windows\System32\atiadlxx.dll'
29451478.9c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
29461478.9c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
29471478.9c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
29481478.9c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'shell32.dll'.
29491478.9c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ole32.dll'.
29501478.9c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcrt.dll'.
29511478.9c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'advapi32.dll'.
29521478.9c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'userenv.dll'.
29531478.9c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'wtsapi32.dll'.
29541478.9c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'setupapi.dll'.
29551478.9c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'psapi.dll'.
29561478.9c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'wsock32.dll'.
29571478.9c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\atiadlxx.dll) WinVerifyTrust
29581478.9c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\atiadlxx.dll
29591478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wsock32.dll'...
29601478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'wsock32.dll' -> '\Device\HarddiskVolume1\Windows\System32\wsock32.dll' [rcNtRedir=0xc0150008]
29611478.9c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000d00 pwszName=\Device\HarddiskVolume1\Windows\System32\wsock32.dll
29621478.9c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
29631478.9c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
29641478.9c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=56BB5C6675EB09C55A32018F501B6713429C47BC
29651478.9c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntph.cat'; file='\Device\HarddiskVolume1\Windows\System32\wsock32.dll'
29661478.9c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
29671478.9c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ws2_32.dll'.
29681478.9c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
29691478.9c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\wsock32.dll) WinVerifyTrust
29701478.9c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\wsock32.dll
29711478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'psapi.dll'...
29721478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'psapi.dll' -> '\Device\HarddiskVolume1\Windows\System32\psapi.dll' [rcNtRedir=0xc0150008]
29731478.9c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\psapi.dll
29741478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
29751478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume1\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
29761478.9c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\setupapi.dll
29771478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wtsapi32.dll'...
29781478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'wtsapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\wtsapi32.dll' [rcNtRedir=0xc0150008]
29791478.9c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\wtsapi32.dll
29801478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'userenv.dll'...
29811478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'userenv.dll' -> '\Device\HarddiskVolume1\Windows\System32\userenv.dll' [rcNtRedir=0xc0150008]
29821478.9c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\userenv.dll
29831478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
29841478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
29851478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
29861478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
29871478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
29881478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
29891478.9c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ole32.dll
29901478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
29911478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume1\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
29921478.9c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\shell32.dll
29931478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
29941478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
29951478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
29961478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
29971478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
29981478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
29991478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
30001478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
30011478.9c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ws2_32.dll
30021478.9c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\atiadlxx.dll (Input=atiadlxx.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c0984:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
30031478.9c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\atiadlxx.dll
30041478.9c8: supR3HardenedDllNotificationCallback: load 6dc20000 LB 0x00062000 C:\Windows\system32\atiadlxx.dll [fFlags=0x0]
30051478.9c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\atiadlxx.dll
30061478.9c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\wsock32.dll
30071478.9c8: supR3HardenedDllNotificationCallback: load 75b00000 LB 0x00007000 C:\Windows\system32\WSOCK32.dll [fFlags=0x0]
30081478.9c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\wsock32.dll
30091478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6dc20000 'C:\Windows\system32\atiadlxx.dll'
30101478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77bd0000 'C:\Windows\system32\gdi32.dll'
30111478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77190000 'C:\Windows\system32\USER32.DLL'
30121478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77190000 'C:\Windows\system32\USER32.DLL'
30131478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77190000 'C:\Windows\system32\USER32.DLL'
30141478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77190000 'C:\Windows\system32\USER32.DLL'
30151478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77190000 'C:\Windows\system32\USER32.DLL'
30161478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77190000 'C:\Windows\system32\USER32.DLL'
30171478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77190000 'C:\Windows\system32\USER32.DLL'
30181478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77190000 'C:\Windows\system32\USER32.DLL'
30191478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77190000 'C:\Windows\system32\USER32.DLL'
30201478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77190000 'C:\Windows\system32\USER32.DLL'
30211478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77190000 'C:\Windows\system32\USER32.DLL'
30221478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77190000 'C:\Windows\system32\USER32.DLL'
30231478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77bd0000 'C:\Windows\system32\gdi32.dll'
30241478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77bd0000 'C:\Windows\system32\gdi32.dll'
30251478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77bd0000 'C:\Windows\system32\gdi32.dll'
30261478.9c8: \Device\HarddiskVolume1\Windows\System32\atigktxx.dll: Owner is administrators group.
30271478.9c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000d04 pwszName=\Device\HarddiskVolume1\Windows\System32\atigktxx.dll
30281478.9c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
30291478.9c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
30301478.9c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=56EBCF42541BF6BB9018C654ABAD26EFD910D0F7
30311478.9c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x47f; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem2.CAT'; file='\Device\HarddiskVolume1\Windows\System32\atigktxx.dll'
30321478.9c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
30331478.9c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
30341478.9c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
30351478.9c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcrt.dll'.
30361478.9c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'version.dll'.
30371478.9c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\atigktxx.dll) WinVerifyTrust
30381478.9c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\atigktxx.dll
30391478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'version.dll'...
30401478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'version.dll' -> '\Device\HarddiskVolume1\Windows\System32\version.dll' [rcNtRedir=0xc0150008]
30411478.9c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\version.dll
30421478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
30431478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
30441478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
30451478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
30461478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
30471478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
30481478.9c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\atigktxx.dll (Input=atigktxx.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c0984:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
30491478.9c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\atigktxx.dll
30501478.9c8: supR3HardenedDllNotificationCallback: load 74aa0000 LB 0x0000b000 C:\Windows\system32\atigktxx.dll [fFlags=0x0]
30511478.9c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\atigktxx.dll
30521478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=74aa0000 'C:\Windows\system32\atigktxx.dll'
30531478.9c8: \Device\HarddiskVolume1\Windows\System32\aticfx32.dll: Owner is administrators group.
30541478.9c8: supR3HardNtViCallWinVerifyTrust: WinVerifyTrust failed with 0x800b010a (CERT_E_CHAINING) on '\Device\HarddiskVolume1\Windows\System32\aticfx32.dll'
30551478.9c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000d08 pwszName=\Device\HarddiskVolume1\Windows\System32\aticfx32.dll
30561478.9c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
30571478.9c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
30581478.9c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=ECEEF84C8C9EF7243B7B94EB76F26F52D85109D1
30591478.9c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x47f; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem2.CAT'; file='\Device\HarddiskVolume1\Windows\System32\aticfx32.dll'
30601478.9c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (was CERT_E_CHAINING)
30611478.9c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
30621478.9c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
30631478.9c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\aticfx32.dll) WinVerifyTrust
30641478.9c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\aticfx32.dll
30651478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
30661478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
30671478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
30681478.9c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
30691478.9c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\aticfx32.dll (Input=aticfx32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c0984:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
30701478.9c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\aticfx32.dll
30711478.9c8: supR3HardenedDllNotificationCallback: load 6ef00000 LB 0x000e6000 C:\Windows\system32\aticfx32.dll [fFlags=0x0]
30721478.9c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\aticfx32.dll
30731478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6ef00000 'C:\Windows\system32\aticfx32.dll'
30741478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77bd0000 'C:\Windows\system32\gdi32.dll'
30751478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77190000 'C:\Windows\system32\USER32.DLL'
30761478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77190000 'C:\Windows\system32\USER32.DLL'
30771478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77bd0000 'C:\Windows\system32\gdi32.dll'
30781478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77190000 'C:\Windows\system32\USER32.DLL'
30791478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77190000 'C:\Windows\system32\USER32.DLL'
30801478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77bd0000 'C:\Windows\system32\gdi32.dll'
30811478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77bd0000 'C:\Windows\system32\gdi32.dll'
30821478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77190000 'C:\Windows\system32\USER32.DLL'
30831478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77190000 'C:\Windows\system32\USER32.DLL'
30841478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77bd0000 'C:\Windows\system32\gdi32.dll'
30851478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77190000 'C:\Windows\system32\USER32.DLL'
30861478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77190000 'C:\Windows\system32\USER32.DLL'
30871478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77bd0000 'C:\Windows\system32\gdi32.dll'
30881478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77bd0000 'C:\Windows\system32\gdi32.dll'
30891478.9c8: supR3HardenedDllNotificationCallback: Unload 74aa0000 LB 0x0000b000 C:\Windows\system32\atigktxx.dll [flags=0x0]
30901478.9c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\atigktxx.dll
30911478.9c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\atigktxx.dll (Input=atigktxx.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c0984:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
30921478.9c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\atigktxx.dll
30931478.9c8: supR3HardenedDllNotificationCallback: load 714a0000 LB 0x0000b000 C:\Windows\system32\atigktxx.dll [fFlags=0x0]
30941478.9c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\atigktxx.dll
30951478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=714a0000 'C:\Windows\system32\atigktxx.dll'
30961478.9c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\aticfx32.dll
30971478.9c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\aticfx32.dll (Input=aticfx32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c0984:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
30981478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6ef00000 'C:\Windows\system32\aticfx32.dll'
30991478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77190000 'C:\Windows\system32\USER32.DLL'
31001478.9c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\user32.dll
31011478.9c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\USER32.DLL (Input=USER32.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c0984:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
31021478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77190000 'C:\Windows\system32\USER32.DLL'
31031478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77190000 'C:\Windows\system32\USER32.DLL'
31041478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77190000 'C:\Windows\system32\USER32.DLL'
31051478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77bd0000 'C:\Windows\system32\gdi32.dll'
31061478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77bd0000 'C:\Windows\system32\gdi32.dll'
31071478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77190000 'C:\Windows\system32\USER32.DLL'
31081478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77190000 'C:\Windows\system32\USER32.DLL'
31091478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77190000 'C:\Windows\system32\USER32.DLL'
31101478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77190000 'C:\Windows\system32\USER32.DLL'
31111478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77bd0000 'C:\Windows\system32\gdi32.dll'
31121478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77bd0000 'C:\Windows\system32\gdi32.dll'
31131478.9c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\opengl32.dll
31141478.9c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\OPENGL32.DLL (Input=OPENGL32.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c0984:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
31151478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6e6f0000 'C:\Windows\system32\OPENGL32.DLL'
31161478.9c8: supR3HardenedMonitor_LdrLoadDll: error opening 'C:\Windows\system32\perf.dll': 0 (NtPath=\??\C:\Windows\system32\perf.dll; Input=perf.dll; rcNtGetDll=0xc0000135
31171478.9c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\perf.dll (Input=perf.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c0984:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
31181478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000135 'C:\Windows\system32\perf.dll'
31191478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6e6f0000 'C:\Windows\system32\OPENGL32.dll'
31201478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6e6f0000 'C:\Windows\system32\OPENGL32.dll'
31211478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6e6f0000 'C:\Windows\system32\OPENGL32.dll'
31221478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6e6f0000 'C:\Windows\system32\OPENGL32.dll'
31231478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6e6f0000 'C:\Windows\system32\OPENGL32.dll'
31241478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6e6f0000 'C:\Windows\system32\OPENGL32.dll'
31251478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6e6f0000 'C:\Windows\system32\OPENGL32.dll'
31261478.9c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\opengl32.dll
31271478.9c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\OPENGL32.dll (Input=OPENGL32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c0984:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
31281478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6e6f0000 'C:\Windows\system32\OPENGL32.dll'
31291478.92c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
31301478.92c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
31311478.92c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
31321478.92c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\VirtualBox\VBoxGuestPropSvc.dll) WinVerifyTrust
31331478.92c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxGuestPropSvc.dll
31341478.92c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
31351478.92c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
31361478.92c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
31371478.92c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
31381478.92c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\msvcp100.dll
31391478.92c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
31401478.92c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
31411478.92c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\VirtualBox\VBoxGuestPropSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c0984:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
31421478.92c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxGuestPropSvc.dll
31431478.92c: supR3HardenedDllNotificationCallback: load 710b0000 LB 0x0000c000 C:\Program Files\VirtualBox\VBoxGuestPropSvc.DLL [fFlags=0x0]
31441478.92c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxGuestPropSvc.dll
31451478.92c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=710b0000 'C:\Program Files\VirtualBox\VBoxGuestPropSvc.DLL'
31461478.151c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
31471478.151c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
31481478.151c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
31491478.151c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\VirtualBox\VBoxGuestControlSvc.dll) WinVerifyTrust
31501478.151c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxGuestControlSvc.dll
31511478.151c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
31521478.151c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
31531478.151c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
31541478.151c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
31551478.151c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
31561478.151c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
31571478.151c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\VirtualBox\VBoxGuestControlSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c0984:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
31581478.151c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxGuestControlSvc.dll
31591478.151c: supR3HardenedDllNotificationCallback: load 70ff0000 LB 0x0000c000 C:\Program Files\VirtualBox\VBoxGuestControlSvc.DLL [fFlags=0x0]
31601478.151c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxGuestControlSvc.dll
31611478.151c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=70ff0000 'C:\Program Files\VirtualBox\VBoxGuestControlSvc.DLL'
31621478.12f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\shell32.dll
31631478.12f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32/Shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c0984:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
31641478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=761b0000 'C:\Windows\system32/Shell32.dll'
31651478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=778c0000 'C:\Windows\system32\ole32.dll'
31661478.12f8: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=008c0984:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
31671478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77eb0000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
31681478.12f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\profapi.dll
31691478.12f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\profapi.dll (Input=profapi.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c0984:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
31701478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=75d40000 'C:\Windows\system32\profapi.dll'
31711478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
31721478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
31731478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
31741478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
31751478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ole32.dll'.
31761478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'oleaut32.dll'.
31771478.12f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.x86\VBoxHostWebcam.dll) WinVerifyTrust
31781478.12f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.x86\VBoxHostWebcam.dll
31791478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
31801478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume1\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
31811478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
31821478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
31831478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
31841478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
31851478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
31861478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
31871478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
31881478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
31891478.12f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxVMM.dll
31901478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
31911478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
31921478.12f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.x86/VBoxHostWebcam.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c0984:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
31931478.12f8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.x86\VBoxHostWebcam.dll
31941478.12f8: supR3HardenedDllNotificationCallback: load 6ee90000 LB 0x0002d000 C:\Program Files\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.x86\VBoxHostWebcam.DLL [fFlags=0x0]
31951478.12f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.x86\VBoxHostWebcam.dll
31961478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6ee90000 'C:\Program Files\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.x86/VBoxHostWebcam.DLL'
31971478.12f8: supR3HardenedDllNotificationCallback: Unload 6ee90000 LB 0x0002d000 C:\Program Files\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.x86\VBoxHostWebcam.DLL [flags=0x0]
31981478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'vboxrt.dll'.
31991478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
32001478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcrt.dll'.
32011478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcrt.dll'.
32021478.12f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\VirtualBox\VBoxREM64.dll) WinVerifyTrust
32031478.12f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxREM64.dll
32041478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
32051478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
32061478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
32071478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
32081478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
32091478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
32101478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
32111478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
32121478.12f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\VirtualBox\VBoxREM64.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c0984:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
32131478.12f8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxREM64.dll
32141478.12f8: supR3HardenedDllNotificationCallback: load 6a020000 LB 0x0014c000 C:\Program Files\VirtualBox\VBoxREM64.DLL [fFlags=0x0]
32151478.12f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxREM64.dll
32161478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6a020000 'C:\Program Files\VirtualBox\VBoxREM64.DLL'
32171478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
32181478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
32191478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
32201478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vboxddu.dll'.
32211478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'vboxdd2.dll'.
32221478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
32231478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'setupapi.dll'.
32241478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'ws2_32.dll'.
32251478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'ole32.dll'.
32261478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'iphlpapi.dll'.
32271478.12f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\VirtualBox\VBoxDD.dll) WinVerifyTrust
32281478.12f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxDD.dll
32291478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'iphlpapi.dll'...
32301478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'iphlpapi.dll' -> '\Device\HarddiskVolume1\Windows\System32\iphlpapi.dll' [rcNtRedir=0xc0150008]
32311478.12f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\IPHLPAPI.DLL
32321478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
32331478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
32341478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
32351478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
32361478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
32371478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume1\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
32381478.12f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\setupapi.dll
32391478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
32401478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
32411478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxdd2.dll'...
32421478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxdd2.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\vboxdd2.dll' [rcNtRedir=0xc0150008]
32431478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
32441478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
32451478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
32461478.12f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\VirtualBox\VBoxDD2.dll) WinVerifyTrust
32471478.12f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxDD2.dll
32481478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxddu.dll'...
32491478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxddu.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\vboxddu.dll' [rcNtRedir=0xc0150008]
32501478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
32511478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
32521478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
32531478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'setupapi.dll'.
32541478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'newdev.dll'.
32551478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'advapi32.dll'.
32561478.12f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\VirtualBox\VBoxDDU.dll) WinVerifyTrust
32571478.12f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxDDU.dll
32581478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
32591478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
32601478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
32611478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
32621478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
32631478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
32641478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
32651478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
32661478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'newdev.dll'...
32671478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'newdev.dll' -> '\Device\HarddiskVolume1\Windows\System32\newdev.dll' [rcNtRedir=0xc0150008]
32681478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000e90 pwszName=\Device\HarddiskVolume1\Windows\System32\newdev.dll
32691478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
32701478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
32711478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=A76062289DF8B2E5D6ADEB5E71265D9C24321CC3
32721478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntph.cat'; file='\Device\HarddiskVolume1\Windows\System32\newdev.dll'
32731478.12f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
32741478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
32751478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
32761478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
32771478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
32781478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'uxtheme.dll'.
32791478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'cfgmgr32.dll'.
32801478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'setupapi.dll'.
32811478.12f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\newdev.dll) WinVerifyTrust
32821478.12f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\newdev.dll
32831478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
32841478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume1\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
32851478.12f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\setupapi.dll
32861478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
32871478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
32881478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
32891478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
32901478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
32911478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
32921478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
32931478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
32941478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
32951478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
32961478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
32971478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
32981478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
32991478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume1\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
33001478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
33011478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume1\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
33021478.12f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\cfgmgr32.dll
33031478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'uxtheme.dll'...
33041478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'uxtheme.dll' -> '\Device\HarddiskVolume1\Windows\System32\uxtheme.dll' [rcNtRedir=0xc0150008]
33051478.12f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\uxtheme.dll
33061478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
33071478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
33081478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
33091478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
33101478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
33111478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
33121478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
33131478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
33141478.12f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\VirtualBox/VBoxDD.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c0984:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
33151478.12f8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxDD.dll
33161478.12f8: supR3HardenedDllNotificationCallback: load 68d10000 LB 0x00864000 C:\Program Files\VirtualBox\VBoxDD.DLL [fFlags=0x0]
33171478.12f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxDD.dll
33181478.12f8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxDDU.dll
33191478.12f8: supR3HardenedDllNotificationCallback: load 6e1e0000 LB 0x0004f000 C:\Program Files\VirtualBox\VBoxDDU.dll [fFlags=0x0]
33201478.12f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxDDU.dll
33211478.12f8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\newdev.dll
33221478.12f8: supR3HardenedDllNotificationCallback: load 72690000 LB 0x0004f000 C:\Windows\system32\newdev.dll [fFlags=0x0]
33231478.12f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\newdev.dll
33241478.12f8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxDD2.dll
33251478.12f8: supR3HardenedDllNotificationCallback: load 6dcc0000 LB 0x00032000 C:\Program Files\VirtualBox\VBoxDD2.dll [fFlags=0x0]
33261478.12f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxDD2.dll
33271478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=68d10000 'C:\Program Files\VirtualBox/VBoxDD.DLL'
33281478.12f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.x86\VBoxHostWebcam.dll
33291478.12f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.x86/VBoxHostWebcam.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c0984:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
33301478.12f8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.x86\VBoxHostWebcam.dll
33311478.12f8: supR3HardenedDllNotificationCallback: load 6dc90000 LB 0x0002d000 C:\Program Files\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.x86\VBoxHostWebcam.DLL [fFlags=0x0]
33321478.12f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.x86\VBoxHostWebcam.dll
33331478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6dc90000 'C:\Program Files\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.x86/VBoxHostWebcam.DLL'
33341478.dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=760a0000 'C:\Windows\system32\OLEAUT32.dll'
33351478.12f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxC.dll
33361478.12f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\VirtualBox/VBoxC.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c06b4:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
33371478.12f8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxC.dll
33381478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6cf70000 'C:\Program Files\VirtualBox/VBoxC.DLL'
33391478.12f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxDD2.dll
33401478.12f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\VirtualBox/VBoxDD2.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c06b4:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
33411478.12f8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxDD2.dll
33421478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6dcc0000 'C:\Program Files\VirtualBox/VBoxDD2.DLL'
33431478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
33441478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
33451478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
33461478.12f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.x86\VBoxEhciR3.dll) WinVerifyTrust
33471478.12f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.x86\VBoxEhciR3.dll
33481478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
33491478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
33501478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
33511478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
33521478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
33531478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
33541478.12f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.x86/VBoxEhciR3.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c06b4:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
33551478.12f8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.x86\VBoxEhciR3.dll
33561478.12f8: supR3HardenedDllNotificationCallback: load 6eea0000 LB 0x00015000 C:\Program Files\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.x86\VBoxEhciR3.DLL [fFlags=0x0]
33571478.12f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.x86\VBoxEhciR3.dll
33581478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6eea0000 'C:\Program Files\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.x86/VBoxEhciR3.DLL'
33591478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
33601478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
33611478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
33621478.12f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.x86\VBoxUsbCardReaderR3.dll) WinVerifyTrust
33631478.12f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.x86\VBoxUsbCardReaderR3.dll
33641478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
33651478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
33661478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
33671478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
33681478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
33691478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
33701478.12f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.x86/VBoxUsbCardReaderR3.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c06b4:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
33711478.12f8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.x86\VBoxUsbCardReaderR3.dll
33721478.12f8: supR3HardenedDllNotificationCallback: load 70590000 LB 0x0000f000 C:\Program Files\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.x86\VBoxUsbCardReaderR3.DLL [fFlags=0x0]
33731478.12f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.x86\VBoxUsbCardReaderR3.dll
33741478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=70590000 'C:\Program Files\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.x86/VBoxUsbCardReaderR3.DLL'
33751478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
33761478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
33771478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
33781478.12f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.x86\VBoxUsbWebcamR3.dll) WinVerifyTrust
33791478.12f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.x86\VBoxUsbWebcamR3.dll
33801478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
33811478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
33821478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
33831478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
33841478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
33851478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
33861478.12f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.x86/VBoxUsbWebcamR3.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c06b4:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
33871478.12f8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.x86\VBoxUsbWebcamR3.dll
33881478.12f8: supR3HardenedDllNotificationCallback: load 70550000 LB 0x00010000 C:\Program Files\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.x86\VBoxUsbWebcamR3.DLL [fFlags=0x0]
33891478.12f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.x86\VBoxUsbWebcamR3.dll
33901478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=70550000 'C:\Program Files\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.x86/VBoxUsbWebcamR3.DLL'
33911478.f64: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
33921478.f64: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
33931478.f64: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
33941478.f64: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\VirtualBox\VBoxSharedFolders.dll) WinVerifyTrust
33951478.f64: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxSharedFolders.dll
33961478.f64: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
33971478.f64: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
33981478.f64: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
33991478.f64: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
34001478.f64: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
34011478.f64: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
34021478.f64: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\VirtualBox\VBoxSharedFolders.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c06b4:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
34031478.f64: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxSharedFolders.dll
34041478.f64: supR3HardenedDllNotificationCallback: load 6fce0000 LB 0x0000c000 C:\Program Files\VirtualBox\VBoxSharedFolders.DLL [fFlags=0x0]
34051478.f64: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\VBoxSharedFolders.dll
34061478.f64: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6fce0000 'C:\Program Files\VirtualBox\VBoxSharedFolders.DLL'
34071478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
34081478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
34091478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
34101478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'gdi32.dll'.
34111478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'advapi32.dll'.
34121478.12f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.x86\VDPluginCrypt.dll) WinVerifyTrust
34131478.12f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.x86\VDPluginCrypt.dll
34141478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
34151478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
34161478.12f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\advapi32.dll
34171478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
34181478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
34191478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
34201478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
34211478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
34221478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
34231478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
34241478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
34251478.12f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.x86/VDPluginCrypt.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c06b4:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
34261478.12f8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.x86\VDPluginCrypt.dll
34271478.12f8: supR3HardenedDllNotificationCallback: load 6e140000 LB 0x00093000 C:\Program Files\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.x86\VDPluginCrypt.DLL [fFlags=0x0]
34281478.12f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.x86\VDPluginCrypt.dll
34291478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6e140000 'C:\Program Files\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.x86/VDPluginCrypt.DLL'
34301478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000f3c pwszName=\Device\HarddiskVolume1\Windows\System32\dsound.dll
34311478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
34321478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
34331478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=21B33CF8A06799AF36E2D0016F2A5AC0D97B1C05
34341478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\WinEmb-AV-Core~31bf3856ad364e35~x86~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\dsound.dll'
34351478.12f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
34361478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
34371478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
34381478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
34391478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ole32.dll'.
34401478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'winmm.dll'.
34411478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'powrprof.dll'.
34421478.12f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\dsound.dll) WinVerifyTrust
34431478.12f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\dsound.dll
34441478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'powrprof.dll'...
34451478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'powrprof.dll' -> '\Device\HarddiskVolume1\Windows\System32\powrprof.dll' [rcNtRedir=0xc0150008]
34461478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000f48 pwszName=\Device\HarddiskVolume1\Windows\System32\powrprof.dll
34471478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
34481478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
34491478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=7DE33595D32B0157063D86824D96D15D1D9B85F8
34501478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume1\Windows\System32\powrprof.dll'
34511478.12f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
34521478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
34531478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'rpcrt4.dll'.
34541478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'setupapi.dll'.
34551478.12f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\powrprof.dll) WinVerifyTrust
34561478.12f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\powrprof.dll
34571478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
34581478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume1\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
34591478.12f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\winmm.dll
34601478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
34611478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
34621478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
34631478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
34641478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
34651478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
34661478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
34671478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
34681478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
34691478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume1\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
34701478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
34711478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
34721478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
34731478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
34741478.12f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32/dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c06b4:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
34751478.12f8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\dsound.dll
34761478.12f8: supR3HardenedDllNotificationCallback: load 6cdf0000 LB 0x00072000 C:\Windows\system32\dsound.dll [fFlags=0x0]
34771478.12f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\dsound.dll
34781478.12f8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\powrprof.dll
34791478.12f8: supR3HardenedDllNotificationCallback: load 71c90000 LB 0x00025000 C:\Windows\system32\POWRPROF.dll [fFlags=0x0]
34801478.12f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\powrprof.dll
34811478.12f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\dsound.dll
34821478.12f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c05c4:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
34831478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6cdf0000 'C:\Windows\system32\dsound.dll'
34841478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6cdf0000 'C:\Windows\system32/dsound.dll'
34851478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000f6c pwszName=\Device\HarddiskVolume1\Windows\System32\MMDevAPI.dll
34861478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
34871478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
34881478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=6A16340019E7F842E4BF56032BF9419CEB94E308
34891478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-EmbeddedCore-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\MMDevAPI.dll'
34901478.12f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
34911478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
34921478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'user32.dll'.
34931478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'rpcrt4.dll'.
34941478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'propsys.dll'.
34951478.12f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\MMDevAPI.dll) WinVerifyTrust
34961478.12f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\MMDevAPI.dll
34971478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'propsys.dll'...
34981478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'propsys.dll' -> '\Device\HarddiskVolume1\Windows\System32\propsys.dll' [rcNtRedir=0xc0150008]
34991478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000f50 pwszName=\Device\HarddiskVolume1\Windows\System32\propsys.dll
35001478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
35011478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
35021478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=39F69E4150BBCFAB9B7D272CB7F7566E77AF0F26
35031478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-EmbeddedCore-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\propsys.dll'
35041478.12f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
35051478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
35061478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ole32.dll'.
35071478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'oleaut32.dll'.
35081478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'user32.dll'.
35091478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'rpcrt4.dll'.
35101478.12f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\propsys.dll) WinVerifyTrust
35111478.12f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\propsys.dll
35121478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
35131478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
35141478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
35151478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
35161478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
35171478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
35181478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
35191478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
35201478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
35211478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
35221478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
35231478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume1\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
35241478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
35251478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
35261478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
35271478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
35281478.12f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\MMDevApi.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008b5fec:C:\Windows\System32;C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
35291478.12f8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\MMDevAPI.dll
35301478.12f8: supR3HardenedDllNotificationCallback: load 74530000 LB 0x00039000 C:\Windows\System32\MMDevApi.dll [fFlags=0x0]
35311478.12f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\MMDevAPI.dll
35321478.12f8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\propsys.dll
35331478.12f8: supR3HardenedDllNotificationCallback: load 74930000 LB 0x000f5000 C:\Windows\System32\PROPSYS.dll [fFlags=0x0]
35341478.12f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\propsys.dll
35351478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77820000 'C:\Windows\system32\ADVAPI32.dll'
35361478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=74530000 'C:\Windows\System32\MMDevApi.dll'
35371478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=778c0000 'C:\Windows\system32\ole32.dll'
35381478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77a30000 'C:\Windows\system32\SETUPAPI.dll'
35391478.12f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\shlwapi.dll
35401478.12f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\SHLWAPI.dll (Input=SHLWAPI.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c05c4:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
35411478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77f00000 'C:\Windows\system32\SHLWAPI.dll'
35421478.12f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\MMDevAPI.dll
35431478.12f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\MMDEVAPI.DLL (Input=MMDEVAPI.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c05c4:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
35441478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=74530000 'C:\Windows\system32\MMDEVAPI.DLL'
35451478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=778c0000 'C:\Windows\system32\ole32.dll'
35461478.12f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\winmm.dll
35471478.12f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\winmm.dll (Input=winmm.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c06b4:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
35481478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=72eb0000 'C:\Windows\system32\winmm.dll'
35491478.12f8: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-Management-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=008c06b4:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
35501478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77eb0000 'API-MS-WIN-Service-Management-L1-1-0.dll'
35511478.12f8: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-winsvc-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=008c06b4:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
35521478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77eb0000 'API-MS-WIN-Service-winsvc-L1-1-0.dll'
35531478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77260000 'C:\Windows\system32\RPCRT4.dll'
35541478.12f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\MMDevAPI.dll
35551478.12f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\MMDevAPI.DLL (Input=MMDevAPI.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c06b4:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
35561478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=74530000 'C:\Windows\system32\MMDevAPI.DLL'
35571478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000f98 pwszName=\Device\HarddiskVolume1\Windows\System32\wdmaud.drv
35581478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
35591478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
35601478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=E4254EC416559B4A64F5A9B6B15BF9ABA3A523A8
35611478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\WinEmb-AV-Core~31bf3856ad364e35~x86~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\wdmaud.drv'
35621478.12f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
35631478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
35641478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
35651478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ole32.dll'.
35661478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
35671478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'winmm.dll'.
35681478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ksuser.dll'.
35691478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'mmdevapi.dll'.
35701478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'avrt.dll'.
35711478.12f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\wdmaud.drv) WinVerifyTrust
35721478.12f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\wdmaud.drv
35731478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'avrt.dll'...
35741478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'avrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\avrt.dll' [rcNtRedir=0xc0150008]
35751478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000f68 pwszName=\Device\HarddiskVolume1\Windows\System32\avrt.dll
35761478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
35771478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
35781478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=4DE9938619CA34D8AB667314479368251A80309D
35791478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\WinEmb-AV-Core~31bf3856ad364e35~x86~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\avrt.dll'
35801478.12f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
35811478.12f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\avrt.dll) WinVerifyTrust
35821478.12f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\avrt.dll
35831478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mmdevapi.dll'...
35841478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'mmdevapi.dll' -> '\Device\HarddiskVolume1\Windows\System32\mmdevapi.dll' [rcNtRedir=0xc0150008]
35851478.12f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\MMDevAPI.dll
35861478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ksuser.dll'...
35871478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ksuser.dll' -> '\Device\HarddiskVolume1\Windows\System32\ksuser.dll' [rcNtRedir=0xc0150008]
35881478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000fa8 pwszName=\Device\HarddiskVolume1\Windows\System32\ksuser.dll
35891478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
35901478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
35911478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=27461195FDA1028613EB103E644A96D64E32EC75
35921478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\WinEmb-AV-Core~31bf3856ad364e35~x86~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\ksuser.dll'
35931478.12f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
35941478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
35951478.12f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\ksuser.dll) WinVerifyTrust
35961478.12f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\ksuser.dll
35971478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
35981478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume1\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
35991478.12f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\winmm.dll
36001478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
36011478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
36021478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
36031478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
36041478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
36051478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
36061478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
36071478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
36081478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
36091478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
36101478.12f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c06b4:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
36111478.12f8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\wdmaud.drv
36121478.12f8: supR3HardenedDllNotificationCallback: load 724f0000 LB 0x00030000 C:\Windows\system32\wdmaud.drv [fFlags=0x0]
36131478.12f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\wdmaud.drv
36141478.12f8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ksuser.dll
36151478.12f8: supR3HardenedDllNotificationCallback: load 718f0000 LB 0x00004000 C:\Windows\system32\ksuser.dll [fFlags=0x0]
36161478.12f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ksuser.dll
36171478.12f8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\avrt.dll
36181478.12f8: supR3HardenedDllNotificationCallback: load 724d0000 LB 0x00007000 C:\Windows\system32\AVRT.dll [fFlags=0x0]
36191478.12f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\avrt.dll
36201478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=724f0000 'C:\Windows\system32\wdmaud.drv'
36211478.12f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\wdmaud.drv
36221478.12f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c06b4:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
36231478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=724f0000 'C:\Windows\system32\wdmaud.drv'
36241478.12f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\wdmaud.drv
36251478.12f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c06b4:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
36261478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=724f0000 'C:\Windows\system32\wdmaud.drv'
36271478.12f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\wdmaud.drv
36281478.12f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c05c4:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
36291478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=724f0000 'C:\Windows\system32\wdmaud.drv'
36301478.12f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\wdmaud.drv
36311478.12f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c05c4:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
36321478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=724f0000 'C:\Windows\system32\wdmaud.drv'
36331478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000fac pwszName=\Device\HarddiskVolume1\Windows\System32\AudioSes.dll
36341478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
36351478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
36361478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=29EB271C656F27DF10164B84692A17D171E07B18
36371478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_153_for_KB3033929~31bf3856ad364e35~x86~~6.1.1.1.cat'; file='\Device\HarddiskVolume1\Windows\System32\AudioSes.dll'
36381478.12f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
36391478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
36401478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
36411478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ole32.dll'.
36421478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
36431478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
36441478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
36451478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'mmdevapi.dll'.
36461478.12f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\AudioSes.dll) WinVerifyTrust
36471478.12f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\AudioSes.dll
36481478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mmdevapi.dll'...
36491478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'mmdevapi.dll' -> '\Device\HarddiskVolume1\Windows\System32\mmdevapi.dll' [rcNtRedir=0xc0150008]
36501478.12f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\MMDevAPI.dll
36511478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
36521478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
36531478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
36541478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
36551478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
36561478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume1\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
36571478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
36581478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
36591478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
36601478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
36611478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
36621478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
36631478.12f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\AUDIOSES.DLL (Input=AUDIOSES.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c0984:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
36641478.12f8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\AudioSes.dll
36651478.12f8: supR3HardenedDllNotificationCallback: load 73300000 LB 0x00036000 C:\Windows\system32\AUDIOSES.DLL [fFlags=0x0]
36661478.12f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\AudioSes.dll
36671478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=73300000 'C:\Windows\system32\AUDIOSES.DLL'
36681478.12f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\wdmaud.drv
36691478.12f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c0984:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
36701478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=724f0000 'C:\Windows\system32\wdmaud.drv'
36711478.12f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\wdmaud.drv
36721478.12f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008bfebc:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
36731478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=724f0000 'C:\Windows\system32\wdmaud.drv'
36741478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=724f0000 'C:\Windows\system32\wdmaud.drv'
36751478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=724f0000 'C:\Windows\system32\wdmaud.drv'
36761478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=724f0000 'C:\Windows\system32\wdmaud.drv'
36771478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=724f0000 'C:\Windows\system32\wdmaud.drv'
36781478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000fcc pwszName=\Device\HarddiskVolume1\Windows\System32\msacm32.drv
36791478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
36801478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
36811478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=A5713EF7E40CCD29B21B2EB6B66D2F9430B21CEA
36821478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume1\Windows\System32\msacm32.drv'
36831478.12f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
36841478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
36851478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
36861478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'winmm.dll'.
36871478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msacm32.dll'.
36881478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'mmdevapi.dll'.
36891478.12f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\msacm32.drv) WinVerifyTrust
36901478.12f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\msacm32.drv
36911478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mmdevapi.dll'...
36921478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'mmdevapi.dll' -> '\Device\HarddiskVolume1\Windows\System32\mmdevapi.dll' [rcNtRedir=0xc0150008]
36931478.12f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\MMDevAPI.dll
36941478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msacm32.dll'...
36951478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msacm32.dll' -> '\Device\HarddiskVolume1\Windows\System32\msacm32.dll' [rcNtRedir=0xc0150008]
36961478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000fe0 pwszName=\Device\HarddiskVolume1\Windows\System32\msacm32.dll
36971478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
36981478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
36991478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=89F1B652F75B0ADD8E12409835E5A467A4A5132A
37001478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume1\Windows\System32\msacm32.dll'
37011478.12f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
37021478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
37031478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
37041478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
37051478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
37061478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'winmm.dll'.
37071478.12f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\msacm32.dll) WinVerifyTrust
37081478.12f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\msacm32.dll
37091478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
37101478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume1\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
37111478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
37121478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
37131478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
37141478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
37151478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
37161478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume1\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
37171478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
37181478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
37191478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
37201478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
37211478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
37221478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
37231478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
37241478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
37251478.12f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0256e724:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
37261478.12f8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\msacm32.drv
37271478.12f8: supR3HardenedDllNotificationCallback: load 72590000 LB 0x00008000 C:\Windows\system32\msacm32.drv [fFlags=0x0]
37281478.12f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\msacm32.drv
37291478.12f8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\msacm32.dll
37301478.12f8: supR3HardenedDllNotificationCallback: load 71f70000 LB 0x00014000 C:\Windows\system32\MSACM32.dll [fFlags=0x0]
37311478.12f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\msacm32.dll
37321478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=72590000 'C:\Windows\system32\msacm32.drv'
37331478.12f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\msacm32.drv
37341478.12f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0256e724:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
37351478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=72590000 'C:\Windows\system32\msacm32.drv'
37361478.12f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\msacm32.drv
37371478.12f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0256e724:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
37381478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=72590000 'C:\Windows\system32\msacm32.drv'
37391478.12f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\msacm32.drv
37401478.12f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0256e724:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
37411478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=72590000 'C:\Windows\system32\msacm32.drv'
37421478.12f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\msacm32.drv
37431478.12f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0256e724:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
37441478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=72590000 'C:\Windows\system32\msacm32.drv'
37451478.12f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\msacm32.drv
37461478.12f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0256e724:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
37471478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=72590000 'C:\Windows\system32\msacm32.drv'
37481478.12f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\msacm32.drv
37491478.12f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0256e724:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
37501478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=72590000 'C:\Windows\system32\msacm32.drv'
37511478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=72590000 'C:\Windows\system32\msacm32.drv'
37521478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=72590000 'C:\Windows\system32\msacm32.drv'
37531478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=72590000 'C:\Windows\system32\msacm32.drv'
37541478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000fd8 pwszName=\Device\HarddiskVolume1\Windows\System32\midimap.dll
37551478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
37561478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
37571478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=5036FF0D7DA44D9D1865A8199BB777EB13FF84EE
37581478.12f8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume1\Windows\System32\midimap.dll'
37591478.12f8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
37601478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
37611478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
37621478.12f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'winmm.dll'.
37631478.12f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\midimap.dll) WinVerifyTrust
37641478.12f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\midimap.dll
37651478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
37661478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume1\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
37671478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
37681478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
37691478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
37701478.12f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
37711478.12f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll
37721478.12f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0256e724:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
37731478.12f8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\midimap.dll
37741478.12f8: supR3HardenedDllNotificationCallback: load 72580000 LB 0x00007000 C:\Windows\system32\midimap.dll [fFlags=0x0]
37751478.12f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\midimap.dll
37761478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=72580000 'C:\Windows\system32\midimap.dll'
37771478.12f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\midimap.dll
37781478.12f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0256e724:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
37791478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=72580000 'C:\Windows\system32\midimap.dll'
37801478.12f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\midimap.dll
37811478.12f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0256e724:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
37821478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=72580000 'C:\Windows\system32\midimap.dll'
37831478.12f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\midimap.dll
37841478.12f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0256e724:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
37851478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=72580000 'C:\Windows\system32\midimap.dll'
37861478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=72eb0000 'C:\Windows\system32\winmm.dll'
37871478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=72eb0000 'C:\Windows\system32\winmm.dll'
37881478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=72eb0000 'C:\Windows\system32\winmm.dll'
37891478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=778c0000 'C:\Windows\system32\ole32.dll'
37901478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=72eb0000 'C:\Windows\system32\winmm.dll'
37911478.12f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\winmm.dll
37921478.12f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\winmm.dll (Input=winmm.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0256e724:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
37931478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=72eb0000 'C:\Windows\system32\winmm.dll'
37941478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=72eb0000 'C:\Windows\system32\winmm.dll'
37951478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=72eb0000 'C:\Windows\system32\winmm.dll'
37961478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=72eb0000 'C:\Windows\system32\winmm.dll'
37971478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=72eb0000 'C:\Windows\system32\winmm.dll'
37981478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=72eb0000 'C:\Windows\system32\winmm.dll'
37991478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=72eb0000 'C:\Windows\system32\winmm.dll'
38001478.12f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\dsound.dll
38011478.12f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008b5fec:C:\Windows\System32;C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
38021478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6cdf0000 'C:\Windows\System32\dsound.dll'
38031478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=72eb0000 'C:\Windows\system32\winmm.dll'
38041478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=72eb0000 'C:\Windows\system32\winmm.dll'
38051478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=72eb0000 'C:\Windows\system32\winmm.dll'
38061478.de0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\AudioSes.dll
38071478.de0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\audioses.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008b5fec:C:\Windows\System32;C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
38081478.de0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=73300000 'C:\Windows\System32\audioses.dll'
38091478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=72eb0000 'C:\Windows\system32\winmm.dll'
38101478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=72eb0000 'C:\Windows\system32\winmm.dll'
38111478.12f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\kernel32.dll
38121478.12f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32/kernel32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0256e904:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
38131478.12f8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\kernel32.dll
38141478.12f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77c80000 'C:\Windows\system32/kernel32.dll'
38151478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000b20 pwszName=\Device\HarddiskVolume1\Windows\System32\mscms.dll
38161478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
38171478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
38181478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\wintrust.dll
38191478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\WINTRUST.DLL (Input=WINTRUST.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0256eb5c:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
38201478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=75f10000 'C:\Windows\system32\WINTRUST.DLL'
38211478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\crypt32.dll
38221478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPT32.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=0256eb5c:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
38231478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=75d90000 'C:\Windows\system32\CRYPT32.dll'
38241478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=5F71A76E21B72F2699E1D2DFFD9B5F7E0901418C
38251478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=74310000 'C:\Windows\system32\cryptnet.dll'
38261478.1738: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Embedded-Features-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\mscms.dll'
38271478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
38281478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
38291478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'userenv.dll'.
38301478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
38311478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
38321478.1738: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\mscms.dll) WinVerifyTrust
38331478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\mscms.dll
38341478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
38351478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
38361478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
38371478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
38381478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'userenv.dll'...
38391478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'userenv.dll' -> '\Device\HarddiskVolume1\Windows\System32\userenv.dll' [rcNtRedir=0xc0150008]
38401478.1738: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\userenv.dll
38411478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
38421478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
38431478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\mscms.dll (Input=mscms.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c0024:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
38441478.1738: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\mscms.dll
38451478.1738: supR3HardenedDllNotificationCallback: load 71030000 LB 0x00079000 C:\Windows\system32\mscms.dll [fFlags=0x0]
38461478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\mscms.dll
38471478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=71030000 'C:\Windows\system32\mscms.dll'
38481478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000113c pwszName=\Device\HarddiskVolume1\Windows\System32\icm32.dll
38491478.1738: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00826fb8
38501478.1738: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00826fb8
38511478.1738: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=6F1E50BC8E3F6E3FC4EF4F36F1F082B464110CD9
38521478.1738: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Embedded-Features-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\icm32.dll'
38531478.1738: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
38541478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
38551478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'mscms.dll'.
38561478.1738: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
38571478.1738: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\icm32.dll) WinVerifyTrust
38581478.1738: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\icm32.dll
38591478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
38601478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
38611478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mscms.dll'...
38621478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'mscms.dll' -> '\Device\HarddiskVolume1\Windows\System32\mscms.dll' [rcNtRedir=0xc0150008]
38631478.1738: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\mscms.dll
38641478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
38651478.1738: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
38661478.1738: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\icm32.dll (Input=icm32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c0024:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
38671478.1738: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\icm32.dll
38681478.1738: supR3HardenedDllNotificationCallback: load 6cc90000 LB 0x00038000 C:\Windows\system32\icm32.dll [fFlags=0x0]
38691478.1738: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\icm32.dll
38701478.1738: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6cc90000 'C:\Windows\system32\icm32.dll'
38711478.173c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\avrt.dll
38721478.173c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\avrt.dll (Input=avrt.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=008c0024:C:\Program Files\VirtualBox;C:\Windows\system32 [calling]
38731478.173c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=724d0000 'C:\Windows\system32\avrt.dll'
38741478.f64: supR3HardenedDllNotificationCallback: Unload 6fce0000 LB 0x0000c000 C:\Program Files\VirtualBox\VBoxSharedFolders.DLL [flags=0x0]
38751478.151c: supR3HardenedDllNotificationCallback: Unload 70ff0000 LB 0x0000c000 C:\Program Files\VirtualBox\VBoxGuestControlSvc.DLL [flags=0x0]
38761478.92c: supR3HardenedDllNotificationCallback: Unload 710b0000 LB 0x0000c000 C:\Program Files\VirtualBox\VBoxGuestPropSvc.DLL [flags=0x0]
38771478.9c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6e6f0000 'C:\Windows\system32\OPENGL32.dll'
38781478.9c8: supR3HardenedDllNotificationCallback: Unload 6e2e0000 LB 0x00018000 C:\Program Files\VirtualBox\VBoxOGLhosterrorspu.dll [flags=0x0]
38791478.9c8: supR3HardenedDllNotificationCallback: Unload 6ce70000 LB 0x000f5000 C:\Program Files\VirtualBox\VBoxSharedCrOpenGL.DLL [flags=0x0]
38801478.9c8: supR3HardenedDllNotificationCallback: Unload 705a0000 LB 0x00020000 C:\Program Files\VirtualBox\VBoxOGLrenderspu.dll [flags=0x0]
38811478.9c8: supR3HardenedDllNotificationCallback: Unload 6fa70000 LB 0x00028000 C:\Program Files\VirtualBox\VBoxOGLhostcrutil.dll [flags=0x0]
38821478.14ac: supR3HardenedDllNotificationCallback: Unload 71cc0000 LB 0x0000c000 C:\Program Files\VirtualBox\VBoxDragAndDropSvc.DLL [flags=0x0]
38831478.1374: supR3HardenedDllNotificationCallback: Unload 71ef0000 LB 0x00009000 C:\Program Files\VirtualBox\VBoxSharedClipboard.DLL [flags=0x0]
38841478.12f8: supR3HardenedDllNotificationCallback: Unload 70550000 LB 0x00010000 C:\Program Files\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.x86\VBoxUsbWebcamR3.DLL [flags=0x0]
38851478.12f8: supR3HardenedDllNotificationCallback: Unload 70590000 LB 0x0000f000 C:\Program Files\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.x86\VBoxUsbCardReaderR3.DLL [flags=0x0]
38861478.12f8: supR3HardenedDllNotificationCallback: Unload 6eea0000 LB 0x00015000 C:\Program Files\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.x86\VBoxEhciR3.DLL [flags=0x0]
38871478.12f8: supR3HardenedDllNotificationCallback: Unload 6dc90000 LB 0x0002d000 C:\Program Files\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.x86\VBoxHostWebcam.DLL [flags=0x0]
38881478.12f8: supR3HardenedDllNotificationCallback: Unload 68d10000 LB 0x00864000 C:\Program Files\VirtualBox\VBoxDD.DLL [flags=0x0]
38891478.12f8: supR3HardenedDllNotificationCallback: Unload 6dcc0000 LB 0x00032000 C:\Program Files\VirtualBox\VBoxDD2.dll [flags=0x0]
38901478.12f8: supR3HardenedDllNotificationCallback: Unload 6e1e0000 LB 0x0004f000 C:\Program Files\VirtualBox\VBoxDDU.dll [flags=0x0]
38911478.12f8: supR3HardenedDllNotificationCallback: Unload 72690000 LB 0x0004f000 C:\Windows\system32\newdev.dll [flags=0x0]
38921478.12f8: supR3HardenedDllNotificationCallback: Unload 6a020000 LB 0x0014c000 C:\Program Files\VirtualBox\VBoxREM64.DLL [flags=0x0]
38931478.1738: supR3HardenedDllNotificationCallback: Unload 71f20000 LB 0x00006000 C:\Program Files\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.x86\VBoxPuelMain.DLL [flags=0x0]
38941478.1738: supR3HardenedDllNotificationCallback: Unload 70040000 LB 0x00067000 c:\Windows\system32\netcfgx.dll [flags=0x0]
38951478.1738: supR3HardenedDllNotificationCallback: Unload 75ae0000 LB 0x0001c000 c:\Windows\system32\IPHLPAPI.DLL [flags=0x0]
38961478.1738: supR3HardenedDllNotificationCallback: Unload 75ad0000 LB 0x00007000 c:\Windows\system32\WINNSI.DLL [flags=0x0]
38971478.1738: supR3HardenedDllNotificationCallback: Unload 75ac0000 LB 0x0000a000 c:\Windows\system32\slc.dll [flags=0x0]
38981478.1738: supR3HardenedDllNotificationCallback: Unload 701e0000 LB 0x00096000 C:\Windows\system32\wbem\fastprox.dll [flags=0x0]
38991478.1738: supR3HardenedDllNotificationCallback: Unload 701c0000 LB 0x00018000 C:\Windows\system32\NTDSAPI.dll [flags=0x0]
39001478.1738: supR3HardenedDllNotificationCallback: Unload 6fe80000 LB 0x0000f000 C:\Windows\system32\wbem\wbemsvc.dll [flags=0x0]
39011478.1738: supR3HardenedDllNotificationCallback: Unload 72990000 LB 0x0000a000 C:\Windows\system32\wbem\wbemprox.dll [flags=0x0]
39021478.1738: supR3HardenedDllNotificationCallback: Unload 70f60000 LB 0x0005c000 C:\Windows\system32\wbemcomn.dll [flags=0x0]
39031478.1738: supR3HardenedDllNotificationCallback: Unload 6cf70000 LB 0x004f4000 C:\Program Files\VirtualBox\VBoxC.dll [flags=0x0]
39041478.1738: Terminating the normal way: rcExit=0
3905d64.1424: supR3HardNtChildWaitFor[2]: Quitting: ExitCode=0x0 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 262063 ms, the end);
390613fc.f84: supR3HardNtChildWaitFor[1]: Quitting: ExitCode=0x0 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 262537 ms, the end);

© 2024 Oracle Support Privacy / Do Not Sell My Info Terms of Use Trademark Policy Automated Access Etiquette