VirtualBox

Ticket #15285: VBoxHardening.log

File VBoxHardening.log, 266.3 KB (added by MattVB, 9 years ago)
Line 
114f4.22f4: Log file opened: 5.0.16r105871 g_hStartupLog=00000000000001c4 g_uNtVerCombined=0x611db110
214f4.22f4: \SystemRoot\System32\ntdll.dll:
314f4.22f4: CreationTime: 2016-01-16T13:40:29.643768300Z
414f4.22f4: LastWriteTime: 2016-01-16T13:40:29.643768300Z
514f4.22f4: ChangeTime: 2016-02-26T07:25:44.265625000Z
614f4.22f4: FileAttributes: 0x20
714f4.22f4: Size: 0x1a67c0
814f4.22f4: NT Headers: 0xe0
914f4.22f4: Timestamp: 0x568429e5
1014f4.22f4: Machine: 0x8664 - amd64
1114f4.22f4: Timestamp: 0x568429e5
1214f4.22f4: Image Version: 6.1
1314f4.22f4: SizeOfImage: 0x1a9000 (1740800)
1414f4.22f4: Resource Dir: 0x14d000 LB 0x5a028
1514f4.22f4: ProductName: Microsoft® Windows® Operating System
1614f4.22f4: ProductVersion: 6.1.7601.19110
1714f4.22f4: FileVersion: 6.1.7601.19110 (win7sp1_gdr.151230-0600)
1814f4.22f4: FileDescription: NT Layer DLL
1914f4.22f4: \SystemRoot\System32\kernel32.dll:
2014f4.22f4: CreationTime: 2016-01-16T13:40:29.659368300Z
2114f4.22f4: LastWriteTime: 2016-01-16T13:40:29.659368300Z
2214f4.22f4: ChangeTime: 2016-02-26T07:25:41.578125000Z
2314f4.22f4: FileAttributes: 0x20
2414f4.22f4: Size: 0x11c000
2514f4.22f4: NT Headers: 0xe8
2614f4.22f4: Timestamp: 0x568429dc
2714f4.22f4: Machine: 0x8664 - amd64
2814f4.22f4: Timestamp: 0x568429dc
2914f4.22f4: Image Version: 6.1
3014f4.22f4: SizeOfImage: 0x11f000 (1175552)
3114f4.22f4: Resource Dir: 0x116000 LB 0x528
3214f4.22f4: ProductName: Microsoft® Windows® Operating System
3314f4.22f4: ProductVersion: 6.1.7601.19110
3414f4.22f4: FileVersion: 6.1.7601.19110 (win7sp1_gdr.151230-0600)
3514f4.22f4: FileDescription: Windows NT BASE API Client DLL
3614f4.22f4: \SystemRoot\System32\KernelBase.dll:
3714f4.22f4: CreationTime: 2016-01-16T13:40:29.674968400Z
3814f4.22f4: LastWriteTime: 2016-01-16T13:40:29.674968400Z
3914f4.22f4: ChangeTime: 2016-02-26T07:25:41.484375000Z
4014f4.22f4: FileAttributes: 0x20
4114f4.22f4: Size: 0x67a00
4214f4.22f4: NT Headers: 0xe8
4314f4.22f4: Timestamp: 0x568429dd
4414f4.22f4: Machine: 0x8664 - amd64
4514f4.22f4: Timestamp: 0x568429dd
4614f4.22f4: Image Version: 6.1
4714f4.22f4: SizeOfImage: 0x6c000 (442368)
4814f4.22f4: Resource Dir: 0x6a000 LB 0x530
4914f4.22f4: ProductName: Microsoft® Windows® Operating System
5014f4.22f4: ProductVersion: 6.1.7601.19110
5114f4.22f4: FileVersion: 6.1.7601.19110 (win7sp1_gdr.151230-0600)
5214f4.22f4: FileDescription: Windows NT BASE API Client DLL
5314f4.22f4: \SystemRoot\System32\apisetschema.dll:
5414f4.22f4: CreationTime: 2016-01-16T13:40:29.643768300Z
5514f4.22f4: LastWriteTime: 2016-01-16T13:40:29.643768300Z
5614f4.22f4: ChangeTime: 2016-02-26T07:25:38.265625000Z
5714f4.22f4: FileAttributes: 0x20
5814f4.22f4: Size: 0x1a00
5914f4.22f4: NT Headers: 0xc0
6014f4.22f4: Timestamp: 0x568428c9
6114f4.22f4: Machine: 0x8664 - amd64
6214f4.22f4: Timestamp: 0x568428c9
6314f4.22f4: Image Version: 6.1
6414f4.22f4: SizeOfImage: 0x50000 (327680)
6514f4.22f4: Resource Dir: 0x30000 LB 0x3f8
6614f4.22f4: ProductName: Microsoft® Windows® Operating System
6714f4.22f4: ProductVersion: 6.1.7601.19110
6814f4.22f4: FileVersion: 6.1.7601.19110 (win7sp1_gdr.151230-0600)
6914f4.22f4: FileDescription: ApiSet Schema DLL
7014f4.22f4: Found driver inspect (0x800)
7114f4.22f4: Found driver cmdHlp (0x800)
7214f4.22f4: supR3HardenedWinFindAdversaries: 0x800
7314f4.22f4: \SystemRoot\System32\drivers\cmdguard.sys:
7414f4.22f4: CreationTime: 2015-11-18T16:14:30.000000000Z
7514f4.22f4: LastWriteTime: 2016-03-21T19:19:25.655000000Z
7614f4.22f4: ChangeTime: 2016-03-28T15:01:39.195312500Z
7714f4.22f4: FileAttributes: 0x2020
7814f4.22f4: Size: 0xc9030
7914f4.22f4: NT Headers: 0xf0
8014f4.22f4: Timestamp: 0x56f03e6a
8114f4.22f4: Machine: 0x8664 - amd64
8214f4.22f4: Timestamp: 0x56f03e6a
8314f4.22f4: Image Version: 6.1
8414f4.22f4: SizeOfImage: 0xd2000 (860160)
8514f4.22f4: Resource Dir: 0xcf000 LB 0x3e8
8614f4.22f4: ProductName: COMODO Internet Security Sandbox Driver
8714f4.22f4: ProductVersion: 8, 2, 0, 4978
8814f4.22f4: FileVersion: 8, 2, 0, 4978 built by: WinDDK
8914f4.22f4: FileDescription: COMODO Internet Security Sandbox Driver
9014f4.22f4: \SystemRoot\System32\drivers\cmderd.sys:
9114f4.22f4: CreationTime: 2015-11-18T16:14:26.000000000Z
9214f4.22f4: LastWriteTime: 2016-03-21T19:19:19.644000000Z
9314f4.22f4: ChangeTime: 2016-03-28T15:01:39.195312500Z
9414f4.22f4: FileAttributes: 0x2020
9514f4.22f4: Size: 0x7ba0
9614f4.22f4: NT Headers: 0xe0
9714f4.22f4: Timestamp: 0x56f03e38
9814f4.22f4: Machine: 0x8664 - amd64
9914f4.22f4: Timestamp: 0x56f03e38
10014f4.22f4: Image Version: 6.1
10114f4.22f4: SizeOfImage: 0x9000 (36864)
10214f4.22f4: Resource Dir: 0x7000 LB 0x3f0
10314f4.22f4: ProductName: COMODO Internet Security Eradication Driver
10414f4.22f4: ProductVersion: 8, 2, 0, 4978
10514f4.22f4: FileVersion: 8, 2, 0, 4978 built by: WinDDK
10614f4.22f4: FileDescription: COMODO Internet Security Eradication Driver
10714f4.22f4: \SystemRoot\System32\drivers\inspect.sys:
10814f4.22f4: CreationTime: 2015-08-04T23:31:28.000000000Z
10914f4.22f4: LastWriteTime: 2016-03-21T19:19:37.672000000Z
11014f4.22f4: ChangeTime: 2016-03-28T15:01:39.234375000Z
11114f4.22f4: FileAttributes: 0x2020
11214f4.22f4: Size: 0x1c618
11314f4.22f4: NT Headers: 0xe0
11414f4.22f4: Timestamp: 0x56f03e40
11514f4.22f4: Machine: 0x8664 - amd64
11614f4.22f4: Timestamp: 0x56f03e40
11714f4.22f4: Image Version: 6.1
11814f4.22f4: SizeOfImage: 0x1d000 (118784)
11914f4.22f4: Resource Dir: 0x1b000 LB 0x3e8
12014f4.22f4: ProductName: COMODO Internet Security Firewall Driver
12114f4.22f4: ProductVersion: 8, 2, 0, 4978
12214f4.22f4: FileVersion: 8, 2, 0, 4978 built by: WinDDK
12314f4.22f4: FileDescription: COMODO Internet Security Firewall Driver
12414f4.22f4: \SystemRoot\System32\drivers\cmdhlp.sys:
12514f4.22f4: CreationTime: 2015-08-04T23:31:26.000000000Z
12614f4.22f4: LastWriteTime: 2016-03-21T19:19:31.664000000Z
12714f4.22f4: ChangeTime: 2016-03-28T15:01:39.196289000Z
12814f4.22f4: FileAttributes: 0x2020
12914f4.22f4: Size: 0xdc90
13014f4.22f4: NT Headers: 0xe8
13114f4.22f4: Timestamp: 0x56f03e4b
13214f4.22f4: Machine: 0x8664 - amd64
13314f4.22f4: Timestamp: 0x56f03e4b
13414f4.22f4: Image Version: 6.1
13514f4.22f4: SizeOfImage: 0xd000 (53248)
13614f4.22f4: Resource Dir: 0xc000 LB 0x3e0
13714f4.22f4: ProductName: COMODO Internet Security Helper Driver
13814f4.22f4: ProductVersion: 8, 2, 0, 4978
13914f4.22f4: FileVersion: 8, 2, 0, 4978 built by: WinDDK
14014f4.22f4: FileDescription: COMODO Internet Security Helper Driver
14114f4.22f4: \SystemRoot\System32\guard64.dll:
14214f4.22f4: CreationTime: 2015-09-03T10:52:02.000000000Z
14314f4.22f4: LastWriteTime: 2016-03-21T19:17:19.458000000Z
14414f4.22f4: ChangeTime: 2016-03-28T15:01:33.421875000Z
14514f4.22f4: FileAttributes: 0x2020
14614f4.22f4: Size: 0x91908
14714f4.22f4: NT Headers: 0x118
14814f4.22f4: Timestamp: 0x56f03e9b
14914f4.22f4: Machine: 0x8664 - amd64
15014f4.22f4: Timestamp: 0x56f03e9b
15114f4.22f4: Image Version: 0.0
15214f4.22f4: SizeOfImage: 0x96000 (614400)
15314f4.22f4: Resource Dir: 0x93000 LB 0xd80
15414f4.22f4: ProductName: COMODO Internet Security
15514f4.22f4: ProductVersion: 8, 2, 0, 4978
15614f4.22f4: FileVersion: 8, 2, 0, 4978
15714f4.22f4: FileDescription: COMODO Internet Security
15814f4.22f4: \SystemRoot\System32\cmdvrt64.dll:
15914f4.22f4: CreationTime: 2015-08-04T23:28:52.000000000Z
16014f4.22f4: LastWriteTime: 2016-03-21T19:15:25.273000000Z
16114f4.22f4: ChangeTime: 2016-03-28T15:01:33.190429600Z
16214f4.22f4: FileAttributes: 0x2020
16314f4.22f4: Size: 0x592b8
16414f4.22f4: NT Headers: 0x100
16514f4.22f4: Timestamp: 0x56f03e9d
16614f4.22f4: Machine: 0x8664 - amd64
16714f4.22f4: Timestamp: 0x56f03e9d
16814f4.22f4: Image Version: 0.0
16914f4.22f4: SizeOfImage: 0x5d000 (380928)
17014f4.22f4: Resource Dir: 0x5b000 LB 0x5ac
17114f4.22f4: ProductName: COMODO Internet Security
17214f4.22f4: ProductVersion: 8, 2, 0, 4978
17314f4.22f4: FileVersion: 8, 2, 0, 4978
17414f4.22f4: FileDescription: COMODO Internet Security
17514f4.22f4: \SystemRoot\System32\cmdkbd64.dll:
17614f4.22f4: CreationTime: 2015-08-04T23:28:22.000000000Z
17714f4.22f4: LastWriteTime: 2016-03-21T19:14:31.191000000Z
17814f4.22f4: ChangeTime: 2016-03-28T15:01:33.189453100Z
17914f4.22f4: FileAttributes: 0x2020
18014f4.22f4: Size: 0xcab8
18114f4.22f4: NT Headers: 0xe8
18214f4.22f4: Timestamp: 0x56f03e93
18314f4.22f4: Machine: 0x8664 - amd64
18414f4.22f4: Timestamp: 0x56f03e93
18514f4.22f4: Image Version: 0.0
18614f4.22f4: SizeOfImage: 0xf000 (61440)
18714f4.22f4: Resource Dir: 0xd000 LB 0x5ac
18814f4.22f4: ProductName: COMODO Internet Security
18914f4.22f4: ProductVersion: 8, 2, 0, 4978
19014f4.22f4: FileVersion: 8, 2, 0, 4978
19114f4.22f4: FileDescription: COMODO Internet Security
19214f4.22f4: \SystemRoot\System32\cmdcsr.dll:
19314f4.22f4: CreationTime: 2015-08-04T23:29:58.000000000Z
19414f4.22f4: LastWriteTime: 2016-03-21T19:17:37.482000000Z
19514f4.22f4: ChangeTime: 2016-03-28T15:01:33.188476500Z
19614f4.22f4: FileAttributes: 0x2020
19714f4.22f4: Size: 0xca58
19814f4.22f4: NT Headers: 0xd8
19914f4.22f4: Timestamp: 0x56f03e90
20014f4.22f4: Machine: 0x8664 - amd64
20114f4.22f4: Timestamp: 0x56f03e90
20214f4.22f4: Image Version: 0.0
20314f4.22f4: SizeOfImage: 0xc000 (49152)
20414f4.22f4: Resource Dir: 0xa000 LB 0x4a8
20514f4.22f4: ProductName: COMODO Internet Security
20614f4.22f4: ProductVersion: 8, 2, 0, 4978
20714f4.22f4: FileVersion: 8, 2, 0, 4978
20814f4.22f4: FileDescription: COMODO Internet Security
20914f4.22f4: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox'
21014f4.22f4: Calling main()
21114f4.22f4: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
21214f4.22f4: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox'
21314f4.22f4: SUPR3HardenedMain: Respawn #1
21414f4.22f4: System32: \Device\HarddiskVolume1\Windows\System32
21514f4.22f4: WinSxS: \Device\HarddiskVolume1\Windows\winsxs
21614f4.22f4: KnownDllPath: C:\Windows\system32
21714f4.22f4: '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
21814f4.22f4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe)
21914f4.22f4: supR3HardNtEnableThreadCreation:
22014f4.22f4: supR3HardNtDisableThreadCreation: pvLdrInitThunk=0000000076d8b630 pvNtTerminateThread=0000000076dadee0
22114f4.22f4: supR3HardenedWinDoReSpawn(1): New child 1e2c.1c48 [kernel32].
22214f4.22f4: supR3HardNtChildGatherData: PebBaseAddress=000007fffffd9000 cbPeb=0x380
22314f4.22f4: supR3HardNtPuChFindNtdll: uNtDllParentAddr=0000000076d60000 uNtDllChildAddr=0000000076d60000
22414f4.22f4: supR3HardenedWinSetupChildInit: uLdrInitThunk=0000000076d8b630
22514f4.22f4: supR3HardenedWinSetupChildInit: Start child.
22614f4.22f4: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
22714f4.22f4: supR3HardNtChildPurify: Startup delay kludge #1/0: 518 ms, 59 sleeps
22814f4.22f4: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
22914f4.22f4: *0000000000000000-fffffffffffeffff 0x0001/0x0000 0x0000000
23014f4.22f4: *0000000000010000-fffffffffffeffff 0x0004/0x0004 0x0020000
23114f4.22f4: *0000000000030000-000000000002bfff 0x0002/0x0002 0x0040000
23214f4.22f4: 0000000000034000-0000000000027fff 0x0001/0x0000 0x0000000
23314f4.22f4: *0000000000040000-000000000003efff 0x0004/0x0004 0x0020000
23414f4.22f4: 0000000000041000-fffffffffff21fff 0x0001/0x0000 0x0000000
23514f4.22f4: *0000000000160000-0000000000063fff 0x0000/0x0004 0x0020000
23614f4.22f4: 000000000025c000-0000000000258fff 0x0104/0x0004 0x0020000
23714f4.22f4: 000000000025f000-000000000025dfff 0x0004/0x0004 0x0020000
23814f4.22f4: 0000000000260000-ffffffff8975ffff 0x0001/0x0000 0x0000000
23914f4.22f4: *0000000076d60000-0000000076d60fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
24014f4.22f4: 0000000076d61000-0000000076e5efff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
24114f4.22f4: 0000000076e5f000-0000000076e8dfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
24214f4.22f4: 0000000076e8e000-0000000076e95fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
24314f4.22f4: 0000000076e96000-0000000076e96fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
24414f4.22f4: 0000000076e97000-0000000076e99fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
24514f4.22f4: 0000000076e9a000-0000000076f08fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
24614f4.22f4: 0000000076f09000-000000006ee41fff 0x0001/0x0000 0x0000000
24714f4.22f4: *000000007efd0000-000000007efbffff 0x0040/0x0040 0x0020000 !!
24814f4.22f4: supHardNtVpFreeOrReplacePrivateExecMemory: Freeing exec mem at 000000007efd0000 (LB 0x10000, 000000007efd0000 LB 0x10000)
24914f4.22f4: supHardNtVpFreeOrReplacePrivateExecMemory: Free attempt #1 succeeded: 0x0 [000000007efd0000/000000007efd0000 LB 0/0x10000]
25014f4.22f4: supHardNtVpFreeOrReplacePrivateExecMemory: QVM after free 0: [0000000000000000]/000000007efd0000 LB 0x10000 s=0x10000 ap=0x0 rp=0x00000000000001
25114f4.22f4: *000000007efe0000-000000007dfdffff 0x0000/0x0002 0x0020000
25214f4.22f4: *000000007ffe0000-000000007ffdefff 0x0002/0x0002 0x0020000
25314f4.22f4: 000000007ffe1000-000000007ffd1fff 0x0000/0x0002 0x0020000
25414f4.22f4: 000000007fff0000-ffffffffc0d1ffff 0x0001/0x0000 0x0000000
25514f4.22f4: *000000013f2c0000-000000013f2c0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
25614f4.22f4: 000000013f2c1000-000000013f347fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
25714f4.22f4: 000000013f348000-000000013f348fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
25814f4.22f4: 000000013f349000-000000013f393fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
25914f4.22f4: 000000013f394000-000000013f394fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
26014f4.22f4: 000000013f395000-000000013f395fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
26114f4.22f4: 000000013f396000-000000013f39afff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
26214f4.22f4: 000000013f39b000-000000013f39bfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
26314f4.22f4: 000000013f39c000-000000013f39cfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
26414f4.22f4: 000000013f39d000-000000013f3a0fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
26514f4.22f4: 000000013f3a1000-000000013f3ebfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
26614f4.22f4: 000000013f3ec000-fffff8037f757fff 0x0001/0x0000 0x0000000
26714f4.22f4: *000007feff080000-000007feff080fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\apisetschema.dll
26814f4.22f4: 000007feff081000-000007fdfe151fff 0x0001/0x0000 0x0000000
26914f4.22f4: *000007fffffb0000-000007fffff8cfff 0x0002/0x0002 0x0040000
27014f4.22f4: 000007fffffd3000-000007fffffccfff 0x0001/0x0000 0x0000000
27114f4.22f4: *000007fffffd9000-000007fffffd7fff 0x0004/0x0004 0x0020000
27214f4.22f4: 000007fffffda000-000007fffffd5fff 0x0001/0x0000 0x0000000
27314f4.22f4: *000007fffffde000-000007fffffdbfff 0x0004/0x0004 0x0020000
27414f4.22f4: *000007fffffe0000-000007fffffcffff 0x0001/0x0002 0x0020000
27514f4.22f4: apisetschema.dll: timestamp 0x568428c9 (rc=VINF_SUCCESS)
27614f4.22f4: VirtualBox.exe: timestamp 0x56d9b7eb (rc=VINF_SUCCESS)
27714f4.22f4: '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
27814f4.22f4: '\Device\HarddiskVolume1\Windows\System32\apisetschema.dll' has no imports
27914f4.22f4: '\Device\HarddiskVolume1\Windows\System32\ntdll.dll' has no imports
28014f4.22f4: ntdll.dll: Differences in section #1 (.text) between file and memory:
28114f4.22f4: 0000000076daf1c0 / 0x004f1c0: 4c != e9
28214f4.22f4: 0000000076daf1c1 / 0x004f1c1: 8b != 3b
28314f4.22f4: 0000000076daf1c2 / 0x004f1c2: d1 != 0e
28414f4.22f4: 0000000076daf1c3 / 0x004f1c3: b8 != 22
28514f4.22f4: 0000000076daf1c4 / 0x004f1c4: 7e != 08
28614f4.22f4: Restored 0x2000 bytes of original file content at 0000000076dad63e
28714f4.22f4: supR3HardNtChildPurify: cFixes=2 g_fSupAdversaries=0x800 cPatchCount=0
28814f4.22f4: supR3HardNtChildPurify: Startup delay kludge #1/1: 518 ms, 59 sleeps
28914f4.22f4: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
29014f4.22f4: *0000000000000000-fffffffffffeffff 0x0001/0x0000 0x0000000
29114f4.22f4: *0000000000010000-fffffffffffeffff 0x0004/0x0004 0x0020000
29214f4.22f4: *0000000000030000-000000000002bfff 0x0002/0x0002 0x0040000
29314f4.22f4: 0000000000034000-0000000000027fff 0x0001/0x0000 0x0000000
29414f4.22f4: *0000000000040000-000000000003efff 0x0004/0x0004 0x0020000
29514f4.22f4: 0000000000041000-fffffffffff21fff 0x0001/0x0000 0x0000000
29614f4.22f4: *0000000000160000-0000000000063fff 0x0000/0x0004 0x0020000
29714f4.22f4: 000000000025c000-0000000000258fff 0x0104/0x0004 0x0020000
29814f4.22f4: 000000000025f000-000000000025dfff 0x0004/0x0004 0x0020000
29914f4.22f4: 0000000000260000-ffffffff8975ffff 0x0001/0x0000 0x0000000
30014f4.22f4: *0000000076d60000-0000000076d60fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
30114f4.22f4: 0000000076d61000-0000000076e5efff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
30214f4.22f4: 0000000076e5f000-0000000076e8dfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
30314f4.22f4: 0000000076e8e000-0000000076e95fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
30414f4.22f4: 0000000076e96000-0000000076e96fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
30514f4.22f4: 0000000076e97000-0000000076e97fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
30614f4.22f4: 0000000076e98000-0000000076e99fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
30714f4.22f4: 0000000076e9a000-0000000076f08fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
30814f4.22f4: 0000000076f09000-000000006ee31fff 0x0001/0x0000 0x0000000
30914f4.22f4: *000000007efe0000-000000007dfdffff 0x0000/0x0002 0x0020000
31014f4.22f4: *000000007ffe0000-000000007ffdefff 0x0002/0x0002 0x0020000
31114f4.22f4: 000000007ffe1000-000000007ffd1fff 0x0000/0x0002 0x0020000
31214f4.22f4: 000000007fff0000-ffffffffc0d1ffff 0x0001/0x0000 0x0000000
31314f4.22f4: *000000013f2c0000-000000013f2c0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
31414f4.22f4: 000000013f2c1000-000000013f347fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
31514f4.22f4: 000000013f348000-000000013f348fff 0x0040/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
31614f4.22f4: 000000013f349000-000000013f393fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
31714f4.22f4: 000000013f394000-000000013f3a0fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
31814f4.22f4: 000000013f3a1000-000000013f3ebfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
31914f4.22f4: 000000013f3ec000-fffff8037f757fff 0x0001/0x0000 0x0000000
32014f4.22f4: *000007feff080000-000007feff080fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\apisetschema.dll
32114f4.22f4: 000007feff081000-000007fdfe151fff 0x0001/0x0000 0x0000000
32214f4.22f4: *000007fffffb0000-000007fffff8cfff 0x0002/0x0002 0x0040000
32314f4.22f4: 000007fffffd3000-000007fffffccfff 0x0001/0x0000 0x0000000
32414f4.22f4: *000007fffffd9000-000007fffffd7fff 0x0004/0x0004 0x0020000
32514f4.22f4: 000007fffffda000-000007fffffd5fff 0x0001/0x0000 0x0000000
32614f4.22f4: *000007fffffde000-000007fffffdbfff 0x0004/0x0004 0x0020000
32714f4.22f4: *000007fffffe0000-000007fffffcffff 0x0001/0x0002 0x0020000
32814f4.22f4: supR3HardNtChildPurify: Done after 1927 ms and 2 fixes (loop #1).
3291e2c.1c48: Log file opened: 5.0.16r105871 g_hStartupLog=0000000000000004 g_uNtVerCombined=0x611db100
3301e2c.1c48: supR3HardenedVmProcessInit: uNtDllAddr=0000000076d60000 g_uNtVerCombined=0x611db100
3311e2c.1c48: ntdll.dll: timestamp 0x568429e5 (rc=VINF_SUCCESS)
3321e2c.1c48: New simple heap: #1 0000000000260000 LB 0x400000 (for 1740800 allocation)
33314f4.22f4: supR3HardNtEnableThreadCreation:
3341e2c.1c48: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox'
3351e2c.1c48: System32: \Device\HarddiskVolume1\Windows\System32
3361e2c.1c48: WinSxS: \Device\HarddiskVolume1\Windows\winsxs
3371e2c.1c48: KnownDllPath: C:\Windows\system32
3381e2c.1c48: supR3HardenedVmProcessInit: Opening vboxdrv stub...
3391e2c.1c48: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
3401e2c.1c48: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
3411e2c.1c48: Registered Dll notification callback with NTDLL.
3421e2c.1c48: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\kernel32.dll)
3431e2c.1c48: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\kernel32.dll
3441e2c.1c48: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
3451e2c.1c48: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
3461e2c.1c48: supR3HardenedDllNotificationCallback: load 0000000076b40000 LB 0x0011f000 C:\Windows\system32\kernel32.dll [fFlags=0x0]
3471e2c.1c48: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
3481e2c.1c48: supR3HardenedDllNotificationCallback: load 000007fefcbd0000 LB 0x0006c000 C:\Windows\system32\KERNELBASE.dll [fFlags=0x0]
3491e2c.1c48: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\KernelBase.dll)
3501e2c.1c48: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\KernelBase.dll
3511e2c.1c48: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000076b40000 'C:\Windows\system32\kernel32.dll'
3521e2c.1c48: supR3HardNtDisableThreadCreation: pvLdrInitThunk=0000000076d8b630 pvNtTerminateThread=0000000076dadee0
35314f4.22f4: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 20 ms.
3541e2c.1c48: \SystemRoot\System32\ntdll.dll:
3551e2c.1c48: CreationTime: 2016-01-16T13:40:29.643768300Z
3561e2c.1c48: LastWriteTime: 2016-01-16T13:40:29.643768300Z
3571e2c.1c48: ChangeTime: 2016-02-26T07:25:44.265625000Z
3581e2c.1c48: FileAttributes: 0x20
3591e2c.1c48: Size: 0x1a67c0
3601e2c.1c48: NT Headers: 0xe0
3611e2c.1c48: Timestamp: 0x568429e5
3621e2c.1c48: Machine: 0x8664 - amd64
3631e2c.1c48: Timestamp: 0x568429e5
3641e2c.1c48: Image Version: 6.1
3651e2c.1c48: SizeOfImage: 0x1a9000 (1740800)
3661e2c.1c48: Resource Dir: 0x14d000 LB 0x5a028
3671e2c.1c48: ProductName: Microsoft® Windows® Operating System
3681e2c.1c48: ProductVersion: 6.1.7601.19110
3691e2c.1c48: FileVersion: 6.1.7601.19110 (win7sp1_gdr.151230-0600)
3701e2c.1c48: FileDescription: NT Layer DLL
3711e2c.1c48: \SystemRoot\System32\kernel32.dll:
3721e2c.1c48: CreationTime: 2016-01-16T13:40:29.659368300Z
3731e2c.1c48: LastWriteTime: 2016-01-16T13:40:29.659368300Z
3741e2c.1c48: ChangeTime: 2016-02-26T07:25:41.578125000Z
3751e2c.1c48: FileAttributes: 0x20
3761e2c.1c48: Size: 0x11c000
3771e2c.1c48: NT Headers: 0xe8
3781e2c.1c48: Timestamp: 0x568429dc
3791e2c.1c48: Machine: 0x8664 - amd64
3801e2c.1c48: Timestamp: 0x568429dc
3811e2c.1c48: Image Version: 6.1
3821e2c.1c48: SizeOfImage: 0x11f000 (1175552)
3831e2c.1c48: Resource Dir: 0x116000 LB 0x528
3841e2c.1c48: ProductName: Microsoft® Windows® Operating System
3851e2c.1c48: ProductVersion: 6.1.7601.19110
3861e2c.1c48: FileVersion: 6.1.7601.19110 (win7sp1_gdr.151230-0600)
3871e2c.1c48: FileDescription: Windows NT BASE API Client DLL
3881e2c.1c48: \SystemRoot\System32\KernelBase.dll:
3891e2c.1c48: CreationTime: 2016-01-16T13:40:29.674968400Z
3901e2c.1c48: LastWriteTime: 2016-01-16T13:40:29.674968400Z
3911e2c.1c48: ChangeTime: 2016-02-26T07:25:41.484375000Z
3921e2c.1c48: FileAttributes: 0x20
3931e2c.1c48: Size: 0x67a00
3941e2c.1c48: NT Headers: 0xe8
3951e2c.1c48: Timestamp: 0x568429dd
3961e2c.1c48: Machine: 0x8664 - amd64
3971e2c.1c48: Timestamp: 0x568429dd
3981e2c.1c48: Image Version: 6.1
3991e2c.1c48: SizeOfImage: 0x6c000 (442368)
4001e2c.1c48: Resource Dir: 0x6a000 LB 0x530
4011e2c.1c48: ProductName: Microsoft® Windows® Operating System
4021e2c.1c48: ProductVersion: 6.1.7601.19110
4031e2c.1c48: FileVersion: 6.1.7601.19110 (win7sp1_gdr.151230-0600)
4041e2c.1c48: FileDescription: Windows NT BASE API Client DLL
4051e2c.1c48: \SystemRoot\System32\apisetschema.dll:
4061e2c.1c48: CreationTime: 2016-01-16T13:40:29.643768300Z
4071e2c.1c48: LastWriteTime: 2016-01-16T13:40:29.643768300Z
4081e2c.1c48: ChangeTime: 2016-02-26T07:25:38.265625000Z
4091e2c.1c48: FileAttributes: 0x20
4101e2c.1c48: Size: 0x1a00
4111e2c.1c48: NT Headers: 0xc0
4121e2c.1c48: Timestamp: 0x568428c9
4131e2c.1c48: Machine: 0x8664 - amd64
4141e2c.1c48: Timestamp: 0x568428c9
4151e2c.1c48: Image Version: 6.1
4161e2c.1c48: SizeOfImage: 0x50000 (327680)
4171e2c.1c48: Resource Dir: 0x30000 LB 0x3f8
4181e2c.1c48: ProductName: Microsoft® Windows® Operating System
4191e2c.1c48: ProductVersion: 6.1.7601.19110
4201e2c.1c48: FileVersion: 6.1.7601.19110 (win7sp1_gdr.151230-0600)
4211e2c.1c48: FileDescription: ApiSet Schema DLL
4221e2c.1c48: Found driver inspect (0x800)
4231e2c.1c48: Found driver cmdHlp (0x800)
4241e2c.1c48: supR3HardenedWinFindAdversaries: 0x800
4251e2c.1c48: \SystemRoot\System32\drivers\cmdguard.sys:
4261e2c.1c48: CreationTime: 2015-11-18T16:14:30.000000000Z
4271e2c.1c48: LastWriteTime: 2016-03-21T19:19:25.655000000Z
4281e2c.1c48: ChangeTime: 2016-03-28T15:01:39.195312500Z
4291e2c.1c48: FileAttributes: 0x2020
4301e2c.1c48: Size: 0xc9030
4311e2c.1c48: NT Headers: 0xf0
4321e2c.1c48: Timestamp: 0x56f03e6a
4331e2c.1c48: Machine: 0x8664 - amd64
4341e2c.1c48: Timestamp: 0x56f03e6a
4351e2c.1c48: Image Version: 6.1
4361e2c.1c48: SizeOfImage: 0xd2000 (860160)
4371e2c.1c48: Resource Dir: 0xcf000 LB 0x3e8
4381e2c.1c48: ProductName: COMODO Internet Security Sandbox Driver
4391e2c.1c48: ProductVersion: 8, 2, 0, 4978
4401e2c.1c48: FileVersion: 8, 2, 0, 4978 built by: WinDDK
4411e2c.1c48: FileDescription: COMODO Internet Security Sandbox Driver
4421e2c.1c48: \SystemRoot\System32\drivers\cmderd.sys:
4431e2c.1c48: CreationTime: 2015-11-18T16:14:26.000000000Z
4441e2c.1c48: LastWriteTime: 2016-03-21T19:19:19.644000000Z
4451e2c.1c48: ChangeTime: 2016-03-28T15:01:39.195312500Z
4461e2c.1c48: FileAttributes: 0x2020
4471e2c.1c48: Size: 0x7ba0
4481e2c.1c48: NT Headers: 0xe0
4491e2c.1c48: Timestamp: 0x56f03e38
4501e2c.1c48: Machine: 0x8664 - amd64
4511e2c.1c48: Timestamp: 0x56f03e38
4521e2c.1c48: Image Version: 6.1
4531e2c.1c48: SizeOfImage: 0x9000 (36864)
4541e2c.1c48: Resource Dir: 0x7000 LB 0x3f0
4551e2c.1c48: ProductName: COMODO Internet Security Eradication Driver
4561e2c.1c48: ProductVersion: 8, 2, 0, 4978
4571e2c.1c48: FileVersion: 8, 2, 0, 4978 built by: WinDDK
4581e2c.1c48: FileDescription: COMODO Internet Security Eradication Driver
4591e2c.1c48: \SystemRoot\System32\drivers\inspect.sys:
4601e2c.1c48: CreationTime: 2015-08-04T23:31:28.000000000Z
4611e2c.1c48: LastWriteTime: 2016-03-21T19:19:37.672000000Z
4621e2c.1c48: ChangeTime: 2016-03-28T15:01:39.234375000Z
4631e2c.1c48: FileAttributes: 0x2020
4641e2c.1c48: Size: 0x1c618
4651e2c.1c48: NT Headers: 0xe0
4661e2c.1c48: Timestamp: 0x56f03e40
4671e2c.1c48: Machine: 0x8664 - amd64
4681e2c.1c48: Timestamp: 0x56f03e40
4691e2c.1c48: Image Version: 6.1
4701e2c.1c48: SizeOfImage: 0x1d000 (118784)
4711e2c.1c48: Resource Dir: 0x1b000 LB 0x3e8
4721e2c.1c48: ProductName: COMODO Internet Security Firewall Driver
4731e2c.1c48: ProductVersion: 8, 2, 0, 4978
4741e2c.1c48: FileVersion: 8, 2, 0, 4978 built by: WinDDK
4751e2c.1c48: FileDescription: COMODO Internet Security Firewall Driver
4761e2c.1c48: \SystemRoot\System32\drivers\cmdhlp.sys:
4771e2c.1c48: CreationTime: 2015-08-04T23:31:26.000000000Z
4781e2c.1c48: LastWriteTime: 2016-03-21T19:19:31.664000000Z
4791e2c.1c48: ChangeTime: 2016-03-28T15:01:39.196289000Z
4801e2c.1c48: FileAttributes: 0x2020
4811e2c.1c48: Size: 0xdc90
4821e2c.1c48: NT Headers: 0xe8
4831e2c.1c48: Timestamp: 0x56f03e4b
4841e2c.1c48: Machine: 0x8664 - amd64
4851e2c.1c48: Timestamp: 0x56f03e4b
4861e2c.1c48: Image Version: 6.1
4871e2c.1c48: SizeOfImage: 0xd000 (53248)
4881e2c.1c48: Resource Dir: 0xc000 LB 0x3e0
4891e2c.1c48: ProductName: COMODO Internet Security Helper Driver
4901e2c.1c48: ProductVersion: 8, 2, 0, 4978
4911e2c.1c48: FileVersion: 8, 2, 0, 4978 built by: WinDDK
4921e2c.1c48: FileDescription: COMODO Internet Security Helper Driver
4931e2c.1c48: \SystemRoot\System32\guard64.dll:
4941e2c.1c48: CreationTime: 2015-09-03T10:52:02.000000000Z
4951e2c.1c48: LastWriteTime: 2016-03-21T19:17:19.458000000Z
4961e2c.1c48: ChangeTime: 2016-03-28T15:01:33.421875000Z
4971e2c.1c48: FileAttributes: 0x2020
4981e2c.1c48: Size: 0x91908
4991e2c.1c48: NT Headers: 0x118
5001e2c.1c48: Timestamp: 0x56f03e9b
5011e2c.1c48: Machine: 0x8664 - amd64
5021e2c.1c48: Timestamp: 0x56f03e9b
5031e2c.1c48: Image Version: 0.0
5041e2c.1c48: SizeOfImage: 0x96000 (614400)
5051e2c.1c48: Resource Dir: 0x93000 LB 0xd80
5061e2c.1c48: ProductName: COMODO Internet Security
5071e2c.1c48: ProductVersion: 8, 2, 0, 4978
5081e2c.1c48: FileVersion: 8, 2, 0, 4978
5091e2c.1c48: FileDescription: COMODO Internet Security
5101e2c.1c48: \SystemRoot\System32\cmdvrt64.dll:
5111e2c.1c48: CreationTime: 2015-08-04T23:28:52.000000000Z
5121e2c.1c48: LastWriteTime: 2016-03-21T19:15:25.273000000Z
5131e2c.1c48: ChangeTime: 2016-03-28T15:01:33.190429600Z
5141e2c.1c48: FileAttributes: 0x2020
5151e2c.1c48: Size: 0x592b8
5161e2c.1c48: NT Headers: 0x100
5171e2c.1c48: Timestamp: 0x56f03e9d
5181e2c.1c48: Machine: 0x8664 - amd64
5191e2c.1c48: Timestamp: 0x56f03e9d
5201e2c.1c48: Image Version: 0.0
5211e2c.1c48: SizeOfImage: 0x5d000 (380928)
5221e2c.1c48: Resource Dir: 0x5b000 LB 0x5ac
5231e2c.1c48: ProductName: COMODO Internet Security
5241e2c.1c48: ProductVersion: 8, 2, 0, 4978
5251e2c.1c48: FileVersion: 8, 2, 0, 4978
5261e2c.1c48: FileDescription: COMODO Internet Security
5271e2c.1c48: \SystemRoot\System32\cmdkbd64.dll:
5281e2c.1c48: CreationTime: 2015-08-04T23:28:22.000000000Z
5291e2c.1c48: LastWriteTime: 2016-03-21T19:14:31.191000000Z
5301e2c.1c48: ChangeTime: 2016-03-28T15:01:33.189453100Z
5311e2c.1c48: FileAttributes: 0x2020
5321e2c.1c48: Size: 0xcab8
5331e2c.1c48: NT Headers: 0xe8
5341e2c.1c48: Timestamp: 0x56f03e93
5351e2c.1c48: Machine: 0x8664 - amd64
5361e2c.1c48: Timestamp: 0x56f03e93
5371e2c.1c48: Image Version: 0.0
5381e2c.1c48: SizeOfImage: 0xf000 (61440)
5391e2c.1c48: Resource Dir: 0xd000 LB 0x5ac
5401e2c.1c48: ProductName: COMODO Internet Security
5411e2c.1c48: ProductVersion: 8, 2, 0, 4978
5421e2c.1c48: FileVersion: 8, 2, 0, 4978
5431e2c.1c48: FileDescription: COMODO Internet Security
5441e2c.1c48: \SystemRoot\System32\cmdcsr.dll:
5451e2c.1c48: CreationTime: 2015-08-04T23:29:58.000000000Z
5461e2c.1c48: LastWriteTime: 2016-03-21T19:17:37.482000000Z
5471e2c.1c48: ChangeTime: 2016-03-28T15:01:33.188476500Z
5481e2c.1c48: FileAttributes: 0x2020
5491e2c.1c48: Size: 0xca58
5501e2c.1c48: NT Headers: 0xd8
5511e2c.1c48: Timestamp: 0x56f03e90
5521e2c.1c48: Machine: 0x8664 - amd64
5531e2c.1c48: Timestamp: 0x56f03e90
5541e2c.1c48: Image Version: 0.0
5551e2c.1c48: SizeOfImage: 0xc000 (49152)
5561e2c.1c48: Resource Dir: 0xa000 LB 0x4a8
5571e2c.1c48: ProductName: COMODO Internet Security
5581e2c.1c48: ProductVersion: 8, 2, 0, 4978
5591e2c.1c48: FileVersion: 8, 2, 0, 4978
5601e2c.1c48: FileDescription: COMODO Internet Security
5611e2c.1c48: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox'
5621e2c.1c48: Calling main()
5631e2c.1c48: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
5641e2c.1c48: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox'
5651e2c.1c48: '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
5661e2c.1c48: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe)
5671e2c.1c48: SUPR3HardenedMain: Respawn #2
5681e2c.1c48: supR3HardNtEnableThreadCreation:
5691e2c.1c48: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\apphelp.dll)
5701e2c.1c48: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\apphelp.dll
5711e2c.1c48: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\apphelp.dll (rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
5721e2c.1c48: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\apphelp.dll [lacks WinVerifyTrust]
5731e2c.1c48: supR3HardenedDllNotificationCallback: load 000007fefc910000 LB 0x00057000 C:\Windows\system32\apphelp.dll [fFlags=0x0]
5741e2c.1c48: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\apphelp.dll [lacks WinVerifyTrust]
5751e2c.1c48: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc910000 'C:\Windows\system32\apphelp.dll'
5761e2c.1c48: supR3HardNtDisableThreadCreation: pvLdrInitThunk=0000000076d8b630 pvNtTerminateThread=0000000076dadee0
5771e2c.1c48: supR3HardenedWinDoReSpawn(2): New child 2140.19c8 [kernel32].
5781e2c.1c48: supR3HardNtChildGatherData: PebBaseAddress=000007fffffdf000 cbPeb=0x380
5791e2c.1c48: supR3HardNtPuChFindNtdll: uNtDllParentAddr=0000000076d60000 uNtDllChildAddr=0000000076d60000
5801e2c.1c48: supR3HardenedWinSetupChildInit: uLdrInitThunk=0000000076d8b630
5811e2c.1c48: supR3HardenedWinSetupChildInit: Start child.
5821e2c.1c48: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 1 ms.
5831e2c.1c48: supR3HardNtChildPurify: Startup delay kludge #1/0: 518 ms, 59 sleeps
5841e2c.1c48: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
5851e2c.1c48: *0000000000000000-fffffffffffeffff 0x0001/0x0000 0x0000000
5861e2c.1c48: *0000000000010000-fffffffffffeffff 0x0004/0x0004 0x0020000
5871e2c.1c48: *0000000000030000-000000000002bfff 0x0002/0x0002 0x0040000
5881e2c.1c48: 0000000000034000-0000000000027fff 0x0001/0x0000 0x0000000
5891e2c.1c48: *0000000000040000-000000000003efff 0x0004/0x0004 0x0020000
5901e2c.1c48: 0000000000041000-fffffffffff71fff 0x0001/0x0000 0x0000000
5911e2c.1c48: *0000000000110000-0000000000013fff 0x0000/0x0004 0x0020000
5921e2c.1c48: 000000000020c000-0000000000208fff 0x0104/0x0004 0x0020000
5931e2c.1c48: 000000000020f000-000000000020dfff 0x0004/0x0004 0x0020000
5941e2c.1c48: 0000000000210000-ffffffff896bffff 0x0001/0x0000 0x0000000
5951e2c.1c48: *0000000076d60000-0000000076d60fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
5961e2c.1c48: 0000000076d61000-0000000076e5efff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
5971e2c.1c48: 0000000076e5f000-0000000076e8dfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
5981e2c.1c48: 0000000076e8e000-0000000076e95fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
5991e2c.1c48: 0000000076e96000-0000000076e96fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
6001e2c.1c48: 0000000076e97000-0000000076e99fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
6011e2c.1c48: 0000000076e9a000-0000000076f08fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
6021e2c.1c48: 0000000076f09000-000000006ee41fff 0x0001/0x0000 0x0000000
6031e2c.1c48: *000000007efd0000-000000007efbffff 0x0040/0x0040 0x0020000 !!
6041e2c.1c48: supHardNtVpFreeOrReplacePrivateExecMemory: Freeing exec mem at 000000007efd0000 (LB 0x10000, 000000007efd0000 LB 0x10000)
6051e2c.1c48: supHardNtVpFreeOrReplacePrivateExecMemory: Free attempt #1 succeeded: 0x0 [000000007efd0000/000000007efd0000 LB 0/0x10000]
6061e2c.1c48: supHardNtVpFreeOrReplacePrivateExecMemory: QVM after free 0: [0000000000000000]/000000007efd0000 LB 0x10000 s=0x10000 ap=0x0 rp=0x00000000000001
6071e2c.1c48: *000000007efe0000-000000007dfdffff 0x0000/0x0002 0x0020000
6081e2c.1c48: *000000007ffe0000-000000007ffdefff 0x0002/0x0002 0x0020000
6091e2c.1c48: 000000007ffe1000-000000007ffd1fff 0x0000/0x0002 0x0020000
6101e2c.1c48: 000000007fff0000-ffffffffc0d1ffff 0x0001/0x0000 0x0000000
6111e2c.1c48: *000000013f2c0000-000000013f2c0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
6121e2c.1c48: 000000013f2c1000-000000013f347fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
6131e2c.1c48: 000000013f348000-000000013f348fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
6141e2c.1c48: 000000013f349000-000000013f393fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
6151e2c.1c48: 000000013f394000-000000013f394fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
6161e2c.1c48: 000000013f395000-000000013f395fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
6171e2c.1c48: 000000013f396000-000000013f39afff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
6181e2c.1c48: 000000013f39b000-000000013f39bfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
6191e2c.1c48: 000000013f39c000-000000013f39cfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
6201e2c.1c48: 000000013f39d000-000000013f3a0fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
6211e2c.1c48: 000000013f3a1000-000000013f3ebfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
6221e2c.1c48: 000000013f3ec000-fffff8037f757fff 0x0001/0x0000 0x0000000
6231e2c.1c48: *000007feff080000-000007feff080fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\apisetschema.dll
6241e2c.1c48: 000007feff081000-000007fdfe151fff 0x0001/0x0000 0x0000000
6251e2c.1c48: *000007fffffb0000-000007fffff8cfff 0x0002/0x0002 0x0040000
6261e2c.1c48: 000007fffffd3000-000007fffffc8fff 0x0001/0x0000 0x0000000
6271e2c.1c48: *000007fffffdd000-000007fffffdafff 0x0004/0x0004 0x0020000
6281e2c.1c48: *000007fffffdf000-000007fffffddfff 0x0004/0x0004 0x0020000
6291e2c.1c48: *000007fffffe0000-000007fffffcffff 0x0001/0x0002 0x0020000
6301e2c.1c48: apisetschema.dll: timestamp 0x568428c9 (rc=VINF_SUCCESS)
6311e2c.1c48: VirtualBox.exe: timestamp 0x56d9b7eb (rc=VINF_SUCCESS)
6321e2c.1c48: '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
6331e2c.1c48: '\Device\HarddiskVolume1\Windows\System32\apisetschema.dll' has no imports
6341e2c.1c48: '\Device\HarddiskVolume1\Windows\System32\ntdll.dll' has no imports
6351e2c.1c48: ntdll.dll: Differences in section #1 (.text) between file and memory:
6361e2c.1c48: 0000000076daf1c0 / 0x004f1c0: 4c != e9
6371e2c.1c48: 0000000076daf1c1 / 0x004f1c1: 8b != 3b
6381e2c.1c48: 0000000076daf1c2 / 0x004f1c2: d1 != 0e
6391e2c.1c48: 0000000076daf1c3 / 0x004f1c3: b8 != 22
6401e2c.1c48: 0000000076daf1c4 / 0x004f1c4: 7e != 08
6411e2c.1c48: Restored 0x2000 bytes of original file content at 0000000076dad63e
6421e2c.1c48: supR3HardNtChildPurify: cFixes=2 g_fSupAdversaries=0x800 cPatchCount=0
6431e2c.1c48: supR3HardNtChildPurify: Startup delay kludge #1/1: 518 ms, 59 sleeps
6441e2c.1c48: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
6451e2c.1c48: *0000000000000000-fffffffffffeffff 0x0001/0x0000 0x0000000
6461e2c.1c48: *0000000000010000-fffffffffffeffff 0x0004/0x0004 0x0020000
6471e2c.1c48: *0000000000030000-000000000002bfff 0x0002/0x0002 0x0040000
6481e2c.1c48: 0000000000034000-0000000000027fff 0x0001/0x0000 0x0000000
6491e2c.1c48: *0000000000040000-000000000003efff 0x0004/0x0004 0x0020000
6501e2c.1c48: 0000000000041000-fffffffffff71fff 0x0001/0x0000 0x0000000
6511e2c.1c48: *0000000000110000-0000000000013fff 0x0000/0x0004 0x0020000
6521e2c.1c48: 000000000020c000-0000000000208fff 0x0104/0x0004 0x0020000
6531e2c.1c48: 000000000020f000-000000000020dfff 0x0004/0x0004 0x0020000
6541e2c.1c48: 0000000000210000-ffffffff896bffff 0x0001/0x0000 0x0000000
6551e2c.1c48: *0000000076d60000-0000000076d60fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
6561e2c.1c48: 0000000076d61000-0000000076e5efff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
6571e2c.1c48: 0000000076e5f000-0000000076e8dfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
6581e2c.1c48: 0000000076e8e000-0000000076e95fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
6591e2c.1c48: 0000000076e96000-0000000076e96fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
6601e2c.1c48: 0000000076e97000-0000000076e97fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
6611e2c.1c48: 0000000076e98000-0000000076e99fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
6621e2c.1c48: 0000000076e9a000-0000000076f08fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
6631e2c.1c48: 0000000076f09000-000000006ee31fff 0x0001/0x0000 0x0000000
6641e2c.1c48: *000000007efe0000-000000007dfdffff 0x0000/0x0002 0x0020000
6651e2c.1c48: *000000007ffe0000-000000007ffdefff 0x0002/0x0002 0x0020000
6661e2c.1c48: 000000007ffe1000-000000007ffd1fff 0x0000/0x0002 0x0020000
6671e2c.1c48: 000000007fff0000-ffffffffc0d1ffff 0x0001/0x0000 0x0000000
6681e2c.1c48: *000000013f2c0000-000000013f2c0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
6691e2c.1c48: 000000013f2c1000-000000013f347fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
6701e2c.1c48: 000000013f348000-000000013f348fff 0x0040/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
6711e2c.1c48: 000000013f349000-000000013f393fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
6721e2c.1c48: 000000013f394000-000000013f3a0fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
6731e2c.1c48: 000000013f3a1000-000000013f3ebfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
6741e2c.1c48: 000000013f3ec000-fffff8037f757fff 0x0001/0x0000 0x0000000
6751e2c.1c48: *000007feff080000-000007feff080fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\apisetschema.dll
6761e2c.1c48: 000007feff081000-000007fdfe151fff 0x0001/0x0000 0x0000000
6771e2c.1c48: *000007fffffb0000-000007fffff8cfff 0x0002/0x0002 0x0040000
6781e2c.1c48: 000007fffffd3000-000007fffffc8fff 0x0001/0x0000 0x0000000
6791e2c.1c48: *000007fffffdd000-000007fffffdafff 0x0004/0x0004 0x0020000
6801e2c.1c48: *000007fffffdf000-000007fffffddfff 0x0004/0x0004 0x0020000
6811e2c.1c48: *000007fffffe0000-000007fffffcffff 0x0001/0x0002 0x0020000
6821e2c.1c48: supR3HardNtChildPurify: Done after 1341 ms and 2 fixes (loop #1).
6832140.19c8: Log file opened: 5.0.16r105871 g_hStartupLog=0000000000000004 g_uNtVerCombined=0x611db100
6842140.19c8: supR3HardenedVmProcessInit: uNtDllAddr=0000000076d60000 g_uNtVerCombined=0x611db100
6852140.19c8: ntdll.dll: timestamp 0x568429e5 (rc=VINF_SUCCESS)
6862140.19c8: New simple heap: #1 0000000000310000 LB 0x400000 (for 1740800 allocation)
6871e2c.1c48: supR3HardenedEarlyCompact: Removed heap 1 (0x00000000260000 LB 0x400000)
6881e2c.1c48: supR3HardNtEnableThreadCreation:
6892140.19c8: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox'
6902140.19c8: System32: \Device\HarddiskVolume1\Windows\System32
6912140.19c8: WinSxS: \Device\HarddiskVolume1\Windows\winsxs
6922140.19c8: KnownDllPath: C:\Windows\system32
6932140.19c8: supR3HardenedVmProcessInit: Opening vboxdrv...
6942140.19c8: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
6952140.19c8: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
6962140.19c8: Registered Dll notification callback with NTDLL.
6972140.19c8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\kernel32.dll)
6982140.19c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\kernel32.dll
6992140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
7002140.19c8: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
7012140.19c8: supR3HardenedDllNotificationCallback: load 0000000076b40000 LB 0x0011f000 C:\Windows\system32\kernel32.dll [fFlags=0x0]
7022140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
7032140.19c8: supR3HardenedDllNotificationCallback: load 000007fefcbd0000 LB 0x0006c000 C:\Windows\system32\KERNELBASE.dll [fFlags=0x0]
7042140.19c8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\KernelBase.dll)
7052140.19c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\KernelBase.dll
7062140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000076b40000 'C:\Windows\system32\kernel32.dll'
7072140.19c8: supR3HardNtDisableThreadCreation: pvLdrInitThunk=0000000076d8b630 pvNtTerminateThread=0000000076dadee0
7081e2c.1c48: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 26 ms.
7092140.19c8: \SystemRoot\System32\ntdll.dll:
7102140.19c8: CreationTime: 2016-01-16T13:40:29.643768300Z
7112140.19c8: LastWriteTime: 2016-01-16T13:40:29.643768300Z
7122140.19c8: ChangeTime: 2016-02-26T07:25:44.265625000Z
7132140.19c8: FileAttributes: 0x20
7142140.19c8: Size: 0x1a67c0
7152140.19c8: NT Headers: 0xe0
7162140.19c8: Timestamp: 0x568429e5
7172140.19c8: Machine: 0x8664 - amd64
7182140.19c8: Timestamp: 0x568429e5
7192140.19c8: Image Version: 6.1
7202140.19c8: SizeOfImage: 0x1a9000 (1740800)
7212140.19c8: Resource Dir: 0x14d000 LB 0x5a028
7222140.19c8: ProductName: Microsoft® Windows® Operating System
7232140.19c8: ProductVersion: 6.1.7601.19110
7242140.19c8: FileVersion: 6.1.7601.19110 (win7sp1_gdr.151230-0600)
7252140.19c8: FileDescription: NT Layer DLL
7262140.19c8: \SystemRoot\System32\kernel32.dll:
7272140.19c8: CreationTime: 2016-01-16T13:40:29.659368300Z
7282140.19c8: LastWriteTime: 2016-01-16T13:40:29.659368300Z
7292140.19c8: ChangeTime: 2016-02-26T07:25:41.578125000Z
7302140.19c8: FileAttributes: 0x20
7312140.19c8: Size: 0x11c000
7322140.19c8: NT Headers: 0xe8
7332140.19c8: Timestamp: 0x568429dc
7342140.19c8: Machine: 0x8664 - amd64
7352140.19c8: Timestamp: 0x568429dc
7362140.19c8: Image Version: 6.1
7372140.19c8: SizeOfImage: 0x11f000 (1175552)
7382140.19c8: Resource Dir: 0x116000 LB 0x528
7392140.19c8: ProductName: Microsoft® Windows® Operating System
7402140.19c8: ProductVersion: 6.1.7601.19110
7412140.19c8: FileVersion: 6.1.7601.19110 (win7sp1_gdr.151230-0600)
7422140.19c8: FileDescription: Windows NT BASE API Client DLL
7432140.19c8: \SystemRoot\System32\KernelBase.dll:
7442140.19c8: CreationTime: 2016-01-16T13:40:29.674968400Z
7452140.19c8: LastWriteTime: 2016-01-16T13:40:29.674968400Z
7462140.19c8: ChangeTime: 2016-02-26T07:25:41.484375000Z
7472140.19c8: FileAttributes: 0x20
7482140.19c8: Size: 0x67a00
7492140.19c8: NT Headers: 0xe8
7502140.19c8: Timestamp: 0x568429dd
7512140.19c8: Machine: 0x8664 - amd64
7522140.19c8: Timestamp: 0x568429dd
7532140.19c8: Image Version: 6.1
7542140.19c8: SizeOfImage: 0x6c000 (442368)
7552140.19c8: Resource Dir: 0x6a000 LB 0x530
7562140.19c8: ProductName: Microsoft® Windows® Operating System
7572140.19c8: ProductVersion: 6.1.7601.19110
7582140.19c8: FileVersion: 6.1.7601.19110 (win7sp1_gdr.151230-0600)
7592140.19c8: FileDescription: Windows NT BASE API Client DLL
7602140.19c8: \SystemRoot\System32\apisetschema.dll:
7612140.19c8: CreationTime: 2016-01-16T13:40:29.643768300Z
7622140.19c8: LastWriteTime: 2016-01-16T13:40:29.643768300Z
7632140.19c8: ChangeTime: 2016-02-26T07:25:38.265625000Z
7642140.19c8: FileAttributes: 0x20
7652140.19c8: Size: 0x1a00
7662140.19c8: NT Headers: 0xc0
7672140.19c8: Timestamp: 0x568428c9
7682140.19c8: Machine: 0x8664 - amd64
7692140.19c8: Timestamp: 0x568428c9
7702140.19c8: Image Version: 6.1
7712140.19c8: SizeOfImage: 0x50000 (327680)
7722140.19c8: Resource Dir: 0x30000 LB 0x3f8
7732140.19c8: ProductName: Microsoft® Windows® Operating System
7742140.19c8: ProductVersion: 6.1.7601.19110
7752140.19c8: FileVersion: 6.1.7601.19110 (win7sp1_gdr.151230-0600)
7762140.19c8: FileDescription: ApiSet Schema DLL
7772140.19c8: Found driver inspect (0x800)
7782140.19c8: Found driver cmdHlp (0x800)
7792140.19c8: supR3HardenedWinFindAdversaries: 0x800
7802140.19c8: \SystemRoot\System32\drivers\cmdguard.sys:
7812140.19c8: CreationTime: 2015-11-18T16:14:30.000000000Z
7822140.19c8: LastWriteTime: 2016-03-21T19:19:25.655000000Z
7832140.19c8: ChangeTime: 2016-03-28T15:01:39.195312500Z
7842140.19c8: FileAttributes: 0x2020
7852140.19c8: Size: 0xc9030
7862140.19c8: NT Headers: 0xf0
7872140.19c8: Timestamp: 0x56f03e6a
7882140.19c8: Machine: 0x8664 - amd64
7892140.19c8: Timestamp: 0x56f03e6a
7902140.19c8: Image Version: 6.1
7912140.19c8: SizeOfImage: 0xd2000 (860160)
7922140.19c8: Resource Dir: 0xcf000 LB 0x3e8
7932140.19c8: ProductName: COMODO Internet Security Sandbox Driver
7942140.19c8: ProductVersion: 8, 2, 0, 4978
7952140.19c8: FileVersion: 8, 2, 0, 4978 built by: WinDDK
7962140.19c8: FileDescription: COMODO Internet Security Sandbox Driver
7972140.19c8: \SystemRoot\System32\drivers\cmderd.sys:
7982140.19c8: CreationTime: 2015-11-18T16:14:26.000000000Z
7992140.19c8: LastWriteTime: 2016-03-21T19:19:19.644000000Z
8002140.19c8: ChangeTime: 2016-03-28T15:01:39.195312500Z
8012140.19c8: FileAttributes: 0x2020
8022140.19c8: Size: 0x7ba0
8032140.19c8: NT Headers: 0xe0
8042140.19c8: Timestamp: 0x56f03e38
8052140.19c8: Machine: 0x8664 - amd64
8062140.19c8: Timestamp: 0x56f03e38
8072140.19c8: Image Version: 6.1
8082140.19c8: SizeOfImage: 0x9000 (36864)
8092140.19c8: Resource Dir: 0x7000 LB 0x3f0
8102140.19c8: ProductName: COMODO Internet Security Eradication Driver
8112140.19c8: ProductVersion: 8, 2, 0, 4978
8122140.19c8: FileVersion: 8, 2, 0, 4978 built by: WinDDK
8132140.19c8: FileDescription: COMODO Internet Security Eradication Driver
8142140.19c8: \SystemRoot\System32\drivers\inspect.sys:
8152140.19c8: CreationTime: 2015-08-04T23:31:28.000000000Z
8162140.19c8: LastWriteTime: 2016-03-21T19:19:37.672000000Z
8172140.19c8: ChangeTime: 2016-03-28T15:01:39.234375000Z
8182140.19c8: FileAttributes: 0x2020
8192140.19c8: Size: 0x1c618
8202140.19c8: NT Headers: 0xe0
8212140.19c8: Timestamp: 0x56f03e40
8222140.19c8: Machine: 0x8664 - amd64
8232140.19c8: Timestamp: 0x56f03e40
8242140.19c8: Image Version: 6.1
8252140.19c8: SizeOfImage: 0x1d000 (118784)
8262140.19c8: Resource Dir: 0x1b000 LB 0x3e8
8272140.19c8: ProductName: COMODO Internet Security Firewall Driver
8282140.19c8: ProductVersion: 8, 2, 0, 4978
8292140.19c8: FileVersion: 8, 2, 0, 4978 built by: WinDDK
8302140.19c8: FileDescription: COMODO Internet Security Firewall Driver
8312140.19c8: \SystemRoot\System32\drivers\cmdhlp.sys:
8322140.19c8: CreationTime: 2015-08-04T23:31:26.000000000Z
8332140.19c8: LastWriteTime: 2016-03-21T19:19:31.664000000Z
8342140.19c8: ChangeTime: 2016-03-28T15:01:39.196289000Z
8352140.19c8: FileAttributes: 0x2020
8362140.19c8: Size: 0xdc90
8372140.19c8: NT Headers: 0xe8
8382140.19c8: Timestamp: 0x56f03e4b
8392140.19c8: Machine: 0x8664 - amd64
8402140.19c8: Timestamp: 0x56f03e4b
8412140.19c8: Image Version: 6.1
8422140.19c8: SizeOfImage: 0xd000 (53248)
8432140.19c8: Resource Dir: 0xc000 LB 0x3e0
8442140.19c8: ProductName: COMODO Internet Security Helper Driver
8452140.19c8: ProductVersion: 8, 2, 0, 4978
8462140.19c8: FileVersion: 8, 2, 0, 4978 built by: WinDDK
8472140.19c8: FileDescription: COMODO Internet Security Helper Driver
8482140.19c8: \SystemRoot\System32\guard64.dll:
8492140.19c8: CreationTime: 2015-09-03T10:52:02.000000000Z
8502140.19c8: LastWriteTime: 2016-03-21T19:17:19.458000000Z
8512140.19c8: ChangeTime: 2016-03-28T15:01:33.421875000Z
8522140.19c8: FileAttributes: 0x2020
8532140.19c8: Size: 0x91908
8542140.19c8: NT Headers: 0x118
8552140.19c8: Timestamp: 0x56f03e9b
8562140.19c8: Machine: 0x8664 - amd64
8572140.19c8: Timestamp: 0x56f03e9b
8582140.19c8: Image Version: 0.0
8592140.19c8: SizeOfImage: 0x96000 (614400)
8602140.19c8: Resource Dir: 0x93000 LB 0xd80
8612140.19c8: ProductName: COMODO Internet Security
8622140.19c8: ProductVersion: 8, 2, 0, 4978
8632140.19c8: FileVersion: 8, 2, 0, 4978
8642140.19c8: FileDescription: COMODO Internet Security
8652140.19c8: \SystemRoot\System32\cmdvrt64.dll:
8662140.19c8: CreationTime: 2015-08-04T23:28:52.000000000Z
8672140.19c8: LastWriteTime: 2016-03-21T19:15:25.273000000Z
8682140.19c8: ChangeTime: 2016-03-28T15:01:33.190429600Z
8692140.19c8: FileAttributes: 0x2020
8702140.19c8: Size: 0x592b8
8712140.19c8: NT Headers: 0x100
8722140.19c8: Timestamp: 0x56f03e9d
8732140.19c8: Machine: 0x8664 - amd64
8742140.19c8: Timestamp: 0x56f03e9d
8752140.19c8: Image Version: 0.0
8762140.19c8: SizeOfImage: 0x5d000 (380928)
8772140.19c8: Resource Dir: 0x5b000 LB 0x5ac
8782140.19c8: ProductName: COMODO Internet Security
8792140.19c8: ProductVersion: 8, 2, 0, 4978
8802140.19c8: FileVersion: 8, 2, 0, 4978
8812140.19c8: FileDescription: COMODO Internet Security
8822140.19c8: \SystemRoot\System32\cmdkbd64.dll:
8832140.19c8: CreationTime: 2015-08-04T23:28:22.000000000Z
8842140.19c8: LastWriteTime: 2016-03-21T19:14:31.191000000Z
8852140.19c8: ChangeTime: 2016-03-28T15:01:33.189453100Z
8862140.19c8: FileAttributes: 0x2020
8872140.19c8: Size: 0xcab8
8882140.19c8: NT Headers: 0xe8
8892140.19c8: Timestamp: 0x56f03e93
8902140.19c8: Machine: 0x8664 - amd64
8912140.19c8: Timestamp: 0x56f03e93
8922140.19c8: Image Version: 0.0
8932140.19c8: SizeOfImage: 0xf000 (61440)
8942140.19c8: Resource Dir: 0xd000 LB 0x5ac
8952140.19c8: ProductName: COMODO Internet Security
8962140.19c8: ProductVersion: 8, 2, 0, 4978
8972140.19c8: FileVersion: 8, 2, 0, 4978
8982140.19c8: FileDescription: COMODO Internet Security
8992140.19c8: \SystemRoot\System32\cmdcsr.dll:
9002140.19c8: CreationTime: 2015-08-04T23:29:58.000000000Z
9012140.19c8: LastWriteTime: 2016-03-21T19:17:37.482000000Z
9022140.19c8: ChangeTime: 2016-03-28T15:01:33.188476500Z
9032140.19c8: FileAttributes: 0x2020
9042140.19c8: Size: 0xca58
9052140.19c8: NT Headers: 0xd8
9062140.19c8: Timestamp: 0x56f03e90
9072140.19c8: Machine: 0x8664 - amd64
9082140.19c8: Timestamp: 0x56f03e90
9092140.19c8: Image Version: 0.0
9102140.19c8: SizeOfImage: 0xc000 (49152)
9112140.19c8: Resource Dir: 0xa000 LB 0x4a8
9122140.19c8: ProductName: COMODO Internet Security
9132140.19c8: ProductVersion: 8, 2, 0, 4978
9142140.19c8: FileVersion: 8, 2, 0, 4978
9152140.19c8: FileDescription: COMODO Internet Security
9162140.19c8: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox'
9172140.19c8: Calling main()
9182140.19c8: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
9192140.19c8: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox'
9202140.19c8: '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
9212140.19c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe)
9222140.19c8: SUPR3HardenedMain: Final process, opening VBoxDrv...
9232140.19c8: supR3HardenedEarlyCompact: Removed heap 1 (0x00000000310000 LB 0x400000)
9242140.19c8: supR3HardNtEnableThreadCreation:
9252140.19c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxSupLib.dll)
9262140.19c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxSupLib.dll
9272140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3df0:C:\Windows\system32 [calling]
9282140.19c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
9292140.19c8: supR3HardenedDllNotificationCallback: load 000007fef6e20000 LB 0x00005000 C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL [fFlags=0x0]
9302140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
9312140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
9322140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e4220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Skype\Phone\;C:\Program Files\OpenVPN\bin [calling]
9332140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef6e20000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
9342140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
9352140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e4220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Skype\Phone\;C:\Program Files\OpenVPN\bin [calling]
9362140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef6e20000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
9372140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef6e20000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
9382140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
9392140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'crypt32.dll'.
9402140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msasn1.dll'.
9412140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
9422140.19c8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\wintrust.dll)
9432140.19c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\wintrust.dll
9442140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
9452140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
9462140.19c8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll)
9472140.19c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\rpcrt4.dll
9482140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
9492140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume1\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
9502140.19c8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\msasn1.dll)
9512140.19c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\msasn1.dll
9522140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
9532140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume1\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
9542140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
9552140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msasn1.dll'.
9562140.19c8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\crypt32.dll)
9572140.19c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\crypt32.dll
9582140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
9592140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
9602140.19c8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\msvcrt.dll)
9612140.19c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\msvcrt.dll
9622140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
9632140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume1\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
9642140.19c8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
9652140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
9662140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
9672140.19c8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
9682140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3df0:C:\Windows\system32 [calling]
9692140.19c8: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
9702140.19c8: supR3HardenedDllNotificationCallback: load 000007fefcb70000 LB 0x0003b000 C:\Windows\system32\Wintrust.dll [fFlags=0x0]
9712140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
9722140.19c8: supR3HardenedDllNotificationCallback: load 000007fefd360000 LB 0x0009f000 C:\Windows\system32\msvcrt.dll [fFlags=0x0]
9732140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
9742140.19c8: supR3HardenedDllNotificationCallback: load 000007fefcc40000 LB 0x0016d000 C:\Windows\system32\CRYPT32.dll [fFlags=0x0]
9752140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
9762140.19c8: supR3HardenedDllNotificationCallback: load 000007fefcb00000 LB 0x0000f000 C:\Windows\system32\MSASN1.dll [fFlags=0x0]
9772140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
9782140.19c8: supR3HardenedDllNotificationCallback: load 000007fefcfa0000 LB 0x0012d000 C:\Windows\system32\RPCRT4.dll [fFlags=0x0]
9792140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
9802140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcb70000 'C:\Windows\system32\Wintrust.dll'
9812140.19c8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\bcrypt.dll)
9822140.19c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\bcrypt.dll
9832140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcrypt.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000008290a0:C:\Windows\system32 [calling]
9842140.19c8: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
9852140.19c8: supR3HardenedDllNotificationCallback: load 000007fefc3a0000 LB 0x00022000 C:\Windows\system32\bcrypt.dll [fFlags=0x0]
9862140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
9872140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc3a0000 'C:\Windows\system32\bcrypt.dll'
9882140.19c8: bcrypt.dll loaded at 000007fefc3a0000, BCryptOpenAlgorithmProvider at 000007fefc3a2640, preloading providers:
9892140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
9902140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'bcrypt.dll'.
9912140.19c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\bcryptprimitives.dll)
9922140.19c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\bcryptprimitives.dll
9932140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
9942140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume1\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
9952140.19c8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
9962140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
9972140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
9982140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
9992140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'rpcrt4.dll'.
10002140.19c8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\advapi32.dll)
10012140.19c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\advapi32.dll
10022140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
10032140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
10042140.19c8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
10052140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
10062140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
10072140.19c8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
10082140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcryptprimitives.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e4220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Skype\Phone\;C:\Program Files\OpenVPN\bin [calling]
10092140.19c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
10102140.19c8: supR3HardenedDllNotificationCallback: load 000007fefbe70000 LB 0x0004c000 C:\Windows\system32\bcryptprimitives.dll [fFlags=0x0]
10112140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
10122140.19c8: supR3HardenedDllNotificationCallback: load 000007fefdad0000 LB 0x000db000 C:\Windows\system32\ADVAPI32.dll [fFlags=0x0]
10132140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
10142140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msvcrt.dll'.
10152140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'rpcrt4.dll'.
10162140.19c8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\sechost.dll)
10172140.19c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\sechost.dll
10182140.19c8: supR3HardenedDllNotificationCallback: load 000007fefee40000 LB 0x0001f000 C:\Windows\SYSTEM32\sechost.dll [fFlags=0x0]
10192140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\sechost.dll [lacks WinVerifyTrust]
10202140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbe70000 'C:\Windows\system32\bcryptprimitives.dll'
10212140.19c8: BCryptOpenAlgorithmProvider(,'MD2',0,0) -> 0x0 (hAlgo=000000000082a6a0)
10222140.19c8: BCryptOpenAlgorithmProvider(,'MD4',0,0) -> 0x0 (hAlgo=000000000082d6c0)
10232140.19c8: BCryptOpenAlgorithmProvider(,'MD5',0,0) -> 0x0 (hAlgo=000000000082d7e0)
10242140.19c8: BCryptOpenAlgorithmProvider(,'SHA1',0,0) -> 0x0 (hAlgo=000000000082d9f0)
10252140.19c8: BCryptOpenAlgorithmProvider(,'SHA256',0,0) -> 0x0 (hAlgo=000000000082db10)
10262140.19c8: BCryptOpenAlgorithmProvider(,'SHA512',0,0) -> 0x0 (hAlgo=000000000082dc30)
10272140.19c8: BCryptOpenAlgorithmProvider(,'RSA',0,0) -> 0x0 (hAlgo=000000000082de70)
10282140.19c8: BCryptOpenAlgorithmProvider(,'DSA',0,0) -> 0x0 (hAlgo=000000000082df90)
10292140.19c8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\cryptsp.dll)
10302140.19c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\cryptsp.dll
10312140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
10322140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
10332140.19c8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
10342140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
10352140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
10362140.19c8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
10372140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTSP.dll (Input=CRYPTSP.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e4220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Skype\Phone\;C:\Program Files\OpenVPN\bin [calling]
10382140.19c8: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
10392140.19c8: supR3HardenedDllNotificationCallback: load 000007fefc230000 LB 0x00018000 C:\Windows\system32\CRYPTSP.dll [fFlags=0x0]
10402140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
10412140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc230000 'C:\Windows\system32\CRYPTSP.dll'
10422140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
10432140.19c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\rsaenh.dll)
10442140.19c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\rsaenh.dll
10452140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
10462140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
10472140.19c8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
10482140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e4220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Skype\Phone\;C:\Program Files\OpenVPN\bin [calling]
10492140.19c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
10502140.19c8: supR3HardenedDllNotificationCallback: load 000007fefbf30000 LB 0x00047000 C:\Windows\system32\rsaenh.dll [fFlags=0x0]
10512140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
10522140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbf30000 'C:\Windows\system32\rsaenh.dll'
10532140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
10542140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ADVAPI32.dll (Input=ADVAPI32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e4220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Skype\Phone\;C:\Program Files\OpenVPN\bin [calling]
10552140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdad0000 'C:\Windows\system32\ADVAPI32.dll'
10562140.19c8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\cryptbase.dll)
10572140.19c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\cryptbase.dll
10582140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTBASE.dll (Input=CRYPTBASE.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e4220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Skype\Phone\;C:\Program Files\OpenVPN\bin [calling]
10592140.19c8: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptbase.dll [lacks WinVerifyTrust]
10602140.19c8: supR3HardenedDllNotificationCallback: load 000007fefc970000 LB 0x0000f000 C:\Windows\system32\CRYPTBASE.dll [fFlags=0x0]
10612140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptbase.dll [lacks WinVerifyTrust]
10622140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc970000 'C:\Windows\system32\CRYPTBASE.dll'
10632140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
10642140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e4220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Skype\Phone\;C:\Program Files\OpenVPN\bin [calling]
10652140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000076b40000 'C:\Windows\system32\kernel32.dll'
10662140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
10672140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\WINTRUST.DLL (Input=WINTRUST.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e4220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Skype\Phone\;C:\Program Files\OpenVPN\bin [calling]
10682140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcb70000 'C:\Windows\system32\WINTRUST.DLL'
10692140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
10702140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPT32.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00000000007e4220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Skype\Phone\;C:\Program Files\OpenVPN\bin [calling]
10712140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcc40000 'C:\Windows\system32\CRYPT32.dll'
10722140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
10732140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'advapi32.dll'.
10742140.19c8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\imagehlp.dll)
10752140.19c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\imagehlp.dll
10762140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
10772140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
10782140.19c8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
10792140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
10802140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
10812140.19c8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
10822140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\imagehlp.dll (Input=imagehlp.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e4220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Skype\Phone\;C:\Program Files\OpenVPN\bin [calling]
10832140.19c8: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\imagehlp.dll [lacks WinVerifyTrust]
10842140.19c8: supR3HardenedDllNotificationCallback: load 000007fefef70000 LB 0x00019000 C:\Windows\system32\imagehlp.dll [fFlags=0x0]
10852140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\imagehlp.dll [lacks WinVerifyTrust]
10862140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefef70000 'C:\Windows\system32\imagehlp.dll'
10872140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
10882140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTSP.dll (Input=CRYPTSP.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e4220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Skype\Phone\;C:\Program Files\OpenVPN\bin [calling]
10892140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc230000 'C:\Windows\system32\CRYPTSP.dll'
10902140.19c8: \Device\HarddiskVolume1\Windows\System32\user32.dll: Owner is administrators group.
10912140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
10922140.19c8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\user32.dll)
10932140.19c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\user32.dll
10942140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
10952140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
10962140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
10972140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'lpk.dll'.
10982140.19c8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\gdi32.dll)
10992140.19c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\gdi32.dll
11002140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'lpk.dll'...
11012140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'lpk.dll' -> '\Device\HarddiskVolume1\Windows\System32\lpk.dll' [rcNtRedir=0xc0150008]
11022140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'gdi32.dll'.
11032140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'user32.dll'.
11042140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'usp10.dll'.
11052140.19c8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\lpk.dll)
11062140.19c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\lpk.dll
11072140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
11082140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
11092140.19c8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\user32.dll [lacks WinVerifyTrust]
11102140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'usp10.dll'...
11112140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'usp10.dll' -> '\Device\HarddiskVolume1\Windows\System32\usp10.dll' [rcNtRedir=0xc0150008]
11122140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
11132140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
11142140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'gdi32.dll'.
11152140.19c8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\usp10.dll)
11162140.19c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\usp10.dll
11172140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
11182140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
11192140.19c8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\user32.dll [lacks WinVerifyTrust]
11202140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
11212140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
11222140.19c8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
11232140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
11242140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
11252140.19c8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
11262140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
11272140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
11282140.19c8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\user32.dll [lacks WinVerifyTrust]
11292140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
11302140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
11312140.19c8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
11322140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\USER32.dll (Input=USER32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e4220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Skype\Phone\;C:\Program Files\OpenVPN\bin [calling]
11332140.19c8: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\user32.dll [lacks WinVerifyTrust]
11342140.19c8: supR3HardenedDllNotificationCallback: load 0000000076c60000 LB 0x000fa000 C:\Windows\system32\USER32.dll [fFlags=0x0]
11352140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\user32.dll [lacks WinVerifyTrust]
11362140.19c8: supR3HardenedDllNotificationCallback: load 000007feff000000 LB 0x00067000 C:\Windows\system32\GDI32.dll [fFlags=0x0]
11372140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
11382140.19c8: supR3HardenedDllNotificationCallback: load 000007fefeff0000 LB 0x0000e000 C:\Windows\system32\LPK.dll [fFlags=0x0]
11392140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\lpk.dll [lacks WinVerifyTrust]
11402140.19c8: supR3HardenedDllNotificationCallback: load 000007fefd520000 LB 0x000ca000 C:\Windows\system32\USP10.dll [fFlags=0x0]
11412140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\usp10.dll [lacks WinVerifyTrust]
11422140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
11432140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\gdi32.dll (Input=gdi32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e4220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Skype\Phone\;C:\Program Files\OpenVPN\bin [calling]
11442140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff000000 'C:\Windows\system32\gdi32.dll'
11452140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'user32.dll'.
11462140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
11472140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msctf.dll'.
11482140.19c8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\imm32.dll)
11492140.19c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\imm32.dll
11502140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msctf.dll'...
11512140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msctf.dll' -> '\Device\HarddiskVolume1\Windows\System32\msctf.dll' [rcNtRedir=0xc0150008]
11522140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
11532140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
11542140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'gdi32.dll'.
11552140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'imm32.dll'.
11562140.19c8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\msctf.dll)
11572140.19c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\msctf.dll
11582140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
11592140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
11602140.19c8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
11612140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
11622140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
11632140.19c8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\user32.dll [lacks WinVerifyTrust]
11642140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
11652140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume1\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
11662140.19c8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\imm32.dll [lacks WinVerifyTrust]
11672140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
11682140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
11692140.19c8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
11702140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
11712140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
11722140.19c8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\user32.dll [lacks WinVerifyTrust]
11732140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
11742140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
11752140.19c8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
11762140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\IMM32.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e4220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Skype\Phone\;C:\Program Files\OpenVPN\bin [calling]
11772140.19c8: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\imm32.dll [lacks WinVerifyTrust]
11782140.19c8: supR3HardenedDllNotificationCallback: load 000007fefd400000 LB 0x0002e000 C:\Windows\system32\IMM32.DLL [fFlags=0x0]
11792140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\imm32.dll [lacks WinVerifyTrust]
11802140.19c8: supR3HardenedDllNotificationCallback: load 000007fefee60000 LB 0x00109000 C:\Windows\system32\MSCTF.dll [fFlags=0x0]
11812140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msctf.dll [lacks WinVerifyTrust]
11822140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd400000 'C:\Windows\system32\IMM32.DLL'
11832140.19c8: \Device\HarddiskVolume1\Program Files (x86)\KeyCryptSDK: Owner is administrators group.
11842140.19c8: supHardenedWinVerifyImageByHandle: -> -23021 (\Device\HarddiskVolume1\Program Files (x86)\KeyCryptSDK潎敮漠⁦桴⁥‱慰桴猨

1185慨敶愠琠畲瑳愠据潨⹲›䑜癥捩履慈摲楤歳潖畬敭就牐杯慲楆敬⁳砨㘸尩敋䍹祲瑰䑓躽闦ꂼ臢뒡臢놀藦뒡賧ꦀ藦뚕蓦ꂐ闧뎑蓦꺍뷦늹胢º)
11862140.19c8: Error (rc=0):
11872140.19c8: supR3HardenedScreenImage/LdrLoadDll: rc=Unknown Status -23021 (0xffffa613) fImage=1 fProtect=0x0 fAccess=0x0 \Device\HarddiskVolume1\Program Files (x86)\KeyCryptSDK潎敮漠⁦桴⁥‱慰桴猨

1188慨敶愠琠畲瑳愠据潨⹲›䑜癥捩履慈摲楤歳潖畬敭就牐杯慲楆敬⁳砨㘸尩敋䍹祲瑰䑓躽闦ꂼ臢뒡臢놀藦뒡賧ꦀ藦뚕蓦ꂐ闧뎑蓦꺍뷦늹胢º: None of the 1 path(s) have a trust anchor.: \Device\HarddiskVolume1\Program Files (x86)\KeyCryptSDK潎敮漠⁦桴⁥‱慰桴猨

1189慨敶愠琠畲瑳愠据潨⹲›
11902140.19c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files (x86)\KeyCryptSDK潎敮漠⁦桴⁥‱慰桴猨

1191慨敶愠琠畲瑳愠据潨⹲›䑜癥捩履慈摲楤歳潖畬敭就牐杯慲楆敬⁳砨㘸尩敋䍹祲瑰䑓躽闦ꂼ臢뒡臢놀藦뒡賧ꦀ藦뚕蓦ꂐ闧뎑蓦꺍뷦늹胢º
11922140.19c8: Error (rc=0):
11932140.19c8: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\PROGRA~2\KEYCRY~1\KEYCRY~4.DLL' (C:\PROGRA~2\KEYCRY~1\KEYCRY~4.DLL): rcNt=0xc0000190
11942140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\PROGRA~2\KEYCRY~1\KEYCRY~4.DLL'
11952140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000076c60000 'C:\Windows\system32\USER32.dll'
11962140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'bcrypt.dll'.
11972140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
11982140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msasn1.dll'.
11992140.19c8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\ncrypt.dll)
12002140.19c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\ncrypt.dll
12012140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
12022140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume1\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
12032140.19c8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
12042140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
12052140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
12062140.19c8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
12072140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
12082140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume1\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
12092140.19c8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
12102140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ncrypt.dll (Input=ncrypt.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e4220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Skype\Phone\;C:\Program Files\OpenVPN\bin [calling]
12112140.19c8: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\ncrypt.dll [lacks WinVerifyTrust]
12122140.19c8: supR3HardenedDllNotificationCallback: load 000007fefc3d0000 LB 0x00050000 C:\Windows\system32\ncrypt.dll [fFlags=0x0]
12132140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\ncrypt.dll [lacks WinVerifyTrust]
12142140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc3d0000 'C:\Windows\system32\ncrypt.dll'
12152140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
12162140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcrypt.dll (Input=bcrypt.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e4220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Skype\Phone\;C:\Program Files\OpenVPN\bin [calling]
12172140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc3a0000 'C:\Windows\system32\bcrypt.dll'
12182140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
12192140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'rpcrt4.dll'.
12202140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'profapi.dll'.
12212140.19c8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\userenv.dll)
12222140.19c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\userenv.dll
12232140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'profapi.dll'...
12242140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'profapi.dll' -> '\Device\HarddiskVolume1\Windows\System32\profapi.dll' [rcNtRedir=0xc0150008]
12252140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
12262140.19c8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\profapi.dll)
12272140.19c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\profapi.dll
12282140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
12292140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
12302140.19c8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
12312140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
12322140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
12332140.19c8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
12342140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
12352140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
12362140.19c8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
12372140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\USERENV.dll (Input=USERENV.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e4220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Skype\Phone\;C:\Program Files\OpenVPN\bin [calling]
12382140.19c8: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\userenv.dll [lacks WinVerifyTrust]
12392140.19c8: supR3HardenedDllNotificationCallback: load 000007fefcb40000 LB 0x0001e000 C:\Windows\system32\USERENV.dll [fFlags=0x0]
12402140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\userenv.dll [lacks WinVerifyTrust]
12412140.19c8: supR3HardenedDllNotificationCallback: load 000007fefcb10000 LB 0x0000f000 C:\Windows\system32\profapi.dll [fFlags=0x0]
12422140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\profapi.dll [lacks WinVerifyTrust]
12432140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcb40000 'C:\Windows\system32\USERENV.dll'
12442140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007e4220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Skype\Phone\;C:\Program Files\OpenVPN\bin [calling]
12452140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefee40000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
12462140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007e4220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Skype\Phone\;C:\Program Files\OpenVPN\bin [calling]
12472140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefee40000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
12482140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
12492140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'rpcrt4.dll'.
12502140.19c8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\gpapi.dll)
12512140.19c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\gpapi.dll
12522140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
12532140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
12542140.19c8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
12552140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
12562140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
12572140.19c8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
12582140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\GPAPI.dll (Input=GPAPI.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e4220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Skype\Phone\;C:\Program Files\OpenVPN\bin [calling]
12592140.19c8: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\gpapi.dll [lacks WinVerifyTrust]
12602140.19c8: supR3HardenedDllNotificationCallback: load 000007fefbcc0000 LB 0x0001b000 C:\Windows\system32\GPAPI.dll [fFlags=0x0]
12612140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\gpapi.dll [lacks WinVerifyTrust]
12622140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbcc0000 'C:\Windows\system32\GPAPI.dll'
12632140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-Management-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007e4220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Skype\Phone\;C:\Program Files\OpenVPN\bin [calling]
12642140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefee40000 'API-MS-WIN-Service-Management-L1-1-0.dll'
12652140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
12662140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rpcrt4.dll (Input=rpcrt4.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e4220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Skype\Phone\;C:\Program Files\OpenVPN\bin [calling]
12672140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcfa0000 'C:\Windows\system32\rpcrt4.dll'
12682140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-Management-L2-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007e4220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Skype\Phone\;C:\Program Files\OpenVPN\bin [calling]
12692140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefee40000 'API-MS-WIN-Service-Management-L2-1-0.dll'
12702140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007e4220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Skype\Phone\;C:\Program Files\OpenVPN\bin [calling]
12712140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefee40000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
12722140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
12732140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'advapi32.dll'.
12742140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'crypt32.dll'.
12752140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'wldap32.dll'.
12762140.19c8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\cryptnet.dll)
12772140.19c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\cryptnet.dll
12782140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wldap32.dll'...
12792140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'wldap32.dll' -> '\Device\HarddiskVolume1\Windows\System32\wldap32.dll' [rcNtRedir=0xc0150008]
12802140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
12812140.19c8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\Wldap32.dll)
12822140.19c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\Wldap32.dll
12832140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
12842140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume1\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
12852140.19c8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
12862140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
12872140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
12882140.19c8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
12892140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
12902140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
12912140.19c8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
12922140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
12932140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
12942140.19c8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
12952140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (Input=cryptnet.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e4220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Skype\Phone\;C:\Program Files\OpenVPN\bin [calling]
12962140.19c8: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
12972140.19c8: supR3HardenedDllNotificationCallback: load 000007fefaab0000 LB 0x00027000 C:\Windows\system32\cryptnet.dll [fFlags=0x0]
12982140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
12992140.19c8: supR3HardenedDllNotificationCallback: load 000007fefef90000 LB 0x00052000 C:\Windows\system32\WLDAP32.dll [fFlags=0x0]
13002140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\Wldap32.dll [lacks WinVerifyTrust]
13012140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
13022140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00000000007e4220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Skype\Phone\;C:\Program Files\OpenVPN\bin [calling]
13032140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefaab0000 'C:\Windows\system32\cryptnet.dll'
13042140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
13052140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00000000007e4220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Skype\Phone\;C:\Program Files\OpenVPN\bin [calling]
13062140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefaab0000 'C:\Windows\system32\cryptnet.dll'
13072140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
13082140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00000000007e4220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Skype\Phone\;C:\Program Files\OpenVPN\bin [calling]
13092140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefaab0000 'C:\Windows\system32\cryptnet.dll'
13102140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
13112140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00000000007e4220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Skype\Phone\;C:\Program Files\OpenVPN\bin [calling]
13122140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefaab0000 'C:\Windows\system32\cryptnet.dll'
13132140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
13142140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00000000007e4220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Skype\Phone\;C:\Program Files\OpenVPN\bin [calling]
13152140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefaab0000 'C:\Windows\system32\cryptnet.dll'
13162140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
13172140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00000000007e4220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Skype\Phone\;C:\Program Files\OpenVPN\bin [calling]
13182140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefaab0000 'C:\Windows\system32\cryptnet.dll'
13192140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
13202140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefaab0000 'C:\Windows\system32\cryptnet.dll'
13212140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
13222140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefaab0000 'C:\Windows\system32\cryptnet.dll'
13232140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
13242140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefaab0000 'C:\Windows\system32\cryptnet.dll'
13252140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
13262140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefaab0000 'C:\Windows\system32\cryptnet.dll'
13272140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
13282140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefaab0000 'C:\Windows\system32\cryptnet.dll'
13292140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefaab0000 'C:\Windows\system32\cryptnet.dll'
13302140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
13312140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefaab0000 'C:\Windows\system32\cryptnet.dll'
13322140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007e4220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Skype\Phone\;C:\Program Files\OpenVPN\bin [calling]
13332140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefee40000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
13342140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\profapi.dll [lacks WinVerifyTrust]
13352140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\profapi.dll (Input=profapi.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e4220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Skype\Phone\;C:\Program Files\OpenVPN\bin [calling]
13362140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcb10000 'C:\Windows\system32\profapi.dll'
13372140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
13382140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
13392140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msvcrt.dll'.
13402140.19c8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\shlwapi.dll)
13412140.19c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\shlwapi.dll
13422140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
13432140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
13442140.19c8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
13452140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
13462140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
13472140.19c8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\user32.dll [lacks WinVerifyTrust]
13482140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
13492140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
13502140.19c8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
13512140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\SHLWAPI.dll (Input=SHLWAPI.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e4220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Skype\Phone\;C:\Program Files\OpenVPN\bin [calling]
13522140.19c8: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\shlwapi.dll [lacks WinVerifyTrust]
13532140.19c8: supR3HardenedDllNotificationCallback: load 000007fefd2e0000 LB 0x00071000 C:\Windows\system32\SHLWAPI.dll [fFlags=0x0]
13542140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\shlwapi.dll [lacks WinVerifyTrust]
13552140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd2e0000 'C:\Windows\system32\SHLWAPI.dll'
13562140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000000 pwszName=\SystemRoot\System32\ntdll.dll
13572140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: New context 00000000008b58e0
13582140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b58e0
13592140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=99113493CCEA6CE03AD58304FCE46D35B665BC85
13602140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007e4220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Skype\Phone\;C:\Program Files\OpenVPN\bin [calling]
13612140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefee40000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
13622140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-Management-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007e4220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Skype\Phone\;C:\Program Files\OpenVPN\bin [calling]
13632140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefee40000 'API-MS-WIN-Service-Management-L1-1-0.dll'
13642140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-winsvc-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007e4220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Skype\Phone\;C:\Program Files\OpenVPN\bin [calling]
13652140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefee40000 'API-MS-WIN-Service-winsvc-L1-1-0.dll'
13662140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
13672140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ADVAPI32.dll (Input=ADVAPI32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e4220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Skype\Phone\;C:\Program Files\OpenVPN\bin [calling]
13682140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdad0000 'C:\Windows\system32\ADVAPI32.dll'
13692140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-LSALookup-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007e4220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Skype\Phone\;C:\Program Files\OpenVPN\bin [calling]
13702140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefee40000 'API-MS-Win-Security-LSALookup-L1-1-0.dll'
13712140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-LSALookup-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007e4220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Skype\Phone\;C:\Program Files\OpenVPN\bin [calling]
13722140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefee40000 'API-MS-Win-Security-LSALookup-L1-1-0.dll'
13732140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_60_for_KB3121212~31bf3856ad364e35~amd64~~6.1.1.2.cat'; file='\SystemRoot\System32\ntdll.dll'
13742140.19c8: g_pfnWinVerifyTrust=000007fefcb71010
13752140.19c8: supR3HardenedScreenImage/preload: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\crypt32.dll [redoing WinVerifyTrust]
13762140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000e0 pwszName=\Device\HarddiskVolume1\Windows\System32\crypt32.dll
13772140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b58e0
13782140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b58e0
13792140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=BFD41401EDEBD4D914977D62B588ECABEE60CFD3
13802140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_112_for_KB3040272~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume1\Windows\System32\crypt32.dll'
13812140.19c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
13822140.19c8: supR3HardenedScreenImage/preload: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\crypt32.dll'
13832140.19c8: supR3HardenedScreenImage/preload: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\wintrust.dll [redoing WinVerifyTrust]
13842140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000d4 pwszName=\Device\HarddiskVolume1\Windows\System32\wintrust.dll
13852140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b58e0
13862140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b58e0
13872140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=E1BBE4EB6D114F50142F24E2E2749EFD81021486
13882140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_75_for_KB3040272~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume1\Windows\System32\wintrust.dll'
13892140.19c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
13902140.19c8: supR3HardenedScreenImage/preload: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\wintrust.dll'
13912140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000394 pwszName=\Device\HarddiskVolume1\Windows\System32\shlwapi.dll
13922140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b58e0
13932140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b58e0
13942140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=0AB8D9C9D3E1FC95D01F9A984B16ED031BB40CD8
13952140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\shlwapi.dll'
13962140.19c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
13972140.19c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\shlwapi.dll'
13982140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000388 pwszName=\Device\HarddiskVolume1\Windows\System32\Wldap32.dll
13992140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b58e0
14002140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b58e0
14012140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=87E73086F2528CF31D3AD5F0D71E04F8B942D5D8
14022140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\Wldap32.dll'
14032140.19c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
14042140.19c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\Wldap32.dll'
14052140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000384 pwszName=\Device\HarddiskVolume1\Windows\System32\cryptnet.dll
14062140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b58e0
14072140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b58e0
14082140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=756DC088EE40CF9369C990D71B200F3CB59FC35D
14092140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_75_for_KB3040272~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume1\Windows\System32\cryptnet.dll'
14102140.19c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
14112140.19c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\cryptnet.dll'
14122140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000264 pwszName=\Device\HarddiskVolume1\Windows\System32\gpapi.dll
14132140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b58e0
14142140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b58e0
14152140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=470795C189226F7BDB8E50F42104CC34488B9340
14162140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\gpapi.dll'
14172140.19c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
14182140.19c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\gpapi.dll'
14192140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000001d0 pwszName=\Device\HarddiskVolume1\Windows\System32\profapi.dll
14202140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b58e0
14212140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b58e0
14222140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2449672745D9BA339420451D13FA0380AA768231
14232140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume1\Windows\System32\profapi.dll'
14242140.19c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
14252140.19c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\profapi.dll'
14262140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000001cc pwszName=\Device\HarddiskVolume1\Windows\System32\userenv.dll
14272140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b58e0
14282140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b58e0
14292140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=D3E1A2CC7367F751C19EBF4E6EDF5E9A10E47313
14302140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\userenv.dll'
14312140.19c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
14322140.19c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\userenv.dll'
14332140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000001ac pwszName=\Device\HarddiskVolume1\Windows\System32\ncrypt.dll
14342140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b58e0
14352140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b58e0
14362140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=AF6214D5B4EE4D004FA11B4426B0E781D4E918A9
14372140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_60_for_KB3121212~31bf3856ad364e35~amd64~~6.1.1.2.cat'; file='\Device\HarddiskVolume1\Windows\System32\ncrypt.dll'
14382140.19c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
14392140.19c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\ncrypt.dll'
14402140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000194 pwszName=\Device\HarddiskVolume1\Windows\System32\msctf.dll
14412140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b58e0
14422140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b58e0
14432140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=03916BC73EE5A0E312E3D3100D0ACE1B78E93BB1
14442140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3033889~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume1\Windows\System32\msctf.dll'
14452140.19c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
14462140.19c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\msctf.dll'
14472140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000190 pwszName=\Device\HarddiskVolume1\Windows\System32\imm32.dll
14482140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b58e0
14492140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b58e0
14502140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=6EEE1AB3B6D79AFF857940FF5F51ED27698153EC
14512140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume1\Windows\System32\imm32.dll'
14522140.19c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
14532140.19c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\imm32.dll'
14542140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000018c pwszName=\Device\HarddiskVolume1\Windows\System32\usp10.dll
14552140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b58e0
14562140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b58e0
14572140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=31498ABFB06219E83141E0AA8B2A55C4CECFD033
14582140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3108670~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume1\Windows\System32\usp10.dll'
14592140.19c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
14602140.19c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\usp10.dll'
14612140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000188 pwszName=\Device\HarddiskVolume1\Windows\System32\lpk.dll
14622140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b58e0
14632140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b58e0
14642140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=FDBA63132AE4F561C5CFC5478222E40A2DAA2ACC
14652140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3087039~31bf3856ad364e35~amd64~~6.1.1.4.cat'; file='\Device\HarddiskVolume1\Windows\System32\lpk.dll'
14662140.19c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
14672140.19c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\lpk.dll'
14682140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000184 pwszName=\Device\HarddiskVolume1\Windows\System32\gdi32.dll
14692140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b58e0
14702140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b58e0
14712140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=E200CE23C0ADD95195EBA5616D50363CEA00DB25
14722140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3124001~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume1\Windows\System32\gdi32.dll'
14732140.19c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
14742140.19c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\gdi32.dll'
14752140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000180 pwszName=\Device\HarddiskVolume1\Windows\System32\user32.dll
14762140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b58e0
14772140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b58e0
14782140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=FB05A6DD4AF9AC247D37C4B7BAFCCBD178A41E64
14792140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: Retrying with fresh context (CryptCATAdminEnumCatalogFromHash -> 1168; iCat=0x0)
14802140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: New context 00000000008b58e0
14812140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b58e0
14822140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=FB05A6DD4AF9AC247D37C4B7BAFCCBD178A41E64
14832140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: CryptCATAdminEnumCatalogFromHash failed ERRROR_NOT_FOUND (1168)
14842140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: New context 00000000008b5ee0
14852140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b5ee0
14862140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=32 wszDigest=7458187B83265348D287AC7AB34C0A5AD0EFDAA5040E43F37D2AC3DBEB747E20
14872140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: CryptCATAdminEnumCatalogFromHash failed ERRROR_NOT_FOUND (1168)
14882140.19c8: supR3HardNtViCallWinVerifyTrustCatFile -> -22900 (org 22900)
14892140.19c8: supR3HardenedWinVerifyCacheProcessWvtTodos: -22900 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\user32.dll'
14902140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000017c pwszName=\Device\HarddiskVolume1\Windows\System32\imagehlp.dll
14912140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b58e0
14922140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b58e0
14932140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2702EE05F1B717B0F2CE0FBE32784A47B8419DCA
14942140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_2_for_KB2893294~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume1\Windows\System32\imagehlp.dll'
14952140.19c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
14962140.19c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\imagehlp.dll'
14972140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000130 pwszName=\Device\HarddiskVolume1\Windows\System32\cryptbase.dll
14982140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b58e0
14992140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b58e0
15002140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=C369CA0A282E9201E8C3399DEF1010F6DC0676FA
15012140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_60_for_KB3121212~31bf3856ad364e35~amd64~~6.1.1.2.cat'; file='\Device\HarddiskVolume1\Windows\System32\cryptbase.dll'
15022140.19c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
15032140.19c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\cryptbase.dll'
15042140.19c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\rsaenh.dll'
15052140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000012c pwszName=\Device\HarddiskVolume1\Windows\System32\cryptsp.dll
15062140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b58e0
15072140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b58e0
15082140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=BA7AC4A7E8ADDFEA90AC951ECB6D6546E4873613
15092140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_115_for_KB3033929~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume1\Windows\System32\cryptsp.dll'
15102140.19c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
15112140.19c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\cryptsp.dll'
15122140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000120 pwszName=\Device\HarddiskVolume1\Windows\System32\sechost.dll
15132140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b58e0
15142140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b58e0
15152140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=3FA2A014BF360CDC0E203A174FFC9DC5343C5323
15162140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume1\Windows\System32\sechost.dll'
15172140.19c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
15182140.19c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\sechost.dll'
15192140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000011c pwszName=\Device\HarddiskVolume1\Windows\System32\advapi32.dll
15202140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b58e0
15212140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b58e0
15222140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=6964F437558F504725B2BE66A35240231044644F
15232140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3121918~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume1\Windows\System32\advapi32.dll'
15242140.19c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
15252140.19c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\advapi32.dll'
15262140.19c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\bcryptprimitives.dll'
15272140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000104 pwszName=\Device\HarddiskVolume1\Windows\System32\bcrypt.dll
15282140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b58e0
15292140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b58e0
15302140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=62E377A1F0AD0C2EDC0A73CB3EFF841FF18D00D2
15312140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume1\Windows\System32\bcrypt.dll'
15322140.19c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
15332140.19c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\bcrypt.dll'
15342140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000e4 pwszName=\Device\HarddiskVolume1\Windows\System32\msvcrt.dll
15352140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b58e0
15362140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b58e0
15372140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2CA2FD632B264C063162F71474266E3615B6420C
15382140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB2654428~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume1\Windows\System32\msvcrt.dll'
15392140.19c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
15402140.19c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll'
15412140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000dc pwszName=\Device\HarddiskVolume1\Windows\System32\msasn1.dll
15422140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b58e0
15432140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b58e0
15442140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F2FF57DC30D774F93061607060DAA0DD15E39CCE
15452140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\msasn1.dll'
15462140.19c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
15472140.19c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\msasn1.dll'
15482140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000d8 pwszName=\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll
15492140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b58e0
15502140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b58e0
15512140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=DA2C80E31A4EEBFA49ACC284D4C1B701145978CB
15522140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_60_for_KB3121212~31bf3856ad364e35~amd64~~6.1.1.2.cat'; file='\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll'
15532140.19c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
15542140.19c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll'
15552140.19c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxSupLib.dll'
15562140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000028 pwszName=\Device\HarddiskVolume1\Windows\System32\KernelBase.dll
15572140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b58e0
15582140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b58e0
15592140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=345936918DE59E26BE1BF613500ED5E48C26873F
15602140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_60_for_KB3121212~31bf3856ad364e35~amd64~~6.1.1.2.cat'; file='\Device\HarddiskVolume1\Windows\System32\KernelBase.dll'
15612140.19c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
15622140.19c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\KernelBase.dll'
15632140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000020 pwszName=\Device\HarddiskVolume1\Windows\System32\kernel32.dll
15642140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b58e0
15652140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b58e0
15662140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=C5B3709F99BA1F5F78D42BD62B72E557388B5AE0
15672140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_60_for_KB3121212~31bf3856ad364e35~amd64~~6.1.1.2.cat'; file='\Device\HarddiskVolume1\Windows\System32\kernel32.dll'
15682140.19c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
15692140.19c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\kernel32.dll'
15702140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\crypt32.dll
15712140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\crypt32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000008d4d40:C:\Windows\system32 [calling]
15722140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcc40000 'C:\Windows\system32\crypt32.dll'
15732140.19c8: supR3HardenedWinIsDesiredRootCA: Adding 0x5ad46780fa5df300 DC=com, DC=microsoft, CN=Microsoft Root Certificate Authority
15742140.19c8: supR3HardenedWinIsDesiredRootCA: Adding 0xea5386456178582b C=ZA, ST=Western Cape, L=Durbanville, O=Thawte, OU=Thawte Certification, CN=Thawte Timestamping CA
15752140.19c8: supR3HardenedWinIsDesiredRootCA: Adding 0x3be670c1bd02a900 OU=Copyright (c) 1997 Microsoft Corp., OU=Microsoft Corporation, CN=Microsoft Root Authority
15762140.19c8: supR3HardenedWinIsDesiredRootCA: Adding 0x4d3835aa4180b200 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2011
15772140.19c8: supR3HardenedWinIsDesiredRootCA: Adding 0x646e3fe3ba08df00 C=US, O=MSFT, CN=Microsoft Authenticode(tm) Root Authority
15782140.19c8: supR3HardenedWinIsDesiredRootCA: Adding 0xece4e4289e08b900 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010
15792140.19c8: supR3HardenedWinIsDesiredRootCA: Adding 0x89aff3418b3ce200 C=US, L=Silicon Valley, O=Authenticode, CN=Google
15802140.19c8: supR3HardenedWinIsDesiredRootCA: Adding 0x43a9cc371ff5385a O=Microsoft Trust Network, OU=Microsoft Corporation, OU=Microsoft Time Stamping Service Root, OU=Copyright (c) 1997 Microsoft Corp.
15812140.19c8: supR3HardenedWinIsDesiredRootCA: Adding 0x2e2d2c7c68f0202e O=VeriSign Trust Network, OU=VeriSign, Inc., OU=VeriSign Time Stamping Service Root, OU=NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.
15822140.19c8: supR3HardenedWinIsDesiredRootCA: Adding 0xd8dbfb2c27bfb200 C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2008 thawte, Inc. - For authorized use only, CN=thawte Primary Root CA - G3
15832140.19c8: supR3HardenedWinIsDesiredRootCA: Adding 0x61a3a33f81aace00 C=US, ST=UT, L=Salt Lake City, O=The USERTRUST Network, OU=http://www.usertrust.com, CN=UTN-USERFirst-Object
15842140.19c8: supR3HardenedWinIsDesiredRootCA: Adding 0x57ba5395b561bf00 C=BM, O=QuoVadis Limited, OU=Root Certification Authority, CN=QuoVadis Root Certification Authority
15852140.19c8: supR3HardenedWinIsDesiredRootCA: Adding 0xf4fd306318ccda00 C=US, O=GeoTrust Inc., CN=GeoTrust Global CA
15862140.19c8: supR3HardenedWinIsDesiredRootCA: Adding 0x83085097e9afdf00 O=Digital Signature Trust Co., CN=DST Root CA X3
15872140.19c8: supR3HardenedWinIsDesiredRootCA: Adding 0x780679907625cc00 OU=GlobalSign Root CA - R3, O=GlobalSign, CN=GlobalSign
15882140.19c8: supR3HardenedWinIsDesiredRootCA: Adding 0x3d98ab22bb04a300 C=IE, O=Baltimore, OU=CyberTrust, CN=Baltimore CyberTrust Root
15892140.19c8: supR3HardenedWinIsDesiredRootCA: Adding 0xa0ee62086758b15d C=US, O=Equifax, OU=Equifax Secure Certificate Authority
15902140.19c8: supR3HardenedWinIsDesiredRootCA: Adding 0x1591b8ac8dcabd00 C=CN, O=WoSign CA Limited, CN=Certification Authority of WoSign
15912140.19c8: supR3HardenedWinIsDesiredRootCA: Adding 0x8ff6fc03c1edbd00 C=US, ST=Arizona, L=Scottsdale, O=Starfield Technologies, Inc., CN=Starfield Root Certificate Authority - G2
15922140.19c8: supR3HardenedWinIsDesiredRootCA: Adding 0xc6fa4243b695b600 C=US, O=Entrust, Inc., OU=www.entrust.net/CPS is incorporated by reference, OU=(c) 2006 Entrust, Inc., CN=Entrust Root Certification Authority
15932140.19c8: supR3HardenedWinIsDesiredRootCA: Adding 0xa3ce8d99e60eda00 C=BE, O=GlobalSign nv-sa, OU=Root CA, CN=GlobalSign Root CA
15942140.19c8: supR3HardenedWinIsDesiredRootCA: Adding 0xa671e9fec832b700 C=US, O=Starfield Technologies, Inc., OU=Starfield Class 2 Certification Authority
15952140.19c8: supR3HardenedWinIsDesiredRootCA: Adding 0xa8de7211e13be200 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root CA
15962140.19c8: supR3HardenedWinIsDesiredRootCA: Adding 0x7ae89c50f0b6a00f C=US, O=GTE Corporation, OU=GTE CyberTrust Solutions, Inc., CN=GTE CyberTrust Global Root
15972140.19c8: supR3HardenedWinIsDesiredRootCA: Adding 0xd45980fbf0a0ac00 C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2006 thawte, Inc. - For authorized use only, CN=thawte Primary Root CA
15982140.19c8: supR3HardenedWinIsDesiredRootCA: Adding 0xf5cd95e581a4ab00 C=US, O=SecureTrust Corporation, CN=SecureTrust CA
15992140.19c8: supR3HardenedWinIsDesiredRootCA: Adding 0x6f2ebe0e24cfa600 OU=GlobalSign Root CA - R2, O=GlobalSign, CN=GlobalSign
16002140.19c8: supR3HardenedWinIsDesiredRootCA: Adding 0x14018a1bf29e595c C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority
16012140.19c8: supR3HardenedWinIsDesiredRootCA: Adding 0x9e5bc2d78b6a3636 C=ZA, ST=Western Cape, L=Cape Town, O=Thawte Consulting cc, OU=Certification Services Division, CN=Thawte Premium Server CA, [email protected]
16022140.19c8: supR3HardenedWinIsDesiredRootCA: Adding 0x7c4fd32ec1b1ce00 C=PL, O=Unizeto Sp. z o.o., CN=Certum CA
16032140.19c8: supR3HardenedWinIsDesiredRootCA: Adding 0xd4fbe673e5ccc600 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA
16042140.19c8: supR3HardenedWinIsDesiredRootCA: Adding 0x16e64d2a56ccf200 C=US, ST=Arizona, L=Scottsdale, O=Starfield Technologies, Inc., OU=http://certificates.starfieldtech.com/repository/, CN=Starfield Services Root Certificate Authority
16052140.19c8: supR3HardenedWinIsDesiredRootCA: Adding 0xb28612a94b4dad00 O=Entrust.net, OU=www.entrust.net/CPS_2048 incorp. by ref. (limits liab.), OU=(c) 1999 Entrust.net Limited, CN=Entrust.net Certification Authority (2048)
16062140.19c8: supR3HardenedWinIsDesiredRootCA: Adding 0x357a29080824af00 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2006 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G5
16072140.19c8: supR3HardenedWinIsDesiredRootCA: Adding 0x59faf1086271bf00 C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com, Inc., CN=Go Daddy Root Certificate Authority - G2
16082140.19c8: supR3HardenedWinIsDesiredRootCA: Adding 0x466cbc09db88c100 C=IL, O=StartCom Ltd., OU=Secure Digital Certificate Signing, CN=StartCom Certification Authority
16092140.19c8: supR3HardenedWinIsDesiredRootCA: Adding 0x3401b15e3761c700 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2008 VeriSign, Inc. - For authorized use only, CN=VeriSign Universal Root Certification Authority
16102140.19c8: supR3HardenedWinIsDesiredRootCA: Adding 0x7cd4ff7b15b8be00 C=US, O=GeoTrust Inc., CN=GeoTrust Primary Certification Authority
16112140.19c8: supR3HardenedWinIsDesiredRootCA: Adding 0x491857ead79dde00 C=US, O=The Go Daddy Group, Inc., OU=Go Daddy Class 2 Certification Authority
16122140.19c8: supR3HardenedWinIsDesiredRootCA: Adding 0x1f78fc529cbacb00 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 1999 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G3
16132140.19c8: supR3HardenedWinIsDesiredRootCA: Adding 0x8043e4ce150ead00 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID Root CA
16142140.19c8: supR3HardenedWinIsDesiredRootCA: Adding 0xa8b43f38c3f7b100 C=US, ST=UT, L=Salt Lake City, O=The USERTRUST Network, OU=http://www.usertrust.com, CN=UTN-USERFirst-Hardware
16152140.19c8: supR3HardenedWinIsDesiredRootCA: Adding 0x331d58625ee2dc00 C=US, O=GeoTrust Inc., OU=(c) 2008 GeoTrust Inc. - For authorized use only, CN=GeoTrust Primary Certification Authority - G3
16162140.19c8: supR3HardenedWinIsDesiredRootCA: Adding 0xf2e6331af7b700 C=SE, O=AddTrust AB, OU=AddTrust External TTP Network, CN=AddTrust External CA Root
16172140.19c8: supR3HardenedWinRetrieveTrustedRootCAs: cAdded=44
16182140.19c8: SUPR3HardenedMain: Load Runtime...
16192140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
16202140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
16212140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ws2_32.dll'.
16222140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'rpcrt4.dll'.
16232140.19c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxRT.dll) WinVerifyTrust
16242140.19c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxRT.dll
16252140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
16262140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
16272140.19c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\rpcrt4.dll
16282140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
16292140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
16302140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000003b8 pwszName=\Device\HarddiskVolume1\Windows\System32\ws2_32.dll
16312140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b58e0
16322140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b58e0
16332140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=3EF3BDC1E84DFA17EA056313214EE88EC3E66F79
16342140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\ws2_32.dll'
16352140.19c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
16362140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
16372140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'rpcrt4.dll'.
16382140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'nsi.dll'.
16392140.19c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\ws2_32.dll) WinVerifyTrust
16402140.19c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\ws2_32.dll
16412140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
16422140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
16432140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
16442140.19c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcp100.dll) WinVerifyTrust
16452140.19c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcp100.dll
16462140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
16472140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
16482140.19c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcr100.dll) WinVerifyTrust
16492140.19c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcr100.dll
16502140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
16512140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
16522140.19c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcr100.dll
16532140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
16542140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume1\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
16552140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000418 pwszName=\Device\HarddiskVolume1\Windows\System32\nsi.dll
16562140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b58e0
16572140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b58e0
16582140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=7AFD8538945F2D05BC1AF949B9B19B7D2D9FBBF8
16592140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume1\Windows\System32\nsi.dll'
16602140.19c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
16612140.19c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\nsi.dll) WinVerifyTrust
16622140.19c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\nsi.dll
16632140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
16642140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
16652140.19c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\rpcrt4.dll
16662140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
16672140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
16682140.19c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll
16692140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000085d220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
16702140.19c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxRT.dll
16712140.19c8: supR3HardenedDllNotificationCallback: load 000007fee4790000 LB 0x0055a000 C:\Program Files\Oracle\VirtualBox\VBoxRT.dll [fFlags=0x0]
16722140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxRT.dll
16732140.19c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcr100.dll
16742140.19c8: supR3HardenedDllNotificationCallback: load 0000000073c70000 LB 0x000d2000 C:\Program Files\Oracle\VirtualBox\MSVCR100.dll [fFlags=0x0]
16752140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcr100.dll
16762140.19c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcp100.dll
16772140.19c8: supR3HardenedDllNotificationCallback: load 0000000073bd0000 LB 0x00098000 C:\Program Files\Oracle\VirtualBox\MSVCP100.dll [fFlags=0x0]
16782140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcp100.dll
16792140.19c8: supR3HardenedDllNotificationCallback: load 000007fefd4d0000 LB 0x0004d000 C:\Windows\system32\WS2_32.dll [fFlags=0x0]
16802140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ws2_32.dll
16812140.19c8: supR3HardenedDllNotificationCallback: load 000007fefdd90000 LB 0x00008000 C:\Windows\system32\NSI.dll [fFlags=0x0]
16822140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\nsi.dll
16832140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxRT.dll
16842140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e4220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Skype\Phone\;C:\Program Files\OpenVPN\bin [calling]
16852140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4790000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
16862140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxRT.dll
16872140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e4220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Skype\Phone\;C:\Program Files\OpenVPN\bin [calling]
16882140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4790000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
16892140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxRT.dll
16902140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e4220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Skype\Phone\;C:\Program Files\OpenVPN\bin [calling]
16912140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4790000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
16922140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxRT.dll
16932140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e4220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Skype\Phone\;C:\Program Files\OpenVPN\bin [calling]
16942140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4790000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
16952140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxRT.dll
16962140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e4220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Skype\Phone\;C:\Program Files\OpenVPN\bin [calling]
16972140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4790000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
16982140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxRT.dll
16992140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e4220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Skype\Phone\;C:\Program Files\OpenVPN\bin [calling]
17002140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4790000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
17012140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4790000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
17022140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4790000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
17032140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4790000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
17042140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4790000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
17052140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4790000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
17062140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4790000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
17072140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4790000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
17082140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxRT.dll
17092140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e4220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Skype\Phone\;C:\Program Files\OpenVPN\bin [calling]
17102140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4790000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
17112140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4790000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
17122140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4790000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
17132140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4790000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
17142140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4790000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
17152140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4790000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
17162140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4790000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
17172140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4790000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
17182140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4790000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
17192140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4790000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
17202140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4790000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
17212140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4790000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
17222140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4790000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
17232140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4790000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
17242140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4790000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
17252140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4790000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
17262140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxRT.dll
17272140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e4220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Skype\Phone\;C:\Program Files\OpenVPN\bin [calling]
17282140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4790000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
17292140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4790000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
17302140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4790000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
17312140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4790000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
17322140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\wintrust.dll
17332140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000755960:C:\Windows\system32 [calling]
17342140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcb70000 'C:\Windows\system32\Wintrust.dll'
17352140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\crypt32.dll
17362140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\crypt32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000755960:C:\Windows\system32 [calling]
17372140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcc40000 'C:\Windows\system32\crypt32.dll'
17382140.19c8: SUPR3HardenedMain: Load TrustedMain...
17392140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'opengl32.dll'.
17402140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
17412140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcp100.dll'.
17422140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcr100.dll'.
17432140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qtcorevbox4.dll'.
17442140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'qtguivbox4.dll'.
17452140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'qtopenglvbox4.dll'.
17462140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'user32.dll'.
17472140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'gdi32.dll'.
17482140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'advapi32.dll'.
17492140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'shell32.dll'.
17502140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'ole32.dll'.
17512140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'oleaut32.dll'.
17522140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'comdlg32.dll'.
17532140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #15 'winmm.dll'.
17542140.19c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.dll) WinVerifyTrust
17552140.19c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.dll
17562140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
17572140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume1\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
17582140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000458 pwszName=\Device\HarddiskVolume1\Windows\System32\winmm.dll
17592140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b58e0
17602140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b58e0
17612140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=82E2B2A7826F88BEB98FFF0540C9BDB0A12F001A
17622140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume1\Windows\System32\winmm.dll'
17632140.19c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
17642140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
17652140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
17662140.19c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\winmm.dll) WinVerifyTrust
17672140.19c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\winmm.dll
17682140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comdlg32.dll'...
17692140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'comdlg32.dll' -> '\Device\HarddiskVolume1\Windows\System32\comdlg32.dll' [rcNtRedir=0xc0150008]
17702140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000438 pwszName=\Device\HarddiskVolume1\Windows\System32\comdlg32.dll
17712140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b58e0
17722140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b58e0
17732140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=66EE5BDFFA413AEA9E1FE7838A08646E94136DA5
17742140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\comdlg32.dll'
17752140.19c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
17762140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
17772140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'shlwapi.dll'.
17782140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
17792140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'gdi32.dll'.
17802140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'comctl32.dll'.
17812140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'shell32.dll'.
17822140.19c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\comdlg32.dll) WinVerifyTrust
17832140.19c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\comdlg32.dll
17842140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
17852140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume1\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
17862140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000044c pwszName=\Device\HarddiskVolume1\Windows\System32\oleaut32.dll
17872140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b58e0
17882140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b58e0
17892140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=8A837B0D823EB506C6A4C447C1962174D27ED954
17902140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3020338~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume1\Windows\System32\oleaut32.dll'
17912140.19c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
17922140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ole32.dll'.
17932140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
17942140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
17952140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'user32.dll'.
17962140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'gdi32.dll'.
17972140.19c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\oleaut32.dll) WinVerifyTrust
17982140.19c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\oleaut32.dll
17992140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
18002140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
18012140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000464 pwszName=\Device\HarddiskVolume1\Windows\System32\ole32.dll
18022140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b58e0
18032140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b58e0
18042140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2E93C1851E5754D607F55581B4DE2A30B711C830
18052140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_2_for_KB3072633~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume1\Windows\System32\ole32.dll'
18062140.19c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
18072140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
18082140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
18092140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'user32.dll'.
18102140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'rpcrt4.dll'.
18112140.19c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\ole32.dll) WinVerifyTrust
18122140.19c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\ole32.dll
18132140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
18142140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume1\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
18152140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000460 pwszName=\Device\HarddiskVolume1\Windows\System32\shell32.dll
18162140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b58e0
18172140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b58e0
18182140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=FB4A0D952E568C1E85DCE662F9A066FFB2E6CE84
18192140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3080446~31bf3856ad364e35~amd64~~6.1.1.2.cat'; file='\Device\HarddiskVolume1\Windows\System32\shell32.dll'
18202140.19c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
18212140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
18222140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #21 'shlwapi.dll'.
18232140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'user32.dll'.
18242140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #24 'gdi32.dll'.
18252140.19c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\shell32.dll) WinVerifyTrust
18262140.19c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\shell32.dll
18272140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
18282140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
18292140.19c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\advapi32.dll
18302140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
18312140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
18322140.19c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\gdi32.dll
18332140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
18342140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
18352140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtopenglvbox4.dll'...
18362140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtopenglvbox4.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\qtopenglvbox4.dll' [rcNtRedir=0xc0150008]
18372140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'opengl32.dll'.
18382140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
18392140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
18402140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qtguivbox4.dll'.
18412140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qtcorevbox4.dll'.
18422140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcr100.dll'.
18432140.19c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll) WinVerifyTrust
18442140.19c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll
18452140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtguivbox4.dll'...
18462140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtguivbox4.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\qtguivbox4.dll' [rcNtRedir=0xc0150008]
18472140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
18482140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'comdlg32.dll'.
18492140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'oleaut32.dll'.
18502140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'imm32.dll'.
18512140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'winmm.dll'.
18522140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'winspool.drv'.
18532140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ole32.dll'.
18542140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'user32.dll'.
18552140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'advapi32.dll'.
18562140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'shell32.dll'.
18572140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'qtcorevbox4.dll'.
18582140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'msvcp100.dll'.
18592140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'msvcr100.dll'.
18602140.19c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll) WinVerifyTrust
18612140.19c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll
18622140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtcorevbox4.dll'...
18632140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtcorevbox4.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\qtcorevbox4.dll' [rcNtRedir=0xc0150008]
18642140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
18652140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'ole32.dll'.
18662140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
18672140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ws2_32.dll'.
18682140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcp100.dll'.
18692140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcr100.dll'.
18702140.19c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll) WinVerifyTrust
18712140.19c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll
18722140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
18732140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
18742140.19c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcr100.dll
18752140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
18762140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
18772140.19c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcp100.dll
18782140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
18792140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
18802140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
18812140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume1\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
18822140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004a0 pwszName=\Device\HarddiskVolume1\Windows\System32\opengl32.dll
18832140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b58e0
18842140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b58e0
18852140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=608AC397FCC42B9FBAE25CB8C25EAF4C19AA384D
18862140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume1\Windows\System32\opengl32.dll'
18872140.19c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
18882140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
18892140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
18902140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'gdi32.dll'.
18912140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'glu32.dll'.
18922140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ddraw.dll'.
18932140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'user32.dll'.
18942140.19c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\opengl32.dll) WinVerifyTrust
18952140.19c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\opengl32.dll
18962140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
18972140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
18982140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ddraw.dll'...
18992140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ddraw.dll' -> '\Device\HarddiskVolume1\Windows\System32\ddraw.dll' [rcNtRedir=0xc0150008]
19002140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004a8 pwszName=\Device\HarddiskVolume1\Windows\System32\ddraw.dll
19012140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b58e0
19022140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b58e0
19032140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=24C763EA54CD792A0F1618411061DC356EE31FF6
19042140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume1\Windows\System32\ddraw.dll'
19052140.19c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
19062140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
19072140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
19082140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'dciman32.dll'.
19092140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
19102140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'setupapi.dll'.
19112140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'dwmapi.dll'.
19122140.19c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\ddraw.dll) WinVerifyTrust
19132140.19c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\ddraw.dll
19142140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'glu32.dll'...
19152140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'glu32.dll' -> '\Device\HarddiskVolume1\Windows\System32\glu32.dll' [rcNtRedir=0xc0150008]
19162140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000494 pwszName=\Device\HarddiskVolume1\Windows\System32\glu32.dll
19172140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b58e0
19182140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b58e0
19192140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=60E45AB914E06A11F44EA76C6EF750AF892F9EA2
19202140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume1\Windows\System32\glu32.dll'
19212140.19c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
19222140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
19232140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'opengl32.dll'.
19242140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
19252140.19c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\glu32.dll) WinVerifyTrust
19262140.19c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\glu32.dll
19272140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
19282140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
19292140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
19302140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
19312140.19c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\advapi32.dll
19322140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
19332140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
19342140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
19352140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
19362140.19c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcr100.dll
19372140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
19382140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
19392140.19c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcp100.dll
19402140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
19412140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
19422140.19c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ws2_32.dll
19432140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
19442140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
19452140.19c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\advapi32.dll
19462140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
19472140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
19482140.19c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ole32.dll
19492140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
19502140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
19512140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
19522140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
19532140.19c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcr100.dll
19542140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
19552140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
19562140.19c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcp100.dll
19572140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtcorevbox4.dll'...
19582140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtcorevbox4.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\qtcorevbox4.dll' [rcNtRedir=0xc0150008]
19592140.19c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll
19602140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
19612140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume1\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
19622140.19c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\shell32.dll
19632140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
19642140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
19652140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
19662140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
19672140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
19682140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
19692140.19c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ole32.dll
19702140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winspool.drv'...
19712140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'winspool.drv' -> '\Device\HarddiskVolume1\Windows\System32\winspool.drv' [rcNtRedir=0xc0150008]
19722140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004a4 pwszName=\Device\HarddiskVolume1\Windows\System32\winspool.drv
19732140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b58e0
19742140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b58e0
19752140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=C89A2ED7B99A056D78CA6BAC9CCAB8B1FF119A14
19762140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\winspool.drv'
19772140.19c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
19782140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
19792140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
19802140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
19812140.19c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\winspool.drv) WinVerifyTrust
19822140.19c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\winspool.drv
19832140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
19842140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume1\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
19852140.19c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\winmm.dll
19862140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
19872140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume1\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
19882140.19c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\imm32.dll
19892140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
19902140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume1\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
19912140.19c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\oleaut32.dll
19922140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comdlg32.dll'...
19932140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'comdlg32.dll' -> '\Device\HarddiskVolume1\Windows\System32\comdlg32.dll' [rcNtRedir=0xc0150008]
19942140.19c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\comdlg32.dll
19952140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
19962140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
19972140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
19982140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
19992140.19c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcr100.dll
20002140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtcorevbox4.dll'...
20012140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtcorevbox4.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\qtcorevbox4.dll' [rcNtRedir=0xc0150008]
20022140.19c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll
20032140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtguivbox4.dll'...
20042140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtguivbox4.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\qtguivbox4.dll' [rcNtRedir=0xc0150008]
20052140.19c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll
20062140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
20072140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
20082140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
20092140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
20102140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
20112140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume1\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
20122140.19c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\opengl32.dll
20132140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
20142140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
20152140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
20162140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
20172140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
20182140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume1\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
20192140.19c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\shlwapi.dll
20202140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
20212140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
20222140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
20232140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
20242140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
20252140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
20262140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
20272140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
20282140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
20292140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
20302140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
20312140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
20322140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
20332140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
20342140.19c8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status -22900 (0xffffa68c)) on \Device\HarddiskVolume1\Windows\System32\user32.dll
20352140.19c8: Error (rc=0):
20362140.19c8: supR3HardenedScreenImage/Imports: cached rc=Unknown Status -22900 (0xffffa68c) fImage=1 fProtect=0x0 fAccess=0x0 cHits=16 \Device\HarddiskVolume1\Windows\System32\user32.dll
20372140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
20382140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
20392140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
20402140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
20412140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
20422140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
20432140.19c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ole32.dll
20442140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
20452140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume1\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
20462140.19c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\shell32.dll
20472140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comctl32.dll'...
20482140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'comctl32.dll' -> '\Device\HarddiskVolume1\Windows\System32\comctl32.dll' [rcNtRedir=0x0]
20492140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004b4 pwszName=\Device\HarddiskVolume1\Windows\System32\comctl32.dll
20502140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b58e0
20512140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b58e0
20522140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=761964761EE466757E306124E042F4C2ACBEA092
20532140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3059317~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume1\Windows\System32\comctl32.dll'
20542140.19c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
20552140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'advapi32.dll'.
20562140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
20572140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
20582140.19c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\comctl32.dll) WinVerifyTrust
20592140.19c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\comctl32.dll
20602140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
20612140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
20622140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
20632140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
20642140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
20652140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume1\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
20662140.19c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\shlwapi.dll
20672140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
20682140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
20692140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
20702140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
20712140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
20722140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
20732140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
20742140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
20752140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
20762140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
20772140.19c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\gdi32.dll
20782140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
20792140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
20802140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
20812140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
20822140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
20832140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
20842140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
20852140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
20862140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
20872140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
20882140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
20892140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume1\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
20902140.19c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\opengl32.dll
20912140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
20922140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
20932140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dwmapi.dll'...
20942140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'dwmapi.dll' -> '\Device\HarddiskVolume1\Windows\System32\dwmapi.dll' [rcNtRedir=0xc0150008]
20952140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000047c pwszName=\Device\HarddiskVolume1\Windows\System32\dwmapi.dll
20962140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b58e0
20972140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b58e0
20982140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F3F3D4867E9140896E0742D7EE8AE1D01FE85ECE
20992140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3078667~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume1\Windows\System32\dwmapi.dll'
21002140.19c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
21012140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
21022140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
21032140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
21042140.19c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\dwmapi.dll) WinVerifyTrust
21052140.19c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\dwmapi.dll
21062140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
21072140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume1\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
21082140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000490 pwszName=\Device\HarddiskVolume1\Windows\System32\setupapi.dll
21092140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b58e0
21102140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b58e0
21112140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=1499C4FEA6E143F9BEC35B4FFA098917D3A6EBF2
21122140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\setupapi.dll'
21132140.19c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
21142140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'cfgmgr32.dll'.
21152140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcrt.dll'.
21162140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'gdi32.dll'.
21172140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
21182140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'user32.dll'.
21192140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'oleaut32.dll'.
21202140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'devobj.dll'.
21212140.19c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\setupapi.dll) WinVerifyTrust
21222140.19c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\setupapi.dll
21232140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
21242140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
21252140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dciman32.dll'...
21262140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'dciman32.dll' -> '\Device\HarddiskVolume1\Windows\System32\dciman32.dll' [rcNtRedir=0xc0150008]
21272140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004c4 pwszName=\Device\HarddiskVolume1\Windows\System32\dciman32.dll
21282140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b58e0
21292140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b58e0
21302140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=779E327CA47BE9830D08A18EEDE8A70C3A978A3B
21312140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3087039~31bf3856ad364e35~amd64~~6.1.1.4.cat'; file='\Device\HarddiskVolume1\Windows\System32\dciman32.dll'
21322140.19c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
21332140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
21342140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'gdi32.dll'.
21352140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
21362140.19c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\dciman32.dll) WinVerifyTrust
21372140.19c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\dciman32.dll
21382140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
21392140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
21402140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
21412140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
21422140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
21432140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
21442140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
21452140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
21462140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
21472140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
21482140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'devobj.dll'...
21492140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'devobj.dll' -> '\Device\HarddiskVolume1\Windows\System32\devobj.dll' [rcNtRedir=0xc0150008]
21502140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000498 pwszName=\Device\HarddiskVolume1\Windows\System32\devobj.dll
21512140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b58e0
21522140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b58e0
21532140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B410A095222E69F0ECE7D66E4AC27A7125D2EB5A
21542140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume1\Windows\System32\devobj.dll'
21552140.19c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
21562140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
21572140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'cfgmgr32.dll'.
21582140.19c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\devobj.dll) WinVerifyTrust
21592140.19c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\devobj.dll
21602140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
21612140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume1\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
21622140.19c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\oleaut32.dll
21632140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
21642140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
21652140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
21662140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
21672140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
21682140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
21692140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
21702140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
21712140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
21722140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume1\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
21732140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004c8 pwszName=\Device\HarddiskVolume1\Windows\System32\cfgmgr32.dll
21742140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b58e0
21752140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b58e0
21762140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=8F731777EFC4BC982C1E1467FBF29A74CC14D93A
21772140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\cfgmgr32.dll'
21782140.19c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
21792140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
21802140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'rpcrt4.dll'.
21812140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
21822140.19c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\cfgmgr32.dll) WinVerifyTrust
21832140.19c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\cfgmgr32.dll
21842140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
21852140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
21862140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
21872140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
21882140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
21892140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
21902140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
21912140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
21922140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
21932140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
21942140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
21952140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
21962140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
21972140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume1\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
21982140.19c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\cfgmgr32.dll
21992140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
22002140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
22012140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VirtualBox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000085d220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
22022140.19c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.dll
22032140.19c8: supR3HardenedDllNotificationCallback: load 000007fee3cd0000 LB 0x00abf000 C:\Program Files\Oracle\VirtualBox\VirtualBox.dll [fFlags=0x0]
22042140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.dll
22052140.19c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\opengl32.dll
22062140.19c8: supR3HardenedDllNotificationCallback: load 000007fef1840000 LB 0x0011d000 C:\Windows\system32\OPENGL32.dll [fFlags=0x0]
22072140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\opengl32.dll
22082140.19c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\glu32.dll
22092140.19c8: supR3HardenedDllNotificationCallback: load 000007fef1810000 LB 0x0002d000 C:\Windows\system32\GLU32.dll [fFlags=0x0]
22102140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\glu32.dll
22112140.19c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ddraw.dll
22122140.19c8: supR3HardenedDllNotificationCallback: load 000007fef1710000 LB 0x000f1000 C:\Windows\system32\DDRAW.dll [fFlags=0x0]
22132140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ddraw.dll
22142140.19c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\dciman32.dll
22152140.19c8: supR3HardenedDllNotificationCallback: load 000007fef3620000 LB 0x00008000 C:\Windows\system32\DCIMAN32.dll [fFlags=0x0]
22162140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\dciman32.dll
22172140.19c8: supR3HardenedDllNotificationCallback: load 000007fefdbb0000 LB 0x001d7000 C:\Windows\system32\SETUPAPI.dll [fFlags=0x0]
22182140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\setupapi.dll
22192140.19c8: supR3HardenedDllNotificationCallback: load 000007fefcdb0000 LB 0x00036000 C:\Windows\system32\CFGMGR32.dll [fFlags=0x0]
22202140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\cfgmgr32.dll
22212140.19c8: supR3HardenedDllNotificationCallback: load 000007fefcec0000 LB 0x000d7000 C:\Windows\system32\OLEAUT32.dll [fFlags=0x0]
22222140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\oleaut32.dll
22232140.19c8: supR3HardenedDllNotificationCallback: load 000007fefd0d0000 LB 0x00203000 C:\Windows\system32\ole32.dll [fFlags=0x0]
22242140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ole32.dll
22252140.19c8: supR3HardenedDllNotificationCallback: load 000007fefcea0000 LB 0x0001a000 C:\Windows\system32\DEVOBJ.dll [fFlags=0x0]
22262140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\devobj.dll
22272140.19c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\dwmapi.dll
22282140.19c8: supR3HardenedDllNotificationCallback: load 000007fefa810000 LB 0x00018000 C:\Windows\system32\dwmapi.dll [fFlags=0x0]
22292140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\dwmapi.dll
22302140.19c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll
22312140.19c8: supR3HardenedDllNotificationCallback: load 00000000702e0000 LB 0x002de000 C:\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll [fFlags=0x0]
22322140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll
22332140.19c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll
22342140.19c8: supR3HardenedDllNotificationCallback: load 000000006efd0000 LB 0x0096c000 C:\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll [fFlags=0x0]
22352140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll
22362140.19c8: supR3HardenedDllNotificationCallback: load 000007fefd430000 LB 0x00097000 C:\Windows\system32\COMDLG32.dll [fFlags=0x0]
22372140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\comdlg32.dll
22382140.19c8: \Device\HarddiskVolume1\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll: Owner is administrators group.
22392140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'advapi32.dll'.
22402140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
22412140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
22422140.19c8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll)
22432140.19c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll
22442140.19c8: supR3HardenedDllNotificationCallback: load 000007fef91d0000 LB 0x000a0000 C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\COMCTL32.dll [fFlags=0x0]
22452140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll [avoiding WinVerifyTrust]
22462140.19c8: supR3HardenedDllNotificationCallback: load 000007fefe010000 LB 0x00d89000 C:\Windows\system32\SHELL32.dll [fFlags=0x0]
22472140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\shell32.dll
22482140.19c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\winmm.dll
22492140.19c8: supR3HardenedDllNotificationCallback: load 000007fefb960000 LB 0x0003b000 C:\Windows\system32\WINMM.dll [fFlags=0x0]
22502140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\winmm.dll
22512140.19c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\winspool.drv
22522140.19c8: supR3HardenedDllNotificationCallback: load 000007fef88a0000 LB 0x00071000 C:\Windows\system32\WINSPOOL.DRV [fFlags=0x0]
22532140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\winspool.drv
22542140.19c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll
22552140.19c8: supR3HardenedDllNotificationCallback: load 00000000735f0000 LB 0x000dc000 C:\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll [fFlags=0x0]
22562140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll
22572140.19c8: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume1\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll'.
22582140.19c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume1\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll' [rescheduled]
22592140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\imm32.dll
22602140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
22612140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
22622140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
22632140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
22642140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
22652140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
22662140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\imm32.dll (Input=imm32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000085d460:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
22672140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd400000 'C:\Windows\system32\imm32.dll'
22682140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee3cd0000 'C:\Program Files\Oracle\VirtualBox\VirtualBox.dll'
22692140.19c8: SUPR3HardenedMain: Calling TrustedMain (000007fee3cd10f0)...
22702140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\winmm.dll
22712140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\winmm.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000085d220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
22722140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefb960000 'C:\Windows\system32\winmm.dll'
22732140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000056c pwszName=\Device\HarddiskVolume1\Windows\System32\uxtheme.dll
22742140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b58e0
22752140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b58e0
22762140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=936D45CC7026757A151F62882B557DD75D5FCB21
22772140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume1\Windows\System32\uxtheme.dll'
22782140.19c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
22792140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
22802140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
22812140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'gdi32.dll'.
22822140.19c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\uxtheme.dll) WinVerifyTrust
22832140.19c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\uxtheme.dll
22842140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
22852140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
22862140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
22872140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
22882140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
22892140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
22902140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000008dbfd0:C:\Windows\system32;C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
22912140.19c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\uxtheme.dll
22922140.19c8: supR3HardenedDllNotificationCallback: load 000007fefae40000 LB 0x00056000 C:\Windows\system32\uxtheme.dll [fFlags=0x0]
22932140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\uxtheme.dll
22942140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefae40000 'C:\Windows\system32\uxtheme.dll'
22952140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\uxtheme.dll
22962140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000008dbfd0:C:\Windows\system32;C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
22972140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefae40000 'C:\Windows\system32\uxtheme.dll'
22982140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\uxtheme.dll
22992140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000008dcad0:C:\Windows\system32;C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
23002140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefae40000 'C:\Windows\system32\uxtheme.dll'
23012140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\uxtheme.dll
23022140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000008dcad0:C:\Windows\system32;C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
23032140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefae40000 'C:\Windows\system32\uxtheme.dll'
23042140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\dwmapi.dll
23052140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\dwmapi.dll (Input=dwmapi.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000085d220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
23062140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa810000 'C:\Windows\system32\dwmapi.dll'
23072140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\cryptbase.dll
23082140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTBASE.dll (Input=CRYPTBASE.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000085d220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
23092140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc970000 'C:\Windows\system32\CRYPTBASE.dll'
23102140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\shell32.dll
23112140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000085d220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
23122140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe010000 'C:\Windows\system32\shell32.dll'
23132140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\kernel32.dll
23142140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000085d220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
23152140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000076b40000 'C:\Windows\system32\kernel32.dll'
23162140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\uxtheme.dll
23172140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000085d220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
23182140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefae40000 'C:\Windows\system32\uxtheme.dll'
23192140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\uxtheme.dll
23202140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000085d220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
23212140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefae40000 'C:\Windows\system32\uxtheme.dll'
23222140.19c8: supR3HardenedMonitor_LdrLoadDll: error opening 'C:\Windows\system32\wintab32.dll': 0 (NtPath=\??\C:\Windows\system32\wintab32.dll; Input=C:\Windows\system32\wintab32.dll; rcNtGetDll=0x0
23232140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wintab32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000085d220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
23242140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000135 'C:\Windows\system32\wintab32.dll'
23252140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\uxtheme.dll
23262140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000085d220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
23272140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefae40000 'C:\Windows\system32\uxtheme.dll'
23282140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdad0000 'C:\Windows\system32\advapi32.dll'
23292140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\userenv.dll
23302140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\userenv.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000085d220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
23312140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcb40000 'C:\Windows\system32\userenv.dll'
23322140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\kernel32.dll
23332140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000085d220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
23342140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000076b40000 'C:\Windows\system32\kernel32.dll'
23352140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000005cc pwszName=\Device\HarddiskVolume1\Windows\System32\clbcatq.dll
23362140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b58e0
23372140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b58e0
23382140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B01469787CE9D8C6FEE98FB207652B88B8494526
23392140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume1\Windows\System32\clbcatq.dll'
23402140.19c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
23412140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
23422140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'ole32.dll'.
23432140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
23442140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
23452140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
23462140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'rpcrt4.dll'.
23472140.19c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\clbcatq.dll) WinVerifyTrust
23482140.19c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\clbcatq.dll
23492140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
23502140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
23512140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
23522140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume1\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
23532140.19c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\oleaut32.dll
23542140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
23552140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
23562140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
23572140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
23582140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
23592140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
23602140.19c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ole32.dll
23612140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
23622140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
23632140.19c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll
23642140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CLBCatQ.DLL (Input=CLBCatQ.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000085d220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
23652140.19c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\clbcatq.dll
23662140.19c8: supR3HardenedDllNotificationCallback: load 000007fefeda0000 LB 0x00099000 C:\Windows\system32\CLBCatQ.DLL [fFlags=0x0]
23672140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\clbcatq.dll
23682140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefeda0000 'C:\Windows\system32\CLBCatQ.DLL'
23692140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdad0000 'C:\Windows\system32\ADVAPI32.dll'
23702140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\cryptsp.dll
23712140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTSP.dll (Input=CRYPTSP.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000085d6a0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
23722140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc230000 'C:\Windows\system32\CRYPTSP.dll'
23732140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000005ec pwszName=\Device\HarddiskVolume1\Windows\System32\RpcRtRemote.dll
23742140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b58e0
23752140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b58e0
23762140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=DFC4A7C7E103D324218E6EF5D219B953746D6EC1
23772140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\RpcRtRemote.dll'
23782140.19c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
23792140.19c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'rpcrt4.dll'.
23802140.19c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\RpcRtRemote.dll) WinVerifyTrust
23812140.19c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\RpcRtRemote.dll
23822140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
23832140.19c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
23842140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\RpcRtRemote.dll (Input=RpcRtRemote.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000085d6a0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
23852140.19c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\RpcRtRemote.dll
23862140.19c8: supR3HardenedDllNotificationCallback: load 000007fefca20000 LB 0x00014000 C:\Windows\system32\RpcRtRemote.dll [fFlags=0x0]
23872140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\RpcRtRemote.dll
23882140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefca20000 'C:\Windows\system32\RpcRtRemote.dll'
23892140.18a4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
23902140.18a4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
23912140.18a4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
23922140.18a4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
23932140.18a4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ws2_32.dll'.
23942140.18a4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ole32.dll'.
23952140.18a4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'oleaut32.dll'.
23962140.18a4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxC.dll) WinVerifyTrust
23972140.18a4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxC.dll
23982140.18a4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
23992140.18a4: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume1\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
24002140.18a4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\oleaut32.dll
24012140.18a4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
24022140.18a4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
24032140.18a4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ole32.dll
24042140.18a4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
24052140.18a4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
24062140.18a4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ws2_32.dll
24072140.18a4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
24082140.18a4: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
24092140.18a4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\advapi32.dll
24102140.18a4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
24112140.18a4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
24122140.18a4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
24132140.18a4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
24142140.18a4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcp100.dll
24152140.18a4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
24162140.18a4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
24172140.18a4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcr100.dll
24182140.18a4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxC.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000890ed0:C:\Program Files\Oracle\VirtualBox;C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
24192140.18a4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxC.dll
24202140.18a4: supR3HardenedDllNotificationCallback: load 000007fee0600000 LB 0x005d8000 C:\Program Files\Oracle\VirtualBox\VBoxC.dll [fFlags=0x0]
24212140.18a4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxC.dll
24222140.18a4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee0600000 'C:\Program Files\Oracle\VirtualBox\VBoxC.dll'
24232140.18a4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000650 pwszName=\Device\HarddiskVolume1\Windows\System32\msiltcfg.dll
24242140.18a4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b58e0
24252140.18a4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b58e0
24262140.18a4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=66DB5F28C5BA0EDD9CAD2DDAB24F1A6AD9F2B6A3
24272140.18a4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntph.cat'; file='\Device\HarddiskVolume1\Windows\System32\msiltcfg.dll'
24282140.18a4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
24292140.18a4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
24302140.18a4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
24312140.18a4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'version.dll'.
24322140.18a4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\msiltcfg.dll) WinVerifyTrust
24332140.18a4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\msiltcfg.dll
24342140.18a4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'version.dll'...
24352140.18a4: supR3HardenedWinVerifyCacheProcessImportTodos: 'version.dll' -> '\Device\HarddiskVolume1\Windows\System32\version.dll' [rcNtRedir=0xc0150008]
24362140.18a4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000063c pwszName=\Device\HarddiskVolume1\Windows\System32\version.dll
24372140.18a4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b58e0
24382140.18a4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b58e0
24392140.18a4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=A3AB94A028D0330A3DBCAE54C04C648532198DB9
24402140.18a4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume1\Windows\System32\version.dll'
24412140.18a4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
24422140.18a4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
24432140.18a4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\version.dll) WinVerifyTrust
24442140.18a4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\version.dll
24452140.18a4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
24462140.18a4: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
24472140.18a4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
24482140.18a4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
24492140.18a4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
24502140.18a4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
24512140.18a4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\msiltcfg.dll (Input=msiltcfg.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000085dd60:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
24522140.18a4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\msiltcfg.dll
24532140.18a4: supR3HardenedDllNotificationCallback: load 000007fef3b40000 LB 0x00009000 C:\Windows\system32\msiltcfg.dll [fFlags=0x0]
24542140.18a4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\msiltcfg.dll
24552140.18a4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\version.dll
24562140.18a4: supR3HardenedDllNotificationCallback: load 000007fefc800000 LB 0x0000c000 C:\Windows\system32\VERSION.dll [fFlags=0x0]
24572140.18a4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\version.dll
24582140.18a4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef3b40000 'C:\Windows\system32\msiltcfg.dll'
24592140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff000000 'C:\Windows\system32\gdi32.dll'
24602140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\shell32.dll
24612140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000085ddf0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
24622140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe010000 'C:\Windows\system32\shell32.dll'
24632140.19c8: supR3HardenedMonitor_LdrLoadDll: error opening 'C:\Windows\system32\wintab32.dll': 0 (NtPath=\??\C:\Windows\system32\wintab32.dll; Input=C:\Windows\system32\wintab32.dll; rcNtGetDll=0x0
24642140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wintab32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000085ddf0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
24652140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000135 'C:\Windows\system32\wintab32.dll'
24662140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\shell32.dll
24672140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000085ddf0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
24682140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe010000 'C:\Windows\system32\shell32.dll'
24692140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\shell32.dll
24702140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000085ddf0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
24712140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe010000 'C:\Windows\system32\shell32.dll'
24722140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\shell32.dll
24732140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000085ddf0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
24742140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe010000 'C:\Windows\system32\shell32.dll'
24752140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe010000 'C:\Windows\system32\shell32.dll'
24762140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe010000 'C:\Windows\system32\shell32.dll'
24772140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status -22900 (0xffffa68c)) on \Device\HarddiskVolume1\Windows\System32\user32.dll
24782140.19c8: Error (rc=0):
24792140.19c8: supR3HardenedScreenImage/LdrLoadDll: cached rc=Unknown Status -22900 (0xffffa68c) fImage=1 fProtect=0x0 fAccess=0x0 cHits=32 \Device\HarddiskVolume1\Windows\System32\user32.dll
24802140.19c8: Error (rc=0):
24812140.19c8: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\Windows\system32\user32.dll' (C:\Windows\system32\user32.dll): rcNt=0xc0000190
24822140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Windows\system32\user32.dll'
24832140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdad0000 'C:\Windows\system32\ADVAPI32.dll'
24842140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ole32.dll
24852140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ole32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000085ddf0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
24862140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd0d0000 'C:\Windows\system32\ole32.dll'
24872140.19c8: supR3HardenedMonitor_LdrLoadDll: 'C:\Windows\system32\comctl32.dll' -> 'C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll' [redir]
24882140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll [redoing WinVerifyTrust]
24892140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004e0 pwszName=\Device\HarddiskVolume1\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll
24902140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b58e0
24912140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b58e0
24922140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=761964761EE466757E306124E042F4C2ACBEA092
24932140.19c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3059317~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume1\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll'
24942140.19c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
24952140.19c8: supR3HardenedScreenImage/LdrLoadDll: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll'
24962140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll (Input=C:\Windows\system32\comctl32.dll, rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=000000000085e030:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
24972140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef91d0000 'C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll'
24982140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\msctf.dll
24992140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\MSCTF.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000008dcce0:C:\Windows\system32;C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
25002140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefee60000 'C:\Windows\system32\MSCTF.dll'
25012140.19c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\oleaut32.dll
25022140.19c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\OLEAUT32.DLL (Input=OLEAUT32.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000085e030:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
25032140.19c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcec0000 'C:\Windows\system32\OLEAUT32.DLL'
25042140.19c8: Terminating the normal way: rcExit=1
25051e2c.1c48: supR3HardNtChildWaitFor[2]: Quitting: ExitCode=0x1 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 11327 ms, the end);
250614f4.22f4: supR3HardNtChildWaitFor[1]: Quitting: ExitCode=0x1 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 12710 ms, the end);

© 2024 Oracle Support Privacy / Do Not Sell My Info Terms of Use Trademark Policy Automated Access Etiquette