VirtualBox

Ticket #15711: VBoxHardening.log

File VBoxHardening.log, 210.8 KB (added by Solrac42, 9 years ago)
Line 
1660.72c: Log file opened: 5.1.2r108956 g_hStartupLog=0000000000000014 g_uNtVerCombined=0x611db110
2660.72c: \SystemRoot\System32\ntdll.dll:
3660.72c: CreationTime: 2015-12-02T14:02:30.662842700Z
4660.72c: LastWriteTime: 2015-10-20T01:09:05.164170200Z
5660.72c: ChangeTime: 2015-12-02T15:48:45.539639700Z
6660.72c: FileAttributes: 0x20
7660.72c: Size: 0x1a67c0
8660.72c: NT Headers: 0xe0
9660.72c: Timestamp: 0x56259295
10660.72c: Machine: 0x8664 - amd64
11660.72c: Timestamp: 0x56259295
12660.72c: Image Version: 6.1
13660.72c: SizeOfImage: 0x1a9000 (1740800)
14660.72c: Resource Dir: 0x14d000 LB 0x5a028
15660.72c: ProductName: Microsoft® Windows® Operating System
16660.72c: ProductVersion: 6.1.7601.19045
17660.72c: FileVersion: 6.1.7601.19045 (win7sp1_gdr.151019-1254)
18660.72c: FileDescription: NT Layer DLL
19660.72c: \SystemRoot\System32\kernel32.dll:
20660.72c: CreationTime: 2015-12-02T14:02:30.132441700Z
21660.72c: LastWriteTime: 2015-10-20T01:05:40.819000000Z
22660.72c: ChangeTime: 2015-12-02T15:48:45.617639900Z
23660.72c: FileAttributes: 0x20
24660.72c: Size: 0x11c600
25660.72c: NT Headers: 0xe8
26660.72c: Timestamp: 0x56259270
27660.72c: Machine: 0x8664 - amd64
28660.72c: Timestamp: 0x56259270
29660.72c: Image Version: 6.1
30660.72c: SizeOfImage: 0x120000 (1179648)
31660.72c: Resource Dir: 0x117000 LB 0x528
32660.72c: ProductName: Microsoft® Windows® Operating System
33660.72c: ProductVersion: 6.1.7601.19045
34660.72c: FileVersion: 6.1.7601.19045 (win7sp1_gdr.151019-1254)
35660.72c: FileDescription: Windows NT BASE API Client DLL
36660.72c: \SystemRoot\System32\KernelBase.dll:
37660.72c: CreationTime: 2015-12-02T14:02:30.070041600Z
38660.72c: LastWriteTime: 2015-10-20T01:05:40.819000000Z
39660.72c: ChangeTime: 2015-12-02T15:48:45.617639900Z
40660.72c: FileAttributes: 0x20
41660.72c: Size: 0x67c00
42660.72c: NT Headers: 0xe8
43660.72c: Timestamp: 0x56259271
44660.72c: Machine: 0x8664 - amd64
45660.72c: Timestamp: 0x56259271
46660.72c: Image Version: 6.1
47660.72c: SizeOfImage: 0x6c000 (442368)
48660.72c: Resource Dir: 0x6a000 LB 0x530
49660.72c: ProductName: Microsoft® Windows® Operating System
50660.72c: ProductVersion: 6.1.7601.19045
51660.72c: FileVersion: 6.1.7601.19045 (win7sp1_gdr.151019-1254)
52660.72c: FileDescription: Windows NT BASE API Client DLL
53660.72c: \SystemRoot\System32\apisetschema.dll:
54660.72c: CreationTime: 2015-12-02T14:02:29.524040700Z
55660.72c: LastWriteTime: 2015-10-20T00:53:47.280000000Z
56660.72c: ChangeTime: 2015-12-02T15:48:45.539639700Z
57660.72c: FileAttributes: 0x20
58660.72c: Size: 0x1a00
59660.72c: NT Headers: 0xc0
60660.72c: Timestamp: 0x562590e2
61660.72c: Machine: 0x8664 - amd64
62660.72c: Timestamp: 0x562590e2
63660.72c: Image Version: 6.1
64660.72c: SizeOfImage: 0x50000 (327680)
65660.72c: Resource Dir: 0x30000 LB 0x3f8
66660.72c: ProductName: Microsoft® Windows® Operating System
67660.72c: ProductVersion: 6.1.7601.19045
68660.72c: FileVersion: 6.1.7601.19045 (win7sp1_gdr.151019-1254)
69660.72c: FileDescription: ApiSet Schema DLL
70660.72c: NtOpenDirectoryObject failed on \Driver: 0xc0000022
71660.72c: supR3HardenedWinFindAdversaries: 0x0
72660.72c: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox'
73660.72c: Calling main()
74660.72c: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
75660.72c: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox'
76660.72c: SUPR3HardenedMain: Respawn #1
77660.72c: System32: \Device\HarddiskVolume3\Windows\System32
78660.72c: WinSxS: \Device\HarddiskVolume3\Windows\winsxs
79660.72c: KnownDllPath: C:\Windows\system32
80660.72c: '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
81660.72c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe)
82660.72c: supR3HardNtEnableThreadCreation:
83660.72c: supR3HardNtDisableThreadCreation: pvLdrInitThunk=000000007748b630 pvNtTerminateThread=00000000774adee0
84660.72c: supR3HardenedWinDoReSpawn(1): New child 6d4.4ac [kernel32].
85660.72c: supR3HardNtChildGatherData: PebBaseAddress=000007fffffd9000 cbPeb=0x380
86660.72c: supR3HardNtPuChFindNtdll: uNtDllParentAddr=0000000077460000 uNtDllChildAddr=0000000077460000
87660.72c: supR3HardenedWinSetupChildInit: uLdrInitThunk=000000007748b630
88660.72c: supR3HardenedWinSetupChildInit: Start child.
89660.72c: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
90660.72c: supR3HardNtChildPurify: Startup delay kludge #1/0: 258 ms, 18 sleeps
91660.72c: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
92660.72c: *0000000000000000-fffffffffffeffff 0x0001/0x0000 0x0000000
93660.72c: *0000000000010000-fffffffffffeffff 0x0004/0x0004 0x0020000
94660.72c: *0000000000030000-000000000002bfff 0x0002/0x0002 0x0040000
95660.72c: 0000000000034000-0000000000027fff 0x0001/0x0000 0x0000000
96660.72c: *0000000000040000-000000000003efff 0x0004/0x0004 0x0020000
97660.72c: 0000000000041000-0000000000021fff 0x0001/0x0000 0x0000000
98660.72c: *0000000000060000-fffffffffff63fff 0x0000/0x0004 0x0020000
99660.72c: 000000000015c000-0000000000159fff 0x0104/0x0004 0x0020000
100660.72c: 000000000015e000-000000000015bfff 0x0004/0x0004 0x0020000
101660.72c: 0000000000160000-ffffffff88e5ffff 0x0001/0x0000 0x0000000
102660.72c: *0000000077460000-0000000077460fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
103660.72c: 0000000077461000-000000007755efff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
104660.72c: 000000007755f000-000000007758dfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
105660.72c: 000000007758e000-0000000077595fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
106660.72c: 0000000077596000-0000000077596fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
107660.72c: 0000000077597000-0000000077599fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
108660.72c: 000000007759a000-0000000077608fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
109660.72c: 0000000077609000-000000006fc31fff 0x0001/0x0000 0x0000000
110660.72c: *000000007efe0000-000000007dfdffff 0x0000/0x0002 0x0020000
111660.72c: *000000007ffe0000-000000007ffdefff 0x0002/0x0002 0x0020000
112660.72c: 000000007ffe1000-000000007ffd1fff 0x0000/0x0002 0x0020000
113660.72c: 000000007fff0000-ffffffffc0ceffff 0x0001/0x0000 0x0000000
114660.72c: *000000013f2f0000-000000013f2f0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
115660.72c: 000000013f2f1000-000000013f35ffff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
116660.72c: 000000013f360000-000000013f360fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
117660.72c: 000000013f361000-000000013f3a4fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
118660.72c: 000000013f3a5000-000000013f3a5fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
119660.72c: 000000013f3a6000-000000013f3a6fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
120660.72c: 000000013f3a7000-000000013f3abfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
121660.72c: 000000013f3ac000-000000013f3acfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
122660.72c: 000000013f3ad000-000000013f3adfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
123660.72c: 000000013f3ae000-000000013f3b1fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
124660.72c: 000000013f3b2000-000000013f3f9fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
125660.72c: 000000013f3fa000-fffff8037f073fff 0x0001/0x0000 0x0000000
126660.72c: *000007feff780000-000007feff780fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\apisetschema.dll
127660.72c: 000007feff781000-000007fdfef51fff 0x0001/0x0000 0x0000000
128660.72c: *000007fffffb0000-000007fffff8cfff 0x0002/0x0002 0x0040000
129660.72c: 000007fffffd3000-000007fffffccfff 0x0001/0x0000 0x0000000
130660.72c: *000007fffffd9000-000007fffffd7fff 0x0004/0x0004 0x0020000
131660.72c: 000007fffffda000-000007fffffd5fff 0x0001/0x0000 0x0000000
132660.72c: *000007fffffde000-000007fffffdbfff 0x0004/0x0004 0x0020000
133660.72c: *000007fffffe0000-000007fffffcffff 0x0001/0x0002 0x0020000
134660.72c: apisetschema.dll: timestamp 0x562590e2 (rc=VINF_SUCCESS)
135660.72c: VirtualBox.exe: timestamp 0x5790f053 (rc=VINF_SUCCESS)
136660.72c: '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
137660.72c: '\Device\HarddiskVolume3\Windows\System32\apisetschema.dll' has no imports
138660.72c: '\Device\HarddiskVolume3\Windows\System32\ntdll.dll' has no imports
139660.72c: supR3HardNtChildPurify: Done after 275 ms and 0 fixes (loop #0).
1406d4.4ac: Log file opened: 5.1.2r108956 g_hStartupLog=0000000000000004 g_uNtVerCombined=0x611db100
1416d4.4ac: supR3HardenedVmProcessInit: uNtDllAddr=0000000077460000 g_uNtVerCombined=0x611db100
1426d4.4ac: ntdll.dll: timestamp 0x56259295 (rc=VINF_SUCCESS)
1436d4.4ac: New simple heap: #1 0000000000260000 LB 0x400000 (for 1740800 allocation)
1446d4.4ac: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox'
145660.72c: supR3HardNtEnableThreadCreation:
1466d4.4ac: System32: \Device\HarddiskVolume3\Windows\System32
1476d4.4ac: WinSxS: \Device\HarddiskVolume3\Windows\winsxs
1486d4.4ac: KnownDllPath: C:\Windows\system32
1496d4.4ac: supR3HardenedVmProcessInit: Opening vboxdrv stub...
1506d4.4ac: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
1516d4.4ac: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
1526d4.4ac: Registered Dll notification callback with NTDLL.
1536d4.4ac: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\kernel32.dll)
1546d4.4ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\kernel32.dll
1556d4.4ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
1566d4.4ac: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
1576d4.4ac: supR3HardenedDllNotificationCallback: load 0000000077340000 LB 0x00120000 C:\Windows\system32\kernel32.dll [fFlags=0x0]
1586d4.4ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
1596d4.4ac: supR3HardenedDllNotificationCallback: load 000007fefd560000 LB 0x0006c000 C:\Windows\system32\KERNELBASE.dll [fFlags=0x0]
1606d4.4ac: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\KernelBase.dll)
1616d4.4ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\KernelBase.dll
1626d4.4ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077340000 'C:\Windows\system32\kernel32.dll'
1636d4.4ac: supR3HardNtDisableThreadCreation: pvLdrInitThunk=000000007748b630 pvNtTerminateThread=00000000774adee0
164660.72c: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 18 ms.
1656d4.4ac: \SystemRoot\System32\ntdll.dll:
1666d4.4ac: CreationTime: 2015-12-02T14:02:30.662842700Z
1676d4.4ac: LastWriteTime: 2015-10-20T01:09:05.164170200Z
1686d4.4ac: ChangeTime: 2015-12-02T15:48:45.539639700Z
1696d4.4ac: FileAttributes: 0x20
1706d4.4ac: Size: 0x1a67c0
1716d4.4ac: NT Headers: 0xe0
1726d4.4ac: Timestamp: 0x56259295
1736d4.4ac: Machine: 0x8664 - amd64
1746d4.4ac: Timestamp: 0x56259295
1756d4.4ac: Image Version: 6.1
1766d4.4ac: SizeOfImage: 0x1a9000 (1740800)
1776d4.4ac: Resource Dir: 0x14d000 LB 0x5a028
1786d4.4ac: ProductName: Microsoft® Windows® Operating System
1796d4.4ac: ProductVersion: 6.1.7601.19045
1806d4.4ac: FileVersion: 6.1.7601.19045 (win7sp1_gdr.151019-1254)
1816d4.4ac: FileDescription: NT Layer DLL
1826d4.4ac: \SystemRoot\System32\kernel32.dll:
1836d4.4ac: CreationTime: 2015-12-02T14:02:30.132441700Z
1846d4.4ac: LastWriteTime: 2015-10-20T01:05:40.819000000Z
1856d4.4ac: ChangeTime: 2015-12-02T15:48:45.617639900Z
1866d4.4ac: FileAttributes: 0x20
1876d4.4ac: Size: 0x11c600
1886d4.4ac: NT Headers: 0xe8
1896d4.4ac: Timestamp: 0x56259270
1906d4.4ac: Machine: 0x8664 - amd64
1916d4.4ac: Timestamp: 0x56259270
1926d4.4ac: Image Version: 6.1
1936d4.4ac: SizeOfImage: 0x120000 (1179648)
1946d4.4ac: Resource Dir: 0x117000 LB 0x528
1956d4.4ac: ProductName: Microsoft® Windows® Operating System
1966d4.4ac: ProductVersion: 6.1.7601.19045
1976d4.4ac: FileVersion: 6.1.7601.19045 (win7sp1_gdr.151019-1254)
1986d4.4ac: FileDescription: Windows NT BASE API Client DLL
1996d4.4ac: \SystemRoot\System32\KernelBase.dll:
2006d4.4ac: CreationTime: 2015-12-02T14:02:30.070041600Z
2016d4.4ac: LastWriteTime: 2015-10-20T01:05:40.819000000Z
2026d4.4ac: ChangeTime: 2015-12-02T15:48:45.617639900Z
2036d4.4ac: FileAttributes: 0x20
2046d4.4ac: Size: 0x67c00
2056d4.4ac: NT Headers: 0xe8
2066d4.4ac: Timestamp: 0x56259271
2076d4.4ac: Machine: 0x8664 - amd64
2086d4.4ac: Timestamp: 0x56259271
2096d4.4ac: Image Version: 6.1
2106d4.4ac: SizeOfImage: 0x6c000 (442368)
2116d4.4ac: Resource Dir: 0x6a000 LB 0x530
2126d4.4ac: ProductName: Microsoft® Windows® Operating System
2136d4.4ac: ProductVersion: 6.1.7601.19045
2146d4.4ac: FileVersion: 6.1.7601.19045 (win7sp1_gdr.151019-1254)
2156d4.4ac: FileDescription: Windows NT BASE API Client DLL
2166d4.4ac: \SystemRoot\System32\apisetschema.dll:
2176d4.4ac: CreationTime: 2015-12-02T14:02:29.524040700Z
2186d4.4ac: LastWriteTime: 2015-10-20T00:53:47.280000000Z
2196d4.4ac: ChangeTime: 2015-12-02T15:48:45.539639700Z
2206d4.4ac: FileAttributes: 0x20
2216d4.4ac: Size: 0x1a00
2226d4.4ac: NT Headers: 0xc0
2236d4.4ac: Timestamp: 0x562590e2
2246d4.4ac: Machine: 0x8664 - amd64
2256d4.4ac: Timestamp: 0x562590e2
2266d4.4ac: Image Version: 6.1
2276d4.4ac: SizeOfImage: 0x50000 (327680)
2286d4.4ac: Resource Dir: 0x30000 LB 0x3f8
2296d4.4ac: ProductName: Microsoft® Windows® Operating System
2306d4.4ac: ProductVersion: 6.1.7601.19045
2316d4.4ac: FileVersion: 6.1.7601.19045 (win7sp1_gdr.151019-1254)
2326d4.4ac: FileDescription: ApiSet Schema DLL
2336d4.4ac: NtOpenDirectoryObject failed on \Driver: 0xc0000022
2346d4.4ac: supR3HardenedWinFindAdversaries: 0x0
2356d4.4ac: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox'
2366d4.4ac: Calling main()
2376d4.4ac: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
2386d4.4ac: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox'
2396d4.4ac: '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
2406d4.4ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe)
2416d4.4ac: SUPR3HardenedMain: Respawn #2
2426d4.4ac: supR3HardNtEnableThreadCreation:
2436d4.4ac: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\apphelp.dll)
2446d4.4ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\apphelp.dll
2456d4.4ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\apphelp.dll (rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
2466d4.4ac: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\apphelp.dll [lacks WinVerifyTrust]
2476d4.4ac: supR3HardenedDllNotificationCallback: load 000007fefd050000 LB 0x00057000 C:\Windows\system32\apphelp.dll [fFlags=0x0]
2486d4.4ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\apphelp.dll [lacks WinVerifyTrust]
2496d4.4ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd050000 'C:\Windows\system32\apphelp.dll'
2506d4.4ac: supR3HardNtDisableThreadCreation: pvLdrInitThunk=000000007748b630 pvNtTerminateThread=00000000774adee0
2516d4.4ac: supR3HardenedWinDoReSpawn(2): New child 374.f08 [kernel32].
2526d4.4ac: supR3HardNtChildGatherData: PebBaseAddress=000007fffffdf000 cbPeb=0x380
2536d4.4ac: supR3HardNtPuChFindNtdll: uNtDllParentAddr=0000000077460000 uNtDllChildAddr=0000000077460000
2546d4.4ac: supR3HardenedWinSetupChildInit: uLdrInitThunk=000000007748b630
2556d4.4ac: supR3HardenedWinSetupChildInit: Start child.
2566d4.4ac: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
2576d4.4ac: supR3HardNtChildPurify: Startup delay kludge #1/0: 264 ms, 33 sleeps
2586d4.4ac: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
2596d4.4ac: *0000000000000000-fffffffffffeffff 0x0001/0x0000 0x0000000
2606d4.4ac: *0000000000010000-fffffffffffeffff 0x0004/0x0004 0x0020000
2616d4.4ac: *0000000000030000-000000000002bfff 0x0002/0x0002 0x0040000
2626d4.4ac: 0000000000034000-0000000000027fff 0x0001/0x0000 0x0000000
2636d4.4ac: *0000000000040000-000000000003efff 0x0004/0x0004 0x0020000
2646d4.4ac: 0000000000041000-fffffffffff31fff 0x0001/0x0000 0x0000000
2656d4.4ac: *0000000000150000-0000000000053fff 0x0000/0x0004 0x0020000
2666d4.4ac: 000000000024c000-0000000000249fff 0x0104/0x0004 0x0020000
2676d4.4ac: 000000000024e000-000000000024bfff 0x0004/0x0004 0x0020000
2686d4.4ac: 0000000000250000-ffffffff8903ffff 0x0001/0x0000 0x0000000
2696d4.4ac: *0000000077460000-0000000077460fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
2706d4.4ac: 0000000077461000-000000007755efff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
2716d4.4ac: 000000007755f000-000000007758dfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
2726d4.4ac: 000000007758e000-0000000077595fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
2736d4.4ac: 0000000077596000-0000000077596fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
2746d4.4ac: 0000000077597000-0000000077599fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
2756d4.4ac: 000000007759a000-0000000077608fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
2766d4.4ac: 0000000077609000-000000006fc31fff 0x0001/0x0000 0x0000000
2776d4.4ac: *000000007efe0000-000000007dfdffff 0x0000/0x0002 0x0020000
2786d4.4ac: *000000007ffe0000-000000007ffdefff 0x0002/0x0002 0x0020000
2796d4.4ac: 000000007ffe1000-000000007ffd1fff 0x0000/0x0002 0x0020000
2806d4.4ac: 000000007fff0000-ffffffffc0ceffff 0x0001/0x0000 0x0000000
2816d4.4ac: *000000013f2f0000-000000013f2f0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
2826d4.4ac: 000000013f2f1000-000000013f35ffff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
2836d4.4ac: 000000013f360000-000000013f360fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
2846d4.4ac: 000000013f361000-000000013f3a4fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
2856d4.4ac: 000000013f3a5000-000000013f3a5fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
2866d4.4ac: 000000013f3a6000-000000013f3a6fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
2876d4.4ac: 000000013f3a7000-000000013f3abfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
2886d4.4ac: 000000013f3ac000-000000013f3acfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
2896d4.4ac: 000000013f3ad000-000000013f3adfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
2906d4.4ac: 000000013f3ae000-000000013f3b1fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
2916d4.4ac: 000000013f3b2000-000000013f3f9fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
2926d4.4ac: 000000013f3fa000-fffff8037f073fff 0x0001/0x0000 0x0000000
2936d4.4ac: *000007feff780000-000007feff780fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\apisetschema.dll
2946d4.4ac: 000007feff781000-000007fdfef51fff 0x0001/0x0000 0x0000000
2956d4.4ac: *000007fffffb0000-000007fffff8cfff 0x0002/0x0002 0x0040000
2966d4.4ac: 000007fffffd3000-000007fffffc8fff 0x0001/0x0000 0x0000000
2976d4.4ac: *000007fffffdd000-000007fffffdafff 0x0004/0x0004 0x0020000
2986d4.4ac: *000007fffffdf000-000007fffffddfff 0x0004/0x0004 0x0020000
2996d4.4ac: *000007fffffe0000-000007fffffcffff 0x0001/0x0002 0x0020000
3006d4.4ac: apisetschema.dll: timestamp 0x562590e2 (rc=VINF_SUCCESS)
3016d4.4ac: VirtualBox.exe: timestamp 0x5790f053 (rc=VINF_SUCCESS)
3026d4.4ac: '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
3036d4.4ac: '\Device\HarddiskVolume3\Windows\System32\apisetschema.dll' has no imports
3046d4.4ac: '\Device\HarddiskVolume3\Windows\System32\ntdll.dll' has no imports
3056d4.4ac: supR3HardNtChildPurify: Done after 281 ms and 0 fixes (loop #0).
306374.f08: Log file opened: 5.1.2r108956 g_hStartupLog=0000000000000004 g_uNtVerCombined=0x611db100
307374.f08: supR3HardenedVmProcessInit: uNtDllAddr=0000000077460000 g_uNtVerCombined=0x611db100
308374.f08: ntdll.dll: timestamp 0x56259295 (rc=VINF_SUCCESS)
309374.f08: New simple heap: #1 0000000000250000 LB 0x400000 (for 1740800 allocation)
3106d4.4ac: supR3HardenedEarlyCompact: Removed heap 1 (0x00000000260000 LB 0x400000)
3116d4.4ac: supR3HardNtEnableThreadCreation:
312374.f08: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox'
313374.f08: System32: \Device\HarddiskVolume3\Windows\System32
314374.f08: WinSxS: \Device\HarddiskVolume3\Windows\winsxs
315374.f08: KnownDllPath: C:\Windows\system32
316374.f08: supR3HardenedVmProcessInit: Opening vboxdrv...
317374.f08: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
318374.f08: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
319374.f08: Registered Dll notification callback with NTDLL.
320374.f08: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\kernel32.dll)
321374.f08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\kernel32.dll
322374.f08: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
323374.f08: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
324374.f08: supR3HardenedDllNotificationCallback: load 0000000077340000 LB 0x00120000 C:\Windows\system32\kernel32.dll [fFlags=0x0]
325374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
326374.f08: supR3HardenedDllNotificationCallback: load 000007fefd560000 LB 0x0006c000 C:\Windows\system32\KERNELBASE.dll [fFlags=0x0]
327374.f08: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\KernelBase.dll)
328374.f08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\KernelBase.dll
329374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077340000 'C:\Windows\system32\kernel32.dll'
330374.f08: supR3HardNtDisableThreadCreation: pvLdrInitThunk=000000007748b630 pvNtTerminateThread=00000000774adee0
3316d4.4ac: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 21 ms.
332374.f08: \SystemRoot\System32\ntdll.dll:
333374.f08: CreationTime: 2015-12-02T14:02:30.662842700Z
334374.f08: LastWriteTime: 2015-10-20T01:09:05.164170200Z
335374.f08: ChangeTime: 2015-12-02T15:48:45.539639700Z
336374.f08: FileAttributes: 0x20
337374.f08: Size: 0x1a67c0
338374.f08: NT Headers: 0xe0
339374.f08: Timestamp: 0x56259295
340374.f08: Machine: 0x8664 - amd64
341374.f08: Timestamp: 0x56259295
342374.f08: Image Version: 6.1
343374.f08: SizeOfImage: 0x1a9000 (1740800)
344374.f08: Resource Dir: 0x14d000 LB 0x5a028
345374.f08: ProductName: Microsoft® Windows® Operating System
346374.f08: ProductVersion: 6.1.7601.19045
347374.f08: FileVersion: 6.1.7601.19045 (win7sp1_gdr.151019-1254)
348374.f08: FileDescription: NT Layer DLL
349374.f08: \SystemRoot\System32\kernel32.dll:
350374.f08: CreationTime: 2015-12-02T14:02:30.132441700Z
351374.f08: LastWriteTime: 2015-10-20T01:05:40.819000000Z
352374.f08: ChangeTime: 2015-12-02T15:48:45.617639900Z
353374.f08: FileAttributes: 0x20
354374.f08: Size: 0x11c600
355374.f08: NT Headers: 0xe8
356374.f08: Timestamp: 0x56259270
357374.f08: Machine: 0x8664 - amd64
358374.f08: Timestamp: 0x56259270
359374.f08: Image Version: 6.1
360374.f08: SizeOfImage: 0x120000 (1179648)
361374.f08: Resource Dir: 0x117000 LB 0x528
362374.f08: ProductName: Microsoft® Windows® Operating System
363374.f08: ProductVersion: 6.1.7601.19045
364374.f08: FileVersion: 6.1.7601.19045 (win7sp1_gdr.151019-1254)
365374.f08: FileDescription: Windows NT BASE API Client DLL
366374.f08: \SystemRoot\System32\KernelBase.dll:
367374.f08: CreationTime: 2015-12-02T14:02:30.070041600Z
368374.f08: LastWriteTime: 2015-10-20T01:05:40.819000000Z
369374.f08: ChangeTime: 2015-12-02T15:48:45.617639900Z
370374.f08: FileAttributes: 0x20
371374.f08: Size: 0x67c00
372374.f08: NT Headers: 0xe8
373374.f08: Timestamp: 0x56259271
374374.f08: Machine: 0x8664 - amd64
375374.f08: Timestamp: 0x56259271
376374.f08: Image Version: 6.1
377374.f08: SizeOfImage: 0x6c000 (442368)
378374.f08: Resource Dir: 0x6a000 LB 0x530
379374.f08: ProductName: Microsoft® Windows® Operating System
380374.f08: ProductVersion: 6.1.7601.19045
381374.f08: FileVersion: 6.1.7601.19045 (win7sp1_gdr.151019-1254)
382374.f08: FileDescription: Windows NT BASE API Client DLL
383374.f08: \SystemRoot\System32\apisetschema.dll:
384374.f08: CreationTime: 2015-12-02T14:02:29.524040700Z
385374.f08: LastWriteTime: 2015-10-20T00:53:47.280000000Z
386374.f08: ChangeTime: 2015-12-02T15:48:45.539639700Z
387374.f08: FileAttributes: 0x20
388374.f08: Size: 0x1a00
389374.f08: NT Headers: 0xc0
390374.f08: Timestamp: 0x562590e2
391374.f08: Machine: 0x8664 - amd64
392374.f08: Timestamp: 0x562590e2
393374.f08: Image Version: 6.1
394374.f08: SizeOfImage: 0x50000 (327680)
395374.f08: Resource Dir: 0x30000 LB 0x3f8
396374.f08: ProductName: Microsoft® Windows® Operating System
397374.f08: ProductVersion: 6.1.7601.19045
398374.f08: FileVersion: 6.1.7601.19045 (win7sp1_gdr.151019-1254)
399374.f08: FileDescription: ApiSet Schema DLL
400374.f08: NtOpenDirectoryObject failed on \Driver: 0xc0000022
401374.f08: supR3HardenedWinFindAdversaries: 0x0
402374.f08: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox'
403374.f08: Calling main()
404374.f08: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
405374.f08: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox'
406374.f08: '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
407374.f08: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe)
408374.f08: SUPR3HardenedMain: Final process, opening VBoxDrv...
409374.f08: supR3HardenedEarlyCompact: Removed heap 1 (0x00000000250000 LB 0x400000)
410374.f08: supR3HardNtEnableThreadCreation:
411374.f08: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSupLib.dll)
412374.f08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSupLib.dll
413374.f08: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c3c80:C:\Windows\system32 [calling]
414374.f08: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
415374.f08: supR3HardenedDllNotificationCallback: load 000007feee480000 LB 0x00005000 C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL [fFlags=0x0]
416374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
417374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
418374.f08: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c40b0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
419374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feee480000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
420374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
421374.f08: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c40b0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
422374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feee480000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
423374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feee480000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
424374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
425374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'crypt32.dll'.
426374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msasn1.dll'.
427374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
428374.f08: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\wintrust.dll)
429374.f08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\wintrust.dll
430374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
431374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
432374.f08: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll)
433374.f08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll
434374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
435374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume3\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
436374.f08: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\msasn1.dll)
437374.f08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\msasn1.dll
438374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
439374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume3\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
440374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
441374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msasn1.dll'.
442374.f08: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\crypt32.dll)
443374.f08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\crypt32.dll
444374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
445374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
446374.f08: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\msvcrt.dll)
447374.f08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\msvcrt.dll
448374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
449374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume3\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
450374.f08: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
451374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
452374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
453374.f08: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
454374.f08: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c3c80:C:\Windows\system32 [calling]
455374.f08: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
456374.f08: supR3HardenedDllNotificationCallback: load 000007fefd480000 LB 0x0003b000 C:\Windows\system32\Wintrust.dll [fFlags=0x0]
457374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
458374.f08: supR3HardenedDllNotificationCallback: load 000007fefda10000 LB 0x0009f000 C:\Windows\system32\msvcrt.dll [fFlags=0x0]
459374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
460374.f08: supR3HardenedDllNotificationCallback: load 000007fefd310000 LB 0x0016d000 C:\Windows\system32\CRYPT32.dll [fFlags=0x0]
461374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
462374.f08: supR3HardenedDllNotificationCallback: load 000007fefd220000 LB 0x0000f000 C:\Windows\system32\MSASN1.dll [fFlags=0x0]
463374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
464374.f08: supR3HardenedDllNotificationCallback: load 000007fefdc40000 LB 0x0012d000 C:\Windows\system32\RPCRT4.dll [fFlags=0x0]
465374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
466374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd480000 'C:\Windows\system32\Wintrust.dll'
467374.f08: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\bcrypt.dll)
468374.f08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\bcrypt.dll
469374.f08: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcrypt.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007f0e00:C:\Windows\system32 [calling]
470374.f08: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
471374.f08: supR3HardenedDllNotificationCallback: load 000007fefcba0000 LB 0x00022000 C:\Windows\system32\bcrypt.dll [fFlags=0x0]
472374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
473374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcba0000 'C:\Windows\system32\bcrypt.dll'
474374.f08: bcrypt.dll loaded at 000007fefcba0000, BCryptOpenAlgorithmProvider at 000007fefcba2640, preloading providers:
475374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
476374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'bcrypt.dll'.
477374.f08: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\bcryptprimitives.dll)
478374.f08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\bcryptprimitives.dll
479374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
480374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume3\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
481374.f08: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
482374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
483374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
484374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
485374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'rpcrt4.dll'.
486374.f08: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\advapi32.dll)
487374.f08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\advapi32.dll
488374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
489374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
490374.f08: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
491374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
492374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
493374.f08: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
494374.f08: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcryptprimitives.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c40b0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
495374.f08: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
496374.f08: supR3HardenedDllNotificationCallback: load 000007fefc650000 LB 0x0004c000 C:\Windows\system32\bcryptprimitives.dll [fFlags=0x0]
497374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
498374.f08: supR3HardenedDllNotificationCallback: load 000007fefd930000 LB 0x000db000 C:\Windows\system32\ADVAPI32.dll [fFlags=0x0]
499374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
500374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msvcrt.dll'.
501374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'rpcrt4.dll'.
502374.f08: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\sechost.dll)
503374.f08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\sechost.dll
504374.f08: supR3HardenedDllNotificationCallback: load 000007fefddf0000 LB 0x0001f000 C:\Windows\SYSTEM32\sechost.dll [fFlags=0x0]
505374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\sechost.dll [lacks WinVerifyTrust]
506374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc650000 'C:\Windows\system32\bcryptprimitives.dll'
507374.f08: BCryptOpenAlgorithmProvider(,'MD2',0,0) -> 0x0 (hAlgo=00000000007f24e0)
508374.f08: BCryptOpenAlgorithmProvider(,'MD4',0,0) -> 0x0 (hAlgo=00000000007f53a0)
509374.f08: BCryptOpenAlgorithmProvider(,'MD5',0,0) -> 0x0 (hAlgo=00000000007f54c0)
510374.f08: BCryptOpenAlgorithmProvider(,'SHA1',0,0) -> 0x0 (hAlgo=00000000007f56d0)
511374.f08: BCryptOpenAlgorithmProvider(,'SHA256',0,0) -> 0x0 (hAlgo=00000000007f57f0)
512374.f08: BCryptOpenAlgorithmProvider(,'SHA512',0,0) -> 0x0 (hAlgo=00000000007f5910)
513374.f08: BCryptOpenAlgorithmProvider(,'RSA',0,0) -> 0x0 (hAlgo=00000000007f5b50)
514374.f08: BCryptOpenAlgorithmProvider(,'DSA',0,0) -> 0x0 (hAlgo=00000000007f5c70)
515374.f08: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\cryptsp.dll)
516374.f08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\cryptsp.dll
517374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
518374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
519374.f08: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
520374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
521374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
522374.f08: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
523374.f08: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTSP.dll (Input=CRYPTSP.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c40b0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
524374.f08: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
525374.f08: supR3HardenedDllNotificationCallback: load 000007fefca50000 LB 0x00018000 C:\Windows\system32\CRYPTSP.dll [fFlags=0x0]
526374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
527374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefca50000 'C:\Windows\system32\CRYPTSP.dll'
528374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
529374.f08: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\rsaenh.dll)
530374.f08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\rsaenh.dll
531374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
532374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
533374.f08: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
534374.f08: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c40b0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
535374.f08: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
536374.f08: supR3HardenedDllNotificationCallback: load 000007fefc710000 LB 0x00047000 C:\Windows\system32\rsaenh.dll [fFlags=0x0]
537374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
538374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc710000 'C:\Windows\system32\rsaenh.dll'
539374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
540374.f08: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ADVAPI32.dll (Input=ADVAPI32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c40b0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
541374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd930000 'C:\Windows\system32\ADVAPI32.dll'
542374.f08: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\cryptbase.dll)
543374.f08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\cryptbase.dll
544374.f08: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTBASE.dll (Input=CRYPTBASE.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c40b0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
545374.f08: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptbase.dll [lacks WinVerifyTrust]
546374.f08: supR3HardenedDllNotificationCallback: load 000007fefd0b0000 LB 0x0000f000 C:\Windows\system32\CRYPTBASE.dll [fFlags=0x0]
547374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptbase.dll [lacks WinVerifyTrust]
548374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd0b0000 'C:\Windows\system32\CRYPTBASE.dll'
549374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
550374.f08: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c40b0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
551374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077340000 'C:\Windows\system32\kernel32.dll'
552374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
553374.f08: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\WINTRUST.DLL (Input=WINTRUST.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c40b0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
554374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd480000 'C:\Windows\system32\WINTRUST.DLL'
555374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
556374.f08: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPT32.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00000000007c40b0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
557374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd310000 'C:\Windows\system32\CRYPT32.dll'
558374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
559374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'advapi32.dll'.
560374.f08: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\imagehlp.dll)
561374.f08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\imagehlp.dll
562374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
563374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
564374.f08: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
565374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
566374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
567374.f08: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
568374.f08: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\imagehlp.dll (Input=imagehlp.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c40b0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
569374.f08: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\imagehlp.dll [lacks WinVerifyTrust]
570374.f08: supR3HardenedDllNotificationCallback: load 000007feff370000 LB 0x00019000 C:\Windows\system32\imagehlp.dll [fFlags=0x0]
571374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\imagehlp.dll [lacks WinVerifyTrust]
572374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff370000 'C:\Windows\system32\imagehlp.dll'
573374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
574374.f08: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTSP.dll (Input=CRYPTSP.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c40b0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
575374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefca50000 'C:\Windows\system32\CRYPTSP.dll'
576374.f08: \Device\HarddiskVolume3\Windows\System32\user32.dll: Owner is administrators group.
577374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
578374.f08: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\user32.dll)
579374.f08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\user32.dll
580374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
581374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
582374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
583374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'lpk.dll'.
584374.f08: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\gdi32.dll)
585374.f08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\gdi32.dll
586374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'lpk.dll'...
587374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'lpk.dll' -> '\Device\HarddiskVolume3\Windows\System32\lpk.dll' [rcNtRedir=0xc0150008]
588374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'gdi32.dll'.
589374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'user32.dll'.
590374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'usp10.dll'.
591374.f08: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\lpk.dll)
592374.f08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\lpk.dll
593374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
594374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
595374.f08: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\user32.dll [lacks WinVerifyTrust]
596374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'usp10.dll'...
597374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'usp10.dll' -> '\Device\HarddiskVolume3\Windows\System32\usp10.dll' [rcNtRedir=0xc0150008]
598374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
599374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
600374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'gdi32.dll'.
601374.f08: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\usp10.dll)
602374.f08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\usp10.dll
603374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
604374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
605374.f08: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\user32.dll [lacks WinVerifyTrust]
606374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
607374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
608374.f08: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
609374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
610374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
611374.f08: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
612374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
613374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
614374.f08: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\user32.dll [lacks WinVerifyTrust]
615374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
616374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
617374.f08: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
618374.f08: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\USER32.dll (Input=USER32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c40b0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
619374.f08: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\user32.dll [lacks WinVerifyTrust]
620374.f08: supR3HardenedDllNotificationCallback: load 0000000077240000 LB 0x000fa000 C:\Windows\system32\USER32.dll [fFlags=0x0]
621374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\user32.dll [lacks WinVerifyTrust]
622374.f08: supR3HardenedDllNotificationCallback: load 000007feff400000 LB 0x00067000 C:\Windows\system32\GDI32.dll [fFlags=0x0]
623374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
624374.f08: supR3HardenedDllNotificationCallback: load 000007feff390000 LB 0x0000e000 C:\Windows\system32\LPK.dll [fFlags=0x0]
625374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\lpk.dll [lacks WinVerifyTrust]
626374.f08: supR3HardenedDllNotificationCallback: load 000007fefd860000 LB 0x000c9000 C:\Windows\system32\USP10.dll [fFlags=0x0]
627374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\usp10.dll [lacks WinVerifyTrust]
628374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
629374.f08: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\gdi32.dll (Input=gdi32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c40b0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
630374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff400000 'C:\Windows\system32\gdi32.dll'
631374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'user32.dll'.
632374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
633374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msctf.dll'.
634374.f08: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\imm32.dll)
635374.f08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\imm32.dll
636374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msctf.dll'...
637374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'msctf.dll' -> '\Device\HarddiskVolume3\Windows\System32\msctf.dll' [rcNtRedir=0xc0150008]
638374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
639374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
640374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'gdi32.dll'.
641374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'imm32.dll'.
642374.f08: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\msctf.dll)
643374.f08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\msctf.dll
644374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
645374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
646374.f08: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
647374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
648374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
649374.f08: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\user32.dll [lacks WinVerifyTrust]
650374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
651374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume3\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
652374.f08: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\imm32.dll [lacks WinVerifyTrust]
653374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
654374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
655374.f08: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
656374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
657374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
658374.f08: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\user32.dll [lacks WinVerifyTrust]
659374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
660374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
661374.f08: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
662374.f08: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\IMM32.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c40b0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
663374.f08: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\imm32.dll [lacks WinVerifyTrust]
664374.f08: supR3HardenedDllNotificationCallback: load 000007fefd830000 LB 0x0002e000 C:\Windows\system32\IMM32.DLL [fFlags=0x0]
665374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\imm32.dll [lacks WinVerifyTrust]
666374.f08: supR3HardenedDllNotificationCallback: load 000007fefde10000 LB 0x00109000 C:\Windows\system32\MSCTF.dll [fFlags=0x0]
667374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\msctf.dll [lacks WinVerifyTrust]
668374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd830000 'C:\Windows\system32\IMM32.DLL'
669374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077240000 'C:\Windows\system32\USER32.dll'
670374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'bcrypt.dll'.
671374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
672374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msasn1.dll'.
673374.f08: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\ncrypt.dll)
674374.f08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\ncrypt.dll
675374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
676374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume3\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
677374.f08: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
678374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
679374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
680374.f08: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
681374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
682374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume3\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
683374.f08: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
684374.f08: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ncrypt.dll (Input=ncrypt.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c40b0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
685374.f08: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\ncrypt.dll [lacks WinVerifyTrust]
686374.f08: supR3HardenedDllNotificationCallback: load 000007fefcbd0000 LB 0x00050000 C:\Windows\system32\ncrypt.dll [fFlags=0x0]
687374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\ncrypt.dll [lacks WinVerifyTrust]
688374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcbd0000 'C:\Windows\system32\ncrypt.dll'
689374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
690374.f08: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcrypt.dll (Input=bcrypt.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c40b0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
691374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcba0000 'C:\Windows\system32\bcrypt.dll'
692374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
693374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'rpcrt4.dll'.
694374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'profapi.dll'.
695374.f08: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\userenv.dll)
696374.f08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\userenv.dll
697374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'profapi.dll'...
698374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'profapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\profapi.dll' [rcNtRedir=0xc0150008]
699374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
700374.f08: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\profapi.dll)
701374.f08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\profapi.dll
702374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
703374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
704374.f08: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
705374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
706374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
707374.f08: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
708374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
709374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
710374.f08: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
711374.f08: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\USERENV.dll (Input=USERENV.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c40b0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
712374.f08: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\userenv.dll [lacks WinVerifyTrust]
713374.f08: supR3HardenedDllNotificationCallback: load 000007fefd4c0000 LB 0x0001e000 C:\Windows\system32\USERENV.dll [fFlags=0x0]
714374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\userenv.dll [lacks WinVerifyTrust]
715374.f08: supR3HardenedDllNotificationCallback: load 000007fefd210000 LB 0x0000f000 C:\Windows\system32\profapi.dll [fFlags=0x0]
716374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\profapi.dll [lacks WinVerifyTrust]
717374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd4c0000 'C:\Windows\system32\USERENV.dll'
718374.f08: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007c40b0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
719374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefddf0000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
720374.f08: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007c40b0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
721374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefddf0000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
722374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
723374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'rpcrt4.dll'.
724374.f08: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\gpapi.dll)
725374.f08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\gpapi.dll
726374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
727374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
728374.f08: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
729374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
730374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
731374.f08: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
732374.f08: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\GPAPI.dll (Input=GPAPI.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c40b0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
733374.f08: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\gpapi.dll [lacks WinVerifyTrust]
734374.f08: supR3HardenedDllNotificationCallback: load 000007fefc4c0000 LB 0x0001b000 C:\Windows\system32\GPAPI.dll [fFlags=0x0]
735374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\gpapi.dll [lacks WinVerifyTrust]
736374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc4c0000 'C:\Windows\system32\GPAPI.dll'
737374.f08: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-Management-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007c40b0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
738374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefddf0000 'API-MS-WIN-Service-Management-L1-1-0.dll'
739374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
740374.f08: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rpcrt4.dll (Input=rpcrt4.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c40b0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
741374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdc40000 'C:\Windows\system32\rpcrt4.dll'
742374.f08: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-Management-L2-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007c40b0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
743374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefddf0000 'API-MS-WIN-Service-Management-L2-1-0.dll'
744374.f08: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007c40b0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
745374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefddf0000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
746374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
747374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'advapi32.dll'.
748374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'crypt32.dll'.
749374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'wldap32.dll'.
750374.f08: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\cryptnet.dll)
751374.f08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\cryptnet.dll
752374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wldap32.dll'...
753374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'wldap32.dll' -> '\Device\HarddiskVolume3\Windows\System32\wldap32.dll' [rcNtRedir=0xc0150008]
754374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
755374.f08: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\Wldap32.dll)
756374.f08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\Wldap32.dll
757374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
758374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume3\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
759374.f08: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
760374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
761374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
762374.f08: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
763374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
764374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
765374.f08: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
766374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
767374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
768374.f08: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
769374.f08: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (Input=cryptnet.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c40b0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
770374.f08: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
771374.f08: supR3HardenedDllNotificationCallback: load 000007fefa5e0000 LB 0x00027000 C:\Windows\system32\cryptnet.dll [fFlags=0x0]
772374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
773374.f08: supR3HardenedDllNotificationCallback: load 000007feff3a0000 LB 0x00052000 C:\Windows\system32\WLDAP32.dll [fFlags=0x0]
774374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\Wldap32.dll [lacks WinVerifyTrust]
775374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
776374.f08: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00000000007c40b0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
777374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa5e0000 'C:\Windows\system32\cryptnet.dll'
778374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
779374.f08: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00000000007c40b0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
780374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa5e0000 'C:\Windows\system32\cryptnet.dll'
781374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
782374.f08: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00000000007c40b0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
783374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa5e0000 'C:\Windows\system32\cryptnet.dll'
784374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
785374.f08: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00000000007c40b0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
786374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa5e0000 'C:\Windows\system32\cryptnet.dll'
787374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
788374.f08: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00000000007c40b0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
789374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa5e0000 'C:\Windows\system32\cryptnet.dll'
790374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
791374.f08: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00000000007c40b0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
792374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa5e0000 'C:\Windows\system32\cryptnet.dll'
793374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
794374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa5e0000 'C:\Windows\system32\cryptnet.dll'
795374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
796374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa5e0000 'C:\Windows\system32\cryptnet.dll'
797374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
798374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa5e0000 'C:\Windows\system32\cryptnet.dll'
799374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
800374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa5e0000 'C:\Windows\system32\cryptnet.dll'
801374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
802374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa5e0000 'C:\Windows\system32\cryptnet.dll'
803374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa5e0000 'C:\Windows\system32\cryptnet.dll'
804374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
805374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa5e0000 'C:\Windows\system32\cryptnet.dll'
806374.f08: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007c40b0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
807374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefddf0000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
808374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\profapi.dll [lacks WinVerifyTrust]
809374.f08: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\profapi.dll (Input=profapi.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c40b0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
810374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd210000 'C:\Windows\system32\profapi.dll'
811374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
812374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
813374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msvcrt.dll'.
814374.f08: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\shlwapi.dll)
815374.f08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\shlwapi.dll
816374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
817374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
818374.f08: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
819374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
820374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
821374.f08: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\user32.dll [lacks WinVerifyTrust]
822374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
823374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
824374.f08: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
825374.f08: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\SHLWAPI.dll (Input=SHLWAPI.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c40b0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
826374.f08: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\shlwapi.dll [lacks WinVerifyTrust]
827374.f08: supR3HardenedDllNotificationCallback: load 000007feff650000 LB 0x00071000 C:\Windows\system32\SHLWAPI.dll [fFlags=0x0]
828374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\shlwapi.dll [lacks WinVerifyTrust]
829374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff650000 'C:\Windows\system32\SHLWAPI.dll'
830374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000000 pwszName=\SystemRoot\System32\ntdll.dll
831374.f08: supR3HardNtViCallWinVerifyTrustCatFile: New context 00000000008663f0
832374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008663f0
833374.f08: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=9B1D637739FC6B271ED989F7454A98D5A76C1B7A
834374.f08: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007c40b0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
835374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefddf0000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
836374.f08: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-Management-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007c40b0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
837374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefddf0000 'API-MS-WIN-Service-Management-L1-1-0.dll'
838374.f08: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-winsvc-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007c40b0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
839374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefddf0000 'API-MS-WIN-Service-winsvc-L1-1-0.dll'
840374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
841374.f08: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ADVAPI32.dll (Input=ADVAPI32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c40b0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
842374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd930000 'C:\Windows\system32\ADVAPI32.dll'
843374.f08: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-LSALookup-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007c40b0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
844374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefddf0000 'API-MS-Win-Security-LSALookup-L1-1-0.dll'
845374.f08: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-LSALookup-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007c40b0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
846374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefddf0000 'API-MS-Win-Security-LSALookup-L1-1-0.dll'
847374.f08: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_60_for_KB3101746~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\SystemRoot\System32\ntdll.dll'
848374.f08: g_pfnWinVerifyTrust=000007fefd481010
849374.f08: supR3HardenedScreenImage/preload: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll [redoing WinVerifyTrust]
850374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000e0 pwszName=\Device\HarddiskVolume3\Windows\System32\crypt32.dll
851374.f08: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008663f0
852374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008663f0
853374.f08: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=BFD41401EDEBD4D914977D62B588ECABEE60CFD3
854374.f08: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_112_for_KB3040272~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume3\Windows\System32\crypt32.dll'
855374.f08: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
856374.f08: supR3HardenedScreenImage/preload: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\crypt32.dll'
857374.f08: supR3HardenedScreenImage/preload: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\wintrust.dll [redoing WinVerifyTrust]
858374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000d4 pwszName=\Device\HarddiskVolume3\Windows\System32\wintrust.dll
859374.f08: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008663f0
860374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008663f0
861374.f08: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=E1BBE4EB6D114F50142F24E2E2749EFD81021486
862374.f08: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_75_for_KB3040272~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume3\Windows\System32\wintrust.dll'
863374.f08: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
864374.f08: supR3HardenedScreenImage/preload: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\wintrust.dll'
865374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000374 pwszName=\Device\HarddiskVolume3\Windows\System32\shlwapi.dll
866374.f08: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008663f0
867374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008663f0
868374.f08: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=0AB8D9C9D3E1FC95D01F9A984B16ED031BB40CD8
869374.f08: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume3\Windows\System32\shlwapi.dll'
870374.f08: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
871374.f08: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\shlwapi.dll'
872374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000368 pwszName=\Device\HarddiskVolume3\Windows\System32\Wldap32.dll
873374.f08: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008663f0
874374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008663f0
875374.f08: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=87E73086F2528CF31D3AD5F0D71E04F8B942D5D8
876374.f08: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume3\Windows\System32\Wldap32.dll'
877374.f08: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
878374.f08: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\Wldap32.dll'
879374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000364 pwszName=\Device\HarddiskVolume3\Windows\System32\cryptnet.dll
880374.f08: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008663f0
881374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008663f0
882374.f08: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=756DC088EE40CF9369C990D71B200F3CB59FC35D
883374.f08: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_75_for_KB3040272~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume3\Windows\System32\cryptnet.dll'
884374.f08: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
885374.f08: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\cryptnet.dll'
886374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000250 pwszName=\Device\HarddiskVolume3\Windows\System32\gpapi.dll
887374.f08: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008663f0
888374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008663f0
889374.f08: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=470795C189226F7BDB8E50F42104CC34488B9340
890374.f08: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume3\Windows\System32\gpapi.dll'
891374.f08: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
892374.f08: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\gpapi.dll'
893374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000001bc pwszName=\Device\HarddiskVolume3\Windows\System32\profapi.dll
894374.f08: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008663f0
895374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008663f0
896374.f08: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2449672745D9BA339420451D13FA0380AA768231
897374.f08: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume3\Windows\System32\profapi.dll'
898374.f08: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
899374.f08: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\profapi.dll'
900374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000001b8 pwszName=\Device\HarddiskVolume3\Windows\System32\userenv.dll
901374.f08: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008663f0
902374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008663f0
903374.f08: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=D3E1A2CC7367F751C19EBF4E6EDF5E9A10E47313
904374.f08: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume3\Windows\System32\userenv.dll'
905374.f08: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
906374.f08: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\userenv.dll'
907374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000001a4 pwszName=\Device\HarddiskVolume3\Windows\System32\ncrypt.dll
908374.f08: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008663f0
909374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008663f0
910374.f08: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=DE8C9B0409BB6DC8348383C722B4EC4291BB2193
911374.f08: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_60_for_KB3101746~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume3\Windows\System32\ncrypt.dll'
912374.f08: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
913374.f08: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\ncrypt.dll'
914374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000018c pwszName=\Device\HarddiskVolume3\Windows\System32\msctf.dll
915374.f08: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008663f0
916374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008663f0
917374.f08: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=03916BC73EE5A0E312E3D3100D0ACE1B78E93BB1
918374.f08: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3033889~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume3\Windows\System32\msctf.dll'
919374.f08: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
920374.f08: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\msctf.dll'
921374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000188 pwszName=\Device\HarddiskVolume3\Windows\System32\imm32.dll
922374.f08: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008663f0
923374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008663f0
924374.f08: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=6EEE1AB3B6D79AFF857940FF5F51ED27698153EC
925374.f08: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume3\Windows\System32\imm32.dll'
926374.f08: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
927374.f08: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\imm32.dll'
928374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000184 pwszName=\Device\HarddiskVolume3\Windows\System32\usp10.dll
929374.f08: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008663f0
930374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008663f0
931374.f08: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=1F1AA8340DE02FC1B6341EE2706E55D56EDF63B8
932374.f08: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB2957509~31bf3856ad364e35~amd64~~6.1.1.2.cat'; file='\Device\HarddiskVolume3\Windows\System32\usp10.dll'
933374.f08: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
934374.f08: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\usp10.dll'
935374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000180 pwszName=\Device\HarddiskVolume3\Windows\System32\lpk.dll
936374.f08: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008663f0
937374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008663f0
938374.f08: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=FDBA63132AE4F561C5CFC5478222E40A2DAA2ACC
939374.f08: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3087039~31bf3856ad364e35~amd64~~6.1.1.4.cat'; file='\Device\HarddiskVolume3\Windows\System32\lpk.dll'
940374.f08: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
941374.f08: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\lpk.dll'
942374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000017c pwszName=\Device\HarddiskVolume3\Windows\System32\gdi32.dll
943374.f08: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008663f0
944374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008663f0
945374.f08: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=EB178841F5FFC6B05E668168217B0AC222A62955
946374.f08: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3069392~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume3\Windows\System32\gdi32.dll'
947374.f08: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
948374.f08: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\gdi32.dll'
949374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000178 pwszName=\Device\HarddiskVolume3\Windows\System32\user32.dll
950374.f08: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008663f0
951374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008663f0
952374.f08: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=FB05A6DD4AF9AC247D37C4B7BAFCCBD178A41E64
953374.f08: supR3HardNtViCallWinVerifyTrustCatFile: Retrying with fresh context (CryptCATAdminEnumCatalogFromHash -> 1168; iCat=0x0)
954374.f08: supR3HardNtViCallWinVerifyTrustCatFile: New context 0000000002bfe0f0
955374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000002bfe0f0
956374.f08: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=FB05A6DD4AF9AC247D37C4B7BAFCCBD178A41E64
957374.f08: supR3HardNtViCallWinVerifyTrustCatFile: CryptCATAdminEnumCatalogFromHash failed ERRROR_NOT_FOUND (1168)
958374.f08: supR3HardNtViCallWinVerifyTrustCatFile: New context 0000000002bfe1b0
959374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000002bfe1b0
960374.f08: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=32 wszDigest=7458187B83265348D287AC7AB34C0A5AD0EFDAA5040E43F37D2AC3DBEB747E20
961374.f08: supR3HardNtViCallWinVerifyTrustCatFile: CryptCATAdminEnumCatalogFromHash failed ERRROR_NOT_FOUND (1168)
962374.f08: supR3HardNtViCallWinVerifyTrustCatFile -> -22900 (org 22900)
963374.f08: supR3HardenedWinVerifyCacheProcessWvtTodos: -22900 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\user32.dll'
964374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000174 pwszName=\Device\HarddiskVolume3\Windows\System32\imagehlp.dll
965374.f08: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000002bfe0f0
966374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000002bfe0f0
967374.f08: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2702EE05F1B717B0F2CE0FBE32784A47B8419DCA
968374.f08: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_2_for_KB2893294~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume3\Windows\System32\imagehlp.dll'
969374.f08: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
970374.f08: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\imagehlp.dll'
971374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000130 pwszName=\Device\HarddiskVolume3\Windows\System32\cryptbase.dll
972374.f08: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000002bfe0f0
973374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000002bfe0f0
974374.f08: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=DD41E47CDA7ECDD58265F0739B9BC23E0761082B
975374.f08: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_60_for_KB3101746~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume3\Windows\System32\cryptbase.dll'
976374.f08: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
977374.f08: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\cryptbase.dll'
978374.f08: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\rsaenh.dll'
979374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000012c pwszName=\Device\HarddiskVolume3\Windows\System32\cryptsp.dll
980374.f08: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000002bfe0f0
981374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000002bfe0f0
982374.f08: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=BA7AC4A7E8ADDFEA90AC951ECB6D6546E4873613
983374.f08: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_115_for_KB3033929~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume3\Windows\System32\cryptsp.dll'
984374.f08: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
985374.f08: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\cryptsp.dll'
986374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000120 pwszName=\Device\HarddiskVolume3\Windows\System32\sechost.dll
987374.f08: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000002bfe0f0
988374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000002bfe0f0
989374.f08: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=CB669FA8DB80F8E50A29D055BB8D558E10E5E6B4
990374.f08: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_85_for_KB3068708~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume3\Windows\System32\sechost.dll'
991374.f08: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
992374.f08: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\sechost.dll'
993374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000011c pwszName=\Device\HarddiskVolume3\Windows\System32\advapi32.dll
994374.f08: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000002bfe0f0
995374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000002bfe0f0
996374.f08: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=D58A667BECF67ECC76D4BEEDB96E9F1960013145
997374.f08: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_60_for_KB3080149~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume3\Windows\System32\advapi32.dll'
998374.f08: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
999374.f08: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\advapi32.dll'
1000374.f08: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\bcryptprimitives.dll'
1001374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000104 pwszName=\Device\HarddiskVolume3\Windows\System32\bcrypt.dll
1002374.f08: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000002bfe0f0
1003374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000002bfe0f0
1004374.f08: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=62E377A1F0AD0C2EDC0A73CB3EFF841FF18D00D2
1005374.f08: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume3\Windows\System32\bcrypt.dll'
1006374.f08: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1007374.f08: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\bcrypt.dll'
1008374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000e4 pwszName=\Device\HarddiskVolume3\Windows\System32\msvcrt.dll
1009374.f08: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000002bfe0f0
1010374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000002bfe0f0
1011374.f08: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2CA2FD632B264C063162F71474266E3615B6420C
1012374.f08: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB2654428~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume3\Windows\System32\msvcrt.dll'
1013374.f08: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1014374.f08: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll'
1015374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000dc pwszName=\Device\HarddiskVolume3\Windows\System32\msasn1.dll
1016374.f08: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000002bfe0f0
1017374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000002bfe0f0
1018374.f08: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F2FF57DC30D774F93061607060DAA0DD15E39CCE
1019374.f08: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume3\Windows\System32\msasn1.dll'
1020374.f08: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1021374.f08: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\msasn1.dll'
1022374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000d8 pwszName=\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll
1023374.f08: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000002bfe0f0
1024374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000002bfe0f0
1025374.f08: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=35EB15A32FF6A8320A28B76654C7C05F183C0649
1026374.f08: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_60_for_KB3101746~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll'
1027374.f08: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1028374.f08: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll'
1029374.f08: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSupLib.dll'
1030374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000028 pwszName=\Device\HarddiskVolume3\Windows\System32\KernelBase.dll
1031374.f08: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000002bfe0f0
1032374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000002bfe0f0
1033374.f08: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=D187E2BFBA7ED9D015FB710000144445CAD8B2DE
1034374.f08: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_60_for_KB3101746~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume3\Windows\System32\KernelBase.dll'
1035374.f08: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1036374.f08: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\KernelBase.dll'
1037374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000020 pwszName=\Device\HarddiskVolume3\Windows\System32\kernel32.dll
1038374.f08: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000002bfe0f0
1039374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000002bfe0f0
1040374.f08: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=3ABD4E7598BD11C4FA1AD66BF1B854BCC2A7C5DD
1041374.f08: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_60_for_KB3101746~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume3\Windows\System32\kernel32.dll'
1042374.f08: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1043374.f08: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\kernel32.dll'
1044374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll
1045374.f08: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\crypt32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000002b80210:C:\Windows\system32 [calling]
1046374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd310000 'C:\Windows\system32\crypt32.dll'
1047374.f08: supR3HardenedWinIsDesiredRootCA: Adding 0x5ad46780fa5df300 DC=com, DC=microsoft, CN=Microsoft Root Certificate Authority
1048374.f08: supR3HardenedWinIsDesiredRootCA: Adding 0xea5386456178582b C=ZA, ST=Western Cape, L=Durbanville, O=Thawte, OU=Thawte Certification, CN=Thawte Timestamping CA
1049374.f08: supR3HardenedWinIsDesiredRootCA: Adding 0x3be670c1bd02a900 OU=Copyright (c) 1997 Microsoft Corp., OU=Microsoft Corporation, CN=Microsoft Root Authority
1050374.f08: supR3HardenedWinIsDesiredRootCA: Adding 0x4d3835aa4180b200 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2011
1051374.f08: supR3HardenedWinIsDesiredRootCA: Adding 0x646e3fe3ba08df00 C=US, O=MSFT, CN=Microsoft Authenticode(tm) Root Authority
1052374.f08: supR3HardenedWinIsDesiredRootCA: Adding 0xece4e4289e08b900 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010
1053374.f08: supR3HardenedWinIsDesiredRootCA: Adding 0x43a9cc371ff5385a O=Microsoft Trust Network, OU=Microsoft Corporation, OU=Microsoft Time Stamping Service Root, OU=Copyright (c) 1997 Microsoft Corp.
1054374.f08: supR3HardenedWinIsDesiredRootCA: Adding 0x2e2d2c7c68f0202e O=VeriSign Trust Network, OU=VeriSign, Inc., OU=VeriSign Time Stamping Service Root, OU=NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.
1055374.f08: supR3HardenedWinIsDesiredRootCA: Adding 0x61a3a33f81aace00 C=US, ST=UT, L=Salt Lake City, O=The USERTRUST Network, OU=http://www.usertrust.com, CN=UTN-USERFirst-Object
1056374.f08: supR3HardenedWinIsDesiredRootCA: Adding 0x3d98ab22bb04a300 C=IE, O=Baltimore, OU=CyberTrust, CN=Baltimore CyberTrust Root
1057374.f08: supR3HardenedWinIsDesiredRootCA: Adding 0xa0ee62086758b15d C=US, O=Equifax, OU=Equifax Secure Certificate Authority
1058374.f08: supR3HardenedWinIsDesiredRootCA: Adding 0xa3ce8d99e60eda00 C=BE, O=GlobalSign nv-sa, OU=Root CA, CN=GlobalSign Root CA
1059374.f08: supR3HardenedWinIsDesiredRootCA: Adding 0x7ae89c50f0b6a00f C=US, O=GTE Corporation, OU=GTE CyberTrust Solutions, Inc., CN=GTE CyberTrust Global Root
1060374.f08: supR3HardenedWinIsDesiredRootCA: Adding 0x4d3835aa4180b200 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2011
1061374.f08: supR3HardenedWinIsDesiredRootCA: Adding 0x14018a1bf29e595c C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority
1062374.f08: supR3HardenedWinIsDesiredRootCA: Adding 0x9e5bc2d78b6a3636 C=ZA, ST=Western Cape, L=Cape Town, O=Thawte Consulting cc, OU=Certification Services Division, CN=Thawte Premium Server CA, [email protected]
1063374.f08: supR3HardenedWinIsDesiredRootCA: Adding 0x357a29080824af00 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2006 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G5
1064374.f08: supR3HardenedWinIsDesiredRootCA: Adding 0x8043e4ce150ead00 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID Root CA
1065374.f08: supR3HardenedWinRetrieveTrustedRootCAs: cAdded=18
1066374.f08: SUPR3HardenedMain: Load Runtime...
1067374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
1068374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
1069374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ws2_32.dll'.
1070374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'rpcrt4.dll'.
1071374.f08: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll) WinVerifyTrust
1072374.f08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll
1073374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
1074374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
1075374.f08: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll
1076374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
1077374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
1078374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000003c8 pwszName=\Device\HarddiskVolume3\Windows\System32\ws2_32.dll
1079374.f08: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000002bfe0f0
1080374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000002bfe0f0
1081374.f08: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=3EF3BDC1E84DFA17EA056313214EE88EC3E66F79
1082374.f08: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume3\Windows\System32\ws2_32.dll'
1083374.f08: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1084374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1085374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'rpcrt4.dll'.
1086374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'nsi.dll'.
1087374.f08: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\ws2_32.dll) WinVerifyTrust
1088374.f08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\ws2_32.dll
1089374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
1090374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
1091374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
1092374.f08: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll) WinVerifyTrust
1093374.f08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll
1094374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
1095374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
1096374.f08: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll) WinVerifyTrust
1097374.f08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll
1098374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
1099374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
1100374.f08: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll
1101374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
1102374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume3\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
1103374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000003dc pwszName=\Device\HarddiskVolume3\Windows\System32\nsi.dll
1104374.f08: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000002bfe0f0
1105374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000002bfe0f0
1106374.f08: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=7AFD8538945F2D05BC1AF949B9B19B7D2D9FBBF8
1107374.f08: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume3\Windows\System32\nsi.dll'
1108374.f08: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1109374.f08: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\nsi.dll) WinVerifyTrust
1110374.f08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\nsi.dll
1111374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
1112374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
1113374.f08: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll
1114374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1115374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1116374.f08: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll
1117374.f08: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000824220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
1118374.f08: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll
1119374.f08: supR3HardenedDllNotificationCallback: load 000007feed400000 LB 0x00519000 C:\Program Files\Oracle\VirtualBox\VBoxRT.dll [fFlags=0x0]
1120374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll
1121374.f08: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll
1122374.f08: supR3HardenedDllNotificationCallback: load 000000006d4c0000 LB 0x000d2000 C:\Program Files\Oracle\VirtualBox\MSVCR100.dll [fFlags=0x0]
1123374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll
1124374.f08: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll
1125374.f08: supR3HardenedDllNotificationCallback: load 0000000073a20000 LB 0x00098000 C:\Program Files\Oracle\VirtualBox\MSVCP100.dll [fFlags=0x0]
1126374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll
1127374.f08: supR3HardenedDllNotificationCallback: load 000007fefdf20000 LB 0x0004d000 C:\Windows\system32\WS2_32.dll [fFlags=0x0]
1128374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ws2_32.dll
1129374.f08: supR3HardenedDllNotificationCallback: load 000007feff360000 LB 0x00008000 C:\Windows\system32\NSI.dll [fFlags=0x0]
1130374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\nsi.dll
1131374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll
1132374.f08: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c40b0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
1133374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed400000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1134374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll
1135374.f08: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c40b0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
1136374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed400000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1137374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll
1138374.f08: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c40b0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
1139374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed400000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1140374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll
1141374.f08: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c40b0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
1142374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed400000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1143374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll
1144374.f08: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c40b0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
1145374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed400000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1146374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll
1147374.f08: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c40b0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
1148374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed400000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1149374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed400000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1150374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed400000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1151374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed400000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1152374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed400000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1153374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed400000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1154374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed400000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1155374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed400000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1156374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll
1157374.f08: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c40b0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
1158374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed400000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1159374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed400000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1160374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed400000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1161374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed400000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1162374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed400000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1163374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed400000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1164374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed400000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1165374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed400000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1166374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed400000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1167374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed400000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1168374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed400000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1169374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed400000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1170374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed400000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1171374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed400000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1172374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed400000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1173374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed400000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1174374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll
1175374.f08: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c40b0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ [calling]
1176374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed400000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1177374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed400000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1178374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed400000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1179374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed400000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1180374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wintrust.dll
1181374.f08: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007f7780:C:\Windows\system32 [calling]
1182374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd480000 'C:\Windows\system32\Wintrust.dll'
1183374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll
1184374.f08: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\crypt32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007f7780:C:\Windows\system32 [calling]
1185374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd310000 'C:\Windows\system32\crypt32.dll'
1186374.f08: SUPR3HardenedMain: Load TrustedMain...
1187374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'opengl32.dll'.
1188374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
1189374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcp100.dll'.
1190374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcr100.dll'.
1191374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qt5corevbox.dll'.
1192374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'qt5guivbox.dll'.
1193374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'qt5widgetsvbox.dll'.
1194374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'qt5printsupportvbox.dll'.
1195374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'qt5openglvbox.dll'.
1196374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'user32.dll'.
1197374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'advapi32.dll'.
1198374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'shell32.dll'.
1199374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'ole32.dll'.
1200374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'oleaut32.dll'.
1201374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #15 'winmm.dll'.
1202374.f08: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.dll) WinVerifyTrust
1203374.f08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.dll
1204374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
1205374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume3\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
1206374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000448 pwszName=\Device\HarddiskVolume3\Windows\System32\winmm.dll
1207374.f08: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000002bfe0f0
1208374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000002bfe0f0
1209374.f08: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=82E2B2A7826F88BEB98FFF0540C9BDB0A12F001A
1210374.f08: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume3\Windows\System32\winmm.dll'
1211374.f08: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1212374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
1213374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
1214374.f08: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\winmm.dll) WinVerifyTrust
1215374.f08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\winmm.dll
1216374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
1217374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume3\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
1218374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000430 pwszName=\Device\HarddiskVolume3\Windows\System32\oleaut32.dll
1219374.f08: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000002bfe0f0
1220374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000002bfe0f0
1221374.f08: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=8A837B0D823EB506C6A4C447C1962174D27ED954
1222374.f08: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3020338~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume3\Windows\System32\oleaut32.dll'
1223374.f08: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1224374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ole32.dll'.
1225374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
1226374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
1227374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'user32.dll'.
1228374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'gdi32.dll'.
1229374.f08: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\oleaut32.dll) WinVerifyTrust
1230374.f08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\oleaut32.dll
1231374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
1232374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
1233374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000044c pwszName=\Device\HarddiskVolume3\Windows\System32\ole32.dll
1234374.f08: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000002bfe0f0
1235374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000002bfe0f0
1236374.f08: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2E93C1851E5754D607F55581B4DE2A30B711C830
1237374.f08: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_2_for_KB3072633~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume3\Windows\System32\ole32.dll'
1238374.f08: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1239374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1240374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
1241374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'user32.dll'.
1242374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'rpcrt4.dll'.
1243374.f08: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\ole32.dll) WinVerifyTrust
1244374.f08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\ole32.dll
1245374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
1246374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume3\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
1247374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000045c pwszName=\Device\HarddiskVolume3\Windows\System32\shell32.dll
1248374.f08: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000002bfe0f0
1249374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000002bfe0f0
1250374.f08: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=FB4A0D952E568C1E85DCE662F9A066FFB2E6CE84
1251374.f08: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3080446~31bf3856ad364e35~amd64~~6.1.1.2.cat'; file='\Device\HarddiskVolume3\Windows\System32\shell32.dll'
1252374.f08: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1253374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1254374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #21 'shlwapi.dll'.
1255374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'user32.dll'.
1256374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #24 'gdi32.dll'.
1257374.f08: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\shell32.dll) WinVerifyTrust
1258374.f08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\shell32.dll
1259374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
1260374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
1261374.f08: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\advapi32.dll
1262374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1263374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1264374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5openglvbox.dll'...
1265374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5openglvbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5openglvbox.dll' [rcNtRedir=0xc0150008]
1266374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'qt5widgetsvbox.dll'.
1267374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'qt5guivbox.dll'.
1268374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5corevbox.dll'.
1269374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcr100.dll'.
1270374.f08: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll) WinVerifyTrust
1271374.f08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll
1272374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5printsupportvbox.dll'...
1273374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5printsupportvbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5printsupportvbox.dll' [rcNtRedir=0xc0150008]
1274374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
1275374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
1276374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5widgetsvbox.dll'.
1277374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qt5guivbox.dll'.
1278374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qt5corevbox.dll'.
1279374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'winspool.drv'.
1280374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'comdlg32.dll'.
1281374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'msvcr100.dll'.
1282374.f08: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5PrintSupportVBox.dll) WinVerifyTrust
1283374.f08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5PrintSupportVBox.dll
1284374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
1285374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
1286374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
1287374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
1288374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5guivbox.dll'.
1289374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qt5corevbox.dll'.
1290374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'shell32.dll'.
1291374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcr100.dll'.
1292374.f08: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll) WinVerifyTrust
1293374.f08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll
1294374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
1295374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
1296374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'opengl32.dll'.
1297374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
1298374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
1299374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qt5corevbox.dll'.
1300374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msvcp100.dll'.
1301374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcr100.dll'.
1302374.f08: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll) WinVerifyTrust
1303374.f08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
1304374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
1305374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
1306374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
1307374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'shell32.dll'.
1308374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ole32.dll'.
1309374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
1310374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ws2_32.dll'.
1311374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'mpr.dll'.
1312374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'msvcp100.dll'.
1313374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'msvcr100.dll'.
1314374.f08: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll) WinVerifyTrust
1315374.f08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
1316374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
1317374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
1318374.f08: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll
1319374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
1320374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
1321374.f08: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll
1322374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
1323374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
1324374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
1325374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume3\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
1326374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000450 pwszName=\Device\HarddiskVolume3\Windows\System32\opengl32.dll
1327374.f08: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000002bfe0f0
1328374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000002bfe0f0
1329374.f08: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=608AC397FCC42B9FBAE25CB8C25EAF4C19AA384D
1330374.f08: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume3\Windows\System32\opengl32.dll'
1331374.f08: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1332374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1333374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
1334374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'gdi32.dll'.
1335374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'glu32.dll'.
1336374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ddraw.dll'.
1337374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'user32.dll'.
1338374.f08: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\opengl32.dll) WinVerifyTrust
1339374.f08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\opengl32.dll
1340374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1341374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1342374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ddraw.dll'...
1343374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'ddraw.dll' -> '\Device\HarddiskVolume3\Windows\System32\ddraw.dll' [rcNtRedir=0xc0150008]
1344374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000460 pwszName=\Device\HarddiskVolume3\Windows\System32\ddraw.dll
1345374.f08: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000002bfe0f0
1346374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000002bfe0f0
1347374.f08: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=24C763EA54CD792A0F1618411061DC356EE31FF6
1348374.f08: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume3\Windows\System32\ddraw.dll'
1349374.f08: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1350374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1351374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
1352374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'dciman32.dll'.
1353374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
1354374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'setupapi.dll'.
1355374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'dwmapi.dll'.
1356374.f08: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\ddraw.dll) WinVerifyTrust
1357374.f08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\ddraw.dll
1358374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'glu32.dll'...
1359374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'glu32.dll' -> '\Device\HarddiskVolume3\Windows\System32\glu32.dll' [rcNtRedir=0xc0150008]
1360374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000464 pwszName=\Device\HarddiskVolume3\Windows\System32\glu32.dll
1361374.f08: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000002bfe0f0
1362374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000002bfe0f0
1363374.f08: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=60E45AB914E06A11F44EA76C6EF750AF892F9EA2
1364374.f08: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume3\Windows\System32\glu32.dll'
1365374.f08: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1366374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1367374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'opengl32.dll'.
1368374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
1369374.f08: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\glu32.dll) WinVerifyTrust
1370374.f08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\glu32.dll
1371374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1372374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1373374.f08: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll
1374374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
1375374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
1376374.f08: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\advapi32.dll
1377374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1378374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1379374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
1380374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
1381374.f08: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll
1382374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
1383374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
1384374.f08: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll
1385374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mpr.dll'...
1386374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'mpr.dll' -> '\Device\HarddiskVolume3\Windows\System32\mpr.dll' [rcNtRedir=0xc0150008]
1387374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000490 pwszName=\Device\HarddiskVolume3\Windows\System32\mpr.dll
1388374.f08: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000002bfe0f0
1389374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000002bfe0f0
1390374.f08: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F84FE9BA047B24E7694C9E0C349B48B9FD5F925B
1391374.f08: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume3\Windows\System32\mpr.dll'
1392374.f08: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1393374.f08: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\mpr.dll) WinVerifyTrust
1394374.f08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\mpr.dll
1395374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
1396374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
1397374.f08: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ws2_32.dll
1398374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
1399374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
1400374.f08: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\advapi32.dll
1401374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
1402374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
1403374.f08: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ole32.dll
1404374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
1405374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume3\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
1406374.f08: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shell32.dll
1407374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1408374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1409374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
1410374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
1411374.f08: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll
1412374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
1413374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
1414374.f08: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll
1415374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
1416374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
1417374.f08: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
1418374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1419374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1420374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1421374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1422374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
1423374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume3\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
1424374.f08: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\opengl32.dll
1425374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
1426374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
1427374.f08: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll
1428374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
1429374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume3\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
1430374.f08: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shell32.dll
1431374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
1432374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
1433374.f08: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
1434374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
1435374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
1436374.f08: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
1437374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1438374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1439374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1440374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1441374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
1442374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
1443374.f08: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll
1444374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comdlg32.dll'...
1445374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'comdlg32.dll' -> '\Device\HarddiskVolume3\Windows\System32\comdlg32.dll' [rcNtRedir=0xc0150008]
1446374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000420 pwszName=\Device\HarddiskVolume3\Windows\System32\comdlg32.dll
1447374.f08: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000002bfe0f0
1448374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000002bfe0f0
1449374.f08: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=66EE5BDFFA413AEA9E1FE7838A08646E94136DA5
1450374.f08: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume3\Windows\System32\comdlg32.dll'
1451374.f08: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1452374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1453374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'shlwapi.dll'.
1454374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
1455374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'gdi32.dll'.
1456374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'comctl32.dll'.
1457374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'shell32.dll'.
1458374.f08: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\comdlg32.dll) WinVerifyTrust
1459374.f08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\comdlg32.dll
1460374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winspool.drv'...
1461374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'winspool.drv' -> '\Device\HarddiskVolume3\Windows\System32\winspool.drv' [rcNtRedir=0xc0150008]
1462374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000484 pwszName=\Device\HarddiskVolume3\Windows\System32\winspool.drv
1463374.f08: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000002bfe0f0
1464374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000002bfe0f0
1465374.f08: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=C89A2ED7B99A056D78CA6BAC9CCAB8B1FF119A14
1466374.f08: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume3\Windows\System32\winspool.drv'
1467374.f08: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1468374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1469374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
1470374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
1471374.f08: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\winspool.drv) WinVerifyTrust
1472374.f08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\winspool.drv
1473374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
1474374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
1475374.f08: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
1476374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
1477374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
1478374.f08: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
1479374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
1480374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
1481374.f08: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll
1482374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1483374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1484374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1485374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1486374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
1487374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
1488374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
1489374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
1490374.f08: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
1491374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
1492374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
1493374.f08: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
1494374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
1495374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
1496374.f08: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll
1497374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1498374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1499374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1500374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1501374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
1502374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
1503374.f08: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shlwapi.dll
1504374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1505374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1506374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
1507374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
1508374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1509374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1510374.f08: supR3HardenedScreenImage/Imports: cache hit (Unknown Status -22900 (0xffffa68c)) on \Device\HarddiskVolume3\Windows\System32\user32.dll
1511374.f08: Error (rc=0):
1512374.f08: supR3HardenedScreenImage/Imports: cached rc=Unknown Status -22900 (0xffffa68c) fImage=1 fProtect=0x0 fAccess=0x0 cHits=16 \Device\HarddiskVolume3\Windows\System32\user32.dll
1513374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1514374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1515374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1516374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1517374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1518374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1519374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1520374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1521374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
1522374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
1523374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1524374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1525374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
1526374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
1527374.f08: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ole32.dll
1528374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1529374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1530374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1531374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1532374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1533374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1534374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1535374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1536374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1537374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1538374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
1539374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume3\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
1540374.f08: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shell32.dll
1541374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comctl32.dll'...
1542374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'comctl32.dll' -> '\Device\HarddiskVolume3\Windows\System32\comctl32.dll' [rcNtRedir=0x0]
1543374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000478 pwszName=\Device\HarddiskVolume3\Windows\System32\comctl32.dll
1544374.f08: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000002bfe0f0
1545374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000002bfe0f0
1546374.f08: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=761964761EE466757E306124E042F4C2ACBEA092
1547374.f08: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3059317~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume3\Windows\System32\comctl32.dll'
1548374.f08: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1549374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'advapi32.dll'.
1550374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
1551374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
1552374.f08: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\comctl32.dll) WinVerifyTrust
1553374.f08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\comctl32.dll
1554374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1555374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1556374.f08: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll
1557374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1558374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1559374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
1560374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
1561374.f08: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shlwapi.dll
1562374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1563374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1564374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1565374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1566374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
1567374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume3\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
1568374.f08: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\opengl32.dll
1569374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1570374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1571374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dwmapi.dll'...
1572374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'dwmapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\dwmapi.dll' [rcNtRedir=0xc0150008]
1573374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004b0 pwszName=\Device\HarddiskVolume3\Windows\System32\dwmapi.dll
1574374.f08: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000002bfe0f0
1575374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000002bfe0f0
1576374.f08: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F3F3D4867E9140896E0742D7EE8AE1D01FE85ECE
1577374.f08: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3078667~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume3\Windows\System32\dwmapi.dll'
1578374.f08: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1579374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1580374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
1581374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
1582374.f08: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\dwmapi.dll) WinVerifyTrust
1583374.f08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\dwmapi.dll
1584374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
1585374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
1586374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000474 pwszName=\Device\HarddiskVolume3\Windows\System32\setupapi.dll
1587374.f08: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000002bfe0f0
1588374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000002bfe0f0
1589374.f08: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=1499C4FEA6E143F9BEC35B4FFA098917D3A6EBF2
1590374.f08: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume3\Windows\System32\setupapi.dll'
1591374.f08: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1592374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'cfgmgr32.dll'.
1593374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcrt.dll'.
1594374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'gdi32.dll'.
1595374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
1596374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'user32.dll'.
1597374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'oleaut32.dll'.
1598374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'devobj.dll'.
1599374.f08: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\setupapi.dll) WinVerifyTrust
1600374.f08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\setupapi.dll
1601374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1602374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1603374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dciman32.dll'...
1604374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'dciman32.dll' -> '\Device\HarddiskVolume3\Windows\System32\dciman32.dll' [rcNtRedir=0xc0150008]
1605374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004ac pwszName=\Device\HarddiskVolume3\Windows\System32\dciman32.dll
1606374.f08: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000002bfe0f0
1607374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000002bfe0f0
1608374.f08: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=779E327CA47BE9830D08A18EEDE8A70C3A978A3B
1609374.f08: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3087039~31bf3856ad364e35~amd64~~6.1.1.4.cat'; file='\Device\HarddiskVolume3\Windows\System32\dciman32.dll'
1610374.f08: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1611374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1612374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'gdi32.dll'.
1613374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
1614374.f08: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\dciman32.dll) WinVerifyTrust
1615374.f08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\dciman32.dll
1616374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1617374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1618374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1619374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1620374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1621374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1622374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1623374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1624374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1625374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1626374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'devobj.dll'...
1627374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'devobj.dll' -> '\Device\HarddiskVolume3\Windows\System32\devobj.dll' [rcNtRedir=0xc0150008]
1628374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004bc pwszName=\Device\HarddiskVolume3\Windows\System32\devobj.dll
1629374.f08: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000002bfe0f0
1630374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000002bfe0f0
1631374.f08: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B410A095222E69F0ECE7D66E4AC27A7125D2EB5A
1632374.f08: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume3\Windows\System32\devobj.dll'
1633374.f08: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1634374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1635374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'cfgmgr32.dll'.
1636374.f08: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\devobj.dll) WinVerifyTrust
1637374.f08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\devobj.dll
1638374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
1639374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume3\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
1640374.f08: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\oleaut32.dll
1641374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1642374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1643374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
1644374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
1645374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1646374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1647374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1648374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1649374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
1650374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume3\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
1651374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004c4 pwszName=\Device\HarddiskVolume3\Windows\System32\cfgmgr32.dll
1652374.f08: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000002bfe0f0
1653374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000002bfe0f0
1654374.f08: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=8F731777EFC4BC982C1E1467FBF29A74CC14D93A
1655374.f08: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume3\Windows\System32\cfgmgr32.dll'
1656374.f08: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1657374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1658374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'rpcrt4.dll'.
1659374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
1660374.f08: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\cfgmgr32.dll) WinVerifyTrust
1661374.f08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\cfgmgr32.dll
1662374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1663374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1664374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1665374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1666374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1667374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1668374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1669374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1670374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1671374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1672374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
1673374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
1674374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
1675374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
1676374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
1677374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
1678374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1679374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1680374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
1681374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume3\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
1682374.f08: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\cfgmgr32.dll
1683374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1684374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1685374.f08: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VirtualBox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000824220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
1686374.f08: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.dll
1687374.f08: supR3HardenedDllNotificationCallback: load 000007feebd10000 LB 0x008de000 C:\Program Files\Oracle\VirtualBox\VirtualBox.dll [fFlags=0x0]
1688374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.dll
1689374.f08: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\opengl32.dll
1690374.f08: supR3HardenedDllNotificationCallback: load 000007fef1a30000 LB 0x0011d000 C:\Windows\system32\OPENGL32.dll [fFlags=0x0]
1691374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\opengl32.dll
1692374.f08: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\glu32.dll
1693374.f08: supR3HardenedDllNotificationCallback: load 000007fef1a00000 LB 0x0002d000 C:\Windows\system32\GLU32.dll [fFlags=0x0]
1694374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\glu32.dll
1695374.f08: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ddraw.dll
1696374.f08: supR3HardenedDllNotificationCallback: load 000007fef1900000 LB 0x000f1000 C:\Windows\system32\DDRAW.dll [fFlags=0x0]
1697374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ddraw.dll
1698374.f08: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dciman32.dll
1699374.f08: supR3HardenedDllNotificationCallback: load 000007fef18f0000 LB 0x00008000 C:\Windows\system32\DCIMAN32.dll [fFlags=0x0]
1700374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dciman32.dll
1701374.f08: supR3HardenedDllNotificationCallback: load 000007feff470000 LB 0x001d7000 C:\Windows\system32\SETUPAPI.dll [fFlags=0x0]
1702374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\setupapi.dll
1703374.f08: supR3HardenedDllNotificationCallback: load 000007fefd230000 LB 0x00036000 C:\Windows\system32\CFGMGR32.dll [fFlags=0x0]
1704374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\cfgmgr32.dll
1705374.f08: supR3HardenedDllNotificationCallback: load 000007fefe180000 LB 0x000d7000 C:\Windows\system32\OLEAUT32.dll [fFlags=0x0]
1706374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\oleaut32.dll
1707374.f08: supR3HardenedDllNotificationCallback: load 000007fefdf70000 LB 0x00203000 C:\Windows\system32\ole32.dll [fFlags=0x0]
1708374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ole32.dll
1709374.f08: supR3HardenedDllNotificationCallback: load 000007fefd4f0000 LB 0x0001a000 C:\Windows\system32\DEVOBJ.dll [fFlags=0x0]
1710374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\devobj.dll
1711374.f08: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dwmapi.dll
1712374.f08: supR3HardenedDllNotificationCallback: load 000007fefa9a0000 LB 0x00018000 C:\Windows\system32\dwmapi.dll [fFlags=0x0]
1713374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dwmapi.dll
1714374.f08: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
1715374.f08: supR3HardenedDllNotificationCallback: load 000000006cf60000 LB 0x00553000 C:\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [fFlags=0x0]
1716374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
1717374.f08: supR3HardenedDllNotificationCallback: load 000007fefe260000 LB 0x00d89000 C:\Windows\system32\SHELL32.dll [fFlags=0x0]
1718374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shell32.dll
1719374.f08: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\mpr.dll
1720374.f08: supR3HardenedDllNotificationCallback: load 000007fef8d70000 LB 0x00018000 C:\Windows\system32\MPR.dll [fFlags=0x0]
1721374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\mpr.dll
1722374.f08: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
1723374.f08: supR3HardenedDllNotificationCallback: load 000007feeb760000 LB 0x005a1000 C:\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll [fFlags=0x0]
1724374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
1725374.f08: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll
1726374.f08: supR3HardenedDllNotificationCallback: load 000000006ca10000 LB 0x0054f000 C:\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll [fFlags=0x0]
1727374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll
1728374.f08: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5PrintSupportVBox.dll
1729374.f08: supR3HardenedDllNotificationCallback: load 000007feed3a0000 LB 0x00051000 C:\Program Files\Oracle\VirtualBox\Qt5PrintSupportVBox.dll [fFlags=0x0]
1730374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5PrintSupportVBox.dll
1731374.f08: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winspool.drv
1732374.f08: supR3HardenedDllNotificationCallback: load 000007fef9080000 LB 0x00071000 C:\Windows\system32\WINSPOOL.DRV [fFlags=0x0]
1733374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winspool.drv
1734374.f08: supR3HardenedDllNotificationCallback: load 000007fefeff0000 LB 0x00097000 C:\Windows\system32\COMDLG32.dll [fFlags=0x0]
1735374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\comdlg32.dll
1736374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'advapi32.dll'.
1737374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
1738374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
1739374.f08: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll)
1740374.f08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll
1741374.f08: supR3HardenedDllNotificationCallback: load 000007feed300000 LB 0x000a0000 C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\COMCTL32.dll [fFlags=0x0]
1742374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll [avoiding WinVerifyTrust]
1743374.f08: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll
1744374.f08: supR3HardenedDllNotificationCallback: load 00000000734b0000 LB 0x00054000 C:\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll [fFlags=0x0]
1745374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll
1746374.f08: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winmm.dll
1747374.f08: supR3HardenedDllNotificationCallback: load 000007fef4300000 LB 0x0003b000 C:\Windows\system32\WINMM.dll [fFlags=0x0]
1748374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winmm.dll
1749374.f08: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume3\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll'.
1750374.f08: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll' [rescheduled]
1751374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\imm32.dll
1752374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1753374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1754374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1755374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1756374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
1757374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
1758374.f08: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\imm32.dll (Input=imm32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000008242b0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
1759374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd830000 'C:\Windows\system32\imm32.dll'
1760374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd930000 'C:\Windows\system32\ADVAPI32.DLL'
1761374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\cryptbase.dll
1762374.f08: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptbase.dll (Input=cryptbase.dll, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
1763374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd0b0000 'C:\Windows\system32\cryptbase.dll'
1764374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feebd10000 'C:\Program Files\Oracle\VirtualBox\VirtualBox.dll'
1765374.f08: SUPR3HardenedMain: Calling TrustedMain (000007feebd115f0)...
1766374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ole32.dll
1767374.f08: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ole32.dll (Input=ole32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000824220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
1768374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdf70000 'C:\Windows\system32\ole32.dll'
1769374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd930000 'C:\Windows\system32\ADVAPI32.dll'
1770374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shell32.dll
1771374.f08: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000824220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
1772374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe260000 'C:\Windows\system32\shell32.dll'
1773374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ole32.dll'.
1774374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'imm32.dll'.
1775374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'winmm.dll'.
1776374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'oleaut32.dll'.
1777374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'shell32.dll'.
1778374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'advapi32.dll'.
1779374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'gdi32.dll'.
1780374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'user32.dll'.
1781374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'qt5guivbox.dll'.
1782374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'qt5corevbox.dll'.
1783374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'msvcr100.dll'.
1784374.f08: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\platforms\qwindows.dll) WinVerifyTrust
1785374.f08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\platforms\qwindows.dll
1786374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
1787374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
1788374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
1789374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
1790374.f08: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
1791374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
1792374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
1793374.f08: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
1794374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1795374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1796374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1797374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1798374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
1799374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
1800374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
1801374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume3\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
1802374.f08: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shell32.dll
1803374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
1804374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume3\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
1805374.f08: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\oleaut32.dll
1806374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
1807374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume3\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
1808374.f08: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winmm.dll
1809374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
1810374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume3\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
1811374.f08: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\imm32.dll
1812374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
1813374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
1814374.f08: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ole32.dll
1815374.f08: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\platforms\qwindows.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000824220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
1816374.f08: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\platforms\qwindows.dll
1817374.f08: supR3HardenedDllNotificationCallback: load 000007feed1d0000 LB 0x00127000 C:\Program Files\Oracle\VirtualBox\platforms\qwindows.dll [fFlags=0x0]
1818374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\platforms\qwindows.dll
1819374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed1d0000 'C:\Program Files\Oracle\VirtualBox\platforms\qwindows.dll'
1820374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000570 pwszName=\Device\HarddiskVolume3\Windows\System32\uxtheme.dll
1821374.f08: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000002bfe0f0
1822374.f08: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000002bfe0f0
1823374.f08: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=936D45CC7026757A151F62882B557DD75D5FCB21
1824374.f08: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume3\Windows\System32\uxtheme.dll'
1825374.f08: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1826374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1827374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
1828374.f08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'gdi32.dll'.
1829374.f08: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\uxtheme.dll) WinVerifyTrust
1830374.f08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\uxtheme.dll
1831374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1832374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1833374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1834374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1835374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1836374.f08: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1837374.f08: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000002b7b150:C:\Windows\system32;C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
1838374.f08: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\uxtheme.dll
1839374.f08: supR3HardenedDllNotificationCallback: load 000007fefad80000 LB 0x00056000 C:\Windows\system32\uxtheme.dll [fFlags=0x0]
1840374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\uxtheme.dll
1841374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefad80000 'C:\Windows\system32\uxtheme.dll'
1842374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\uxtheme.dll
1843374.f08: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000002b7b150:C:\Windows\system32;C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
1844374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefad80000 'C:\Windows\system32\uxtheme.dll'
1845374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\uxtheme.dll
1846374.f08: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000002b7be60:C:\Windows\system32;C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
1847374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefad80000 'C:\Windows\system32\uxtheme.dll'
1848374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\uxtheme.dll
1849374.f08: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000002b7be60:C:\Windows\system32;C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
1850374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefad80000 'C:\Windows\system32\uxtheme.dll'
1851374.f08: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\cryptbase.dll
1852374.f08: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTBASE.dll (Input=CRYPTBASE.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000824220:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
1853374.f08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd0b0000 'C:\Windows\system32\CRYPTBASE.dll'
18546d4.4ac: supR3HardNtChildWaitFor[2]: Quitting: ExitCode=0x1 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 774 ms, the end);
1855660.72c: supR3HardNtChildWaitFor[1]: Quitting: ExitCode=0x1 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 1085 ms, the end);
1856

© 2024 Oracle Support Privacy / Do Not Sell My Info Terms of Use Trademark Policy Automated Access Etiquette