VirtualBox

Ticket #17007: VBoxHardening.log

File VBoxHardening.log, 358.9 KB (added by SAMLU1, 7 years ago)

Vbox HLog

Line 
1fe0.cac: Log file opened: 5.1.22r115126 g_hStartupLog=0000000000000014 g_uNtVerCombined=0x611db110
2fe0.cac: \SystemRoot\System32\ntdll.dll:
3fe0.cac: CreationTime: 2017-08-08T23:30:52.086684000Z
4fe0.cac: LastWriteTime: 2017-07-07T15:31:14.558275200Z
5fe0.cac: ChangeTime: 2017-08-09T23:19:40.530998500Z
6fe0.cac: FileAttributes: 0x20
7fe0.cac: Size: 0x1a7100
8fe0.cac: NT Headers: 0xe0
9fe0.cac: Timestamp: 0x595fa942
10fe0.cac: Machine: 0x8664 - amd64
11fe0.cac: Timestamp: 0x595fa942
12fe0.cac: Image Version: 6.1
13fe0.cac: SizeOfImage: 0x1aa000 (1744896)
14fe0.cac: Resource Dir: 0x14e000 LB 0x5a028
15fe0.cac: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
16fe0.cac: [Raw version resource data: 0x14e0f0 LB 0x380, codepage 0x0 (reserved 0x0)]
17fe0.cac: ProductName: Microsoft® Windows® Operating System
18fe0.cac: ProductVersion: 6.1.7601.23864
19fe0.cac: FileVersion: 6.1.7601.23864 (win7sp1_ldr.170707-0600)
20fe0.cac: FileDescription: NT Layer DLL
21fe0.cac: \SystemRoot\System32\kernel32.dll:
22fe0.cac: CreationTime: 2017-08-08T23:30:50.869881900Z
23fe0.cac: LastWriteTime: 2017-07-07T15:29:33.479000000Z
24fe0.cac: ChangeTime: 2017-08-09T23:19:40.780598900Z
25fe0.cac: FileAttributes: 0x20
26fe0.cac: Size: 0x11c000
27fe0.cac: NT Headers: 0xe0
28fe0.cac: Timestamp: 0x595fa987
29fe0.cac: Machine: 0x8664 - amd64
30fe0.cac: Timestamp: 0x595fa987
31fe0.cac: Image Version: 6.1
32fe0.cac: SizeOfImage: 0x11f000 (1175552)
33fe0.cac: Resource Dir: 0x116000 LB 0x528
34fe0.cac: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
35fe0.cac: [Raw version resource data: 0x1160b0 LB 0x3a4, codepage 0x0 (reserved 0x0)]
36fe0.cac: ProductName: Microsoft® Windows® Operating System
37fe0.cac: ProductVersion: 6.1.7601.23864
38fe0.cac: FileVersion: 6.1.7601.23864 (win7sp1_ldr.170707-0600)
39fe0.cac: FileDescription: Windows NT BASE API Client DLL
40fe0.cac: \SystemRoot\System32\KernelBase.dll:
41fe0.cac: CreationTime: 2017-08-08T23:30:50.760681700Z
42fe0.cac: LastWriteTime: 2017-07-07T15:29:33.479000000Z
43fe0.cac: ChangeTime: 2017-08-09T23:19:40.780598900Z
44fe0.cac: FileAttributes: 0x20
45fe0.cac: Size: 0x66800
46fe0.cac: NT Headers: 0xe8
47fe0.cac: Timestamp: 0x595fa988
48fe0.cac: Machine: 0x8664 - amd64
49fe0.cac: Timestamp: 0x595fa988
50fe0.cac: Image Version: 6.1
51fe0.cac: SizeOfImage: 0x6a000 (434176)
52fe0.cac: Resource Dir: 0x68000 LB 0x530
53fe0.cac: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
54fe0.cac: [Raw version resource data: 0x680b0 LB 0x3ac, codepage 0x0 (reserved 0x0)]
55fe0.cac: ProductName: Microsoft® Windows® Operating System
56fe0.cac: ProductVersion: 6.1.7601.23864
57fe0.cac: FileVersion: 6.1.7601.23864 (win7sp1_ldr.170707-0600)
58fe0.cac: FileDescription: Windows NT BASE API Client DLL
59fe0.cac: \SystemRoot\System32\apisetschema.dll:
60fe0.cac: CreationTime: 2017-08-08T23:30:50.386281000Z
61fe0.cac: LastWriteTime: 2017-07-07T15:29:28.923000000Z
62fe0.cac: ChangeTime: 2017-08-09T23:19:40.515398500Z
63fe0.cac: FileAttributes: 0x20
64fe0.cac: Size: 0x1a00
65fe0.cac: NT Headers: 0xc0
66fe0.cac: Timestamp: 0x595fa921
67fe0.cac: Machine: 0x8664 - amd64
68fe0.cac: Timestamp: 0x595fa921
69fe0.cac: Image Version: 6.1
70fe0.cac: SizeOfImage: 0x50000 (327680)
71fe0.cac: Resource Dir: 0x30000 LB 0x3f8
72fe0.cac: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
73fe0.cac: [Raw version resource data: 0x30060 LB 0x398, codepage 0x0 (reserved 0x0)]
74fe0.cac: ProductName: Microsoft® Windows® Operating System
75fe0.cac: ProductVersion: 6.1.7601.23864
76fe0.cac: FileVersion: 6.1.7601.23864 (win7sp1_ldr.170707-0600)
77fe0.cac: FileDescription: ApiSet Schema DLL
78fe0.cac: NtOpenDirectoryObject failed on \Driver: 0xc0000022
79fe0.cac: supR3HardenedWinFindAdversaries: 0x4
80fe0.cac: \SystemRoot\System32\drivers\aswHwid.sys:
81fe0.cac: CreationTime: 2017-06-29T23:00:17.426945600Z
82fe0.cac: LastWriteTime: 2017-06-29T23:00:14.915341100Z
83fe0.cac: ChangeTime: 2017-07-25T16:12:53.136855600Z
84fe0.cac: FileAttributes: 0x20
85fe0.cac: Size: 0xb788
86fe0.cac: NT Headers: 0xe8
87fe0.cac: Timestamp: 0x5948521a
88fe0.cac: Machine: 0x8664 - amd64
89fe0.cac: Timestamp: 0x5948521a
90fe0.cac: Image Version: 6.0
91fe0.cac: SizeOfImage: 0xa000 (40960)
92fe0.cac: Resource Dir: 0x8000 LB 0x388
93fe0.cac: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
94fe0.cac: [Raw version resource data: 0x8060 LB 0x324, codepage 0x0 (reserved 0x0)]
95fe0.cac: ProductName: Avast Antivirus
96fe0.cac: ProductVersion: 17.5.3540.0
97fe0.cac: FileVersion: 17.5.3540.0
98fe0.cac: FileDescription: Avast HWID
99fe0.cac: \SystemRoot\System32\drivers\aswMonFlt.sys:
100fe0.cac: CreationTime: 2017-06-29T23:00:17.442545600Z
101fe0.cac: LastWriteTime: 2017-08-09T23:07:02.319304500Z
102fe0.cac: ChangeTime: 2017-08-09T23:07:02.319304500Z
103fe0.cac: FileAttributes: 0x20
104fe0.cac: Size: 0x23d10
105fe0.cac: NT Headers: 0xe0
106fe0.cac: Timestamp: 0x59835a6c
107fe0.cac: Machine: 0x8664 - amd64
108fe0.cac: Timestamp: 0x59835a6c
109fe0.cac: Image Version: 6.0
110fe0.cac: SizeOfImage: 0x27000 (159744)
111fe0.cac: Resource Dir: 0x25000 LB 0x3b8
112fe0.cac: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
113fe0.cac: [Raw version resource data: 0x25060 LB 0x354, codepage 0x0 (reserved 0x0)]
114fe0.cac: ProductName: Avast Antivirus
115fe0.cac: ProductVersion: 17.5.3585.203
116fe0.cac: FileVersion: 17.5.3585.203
117fe0.cac: FileDescription: Avast File System Minifilter for Windows 2003/Vista
118fe0.cac: \SystemRoot\System32\drivers\aswRdr2.sys:
119fe0.cac: CreationTime: 2017-06-29T23:00:17.411345500Z
120fe0.cac: LastWriteTime: 2017-06-29T23:00:14.852941000Z
121fe0.cac: ChangeTime: 2017-07-25T16:12:53.136855600Z
122fe0.cac: FileAttributes: 0x20
123fe0.cac: Size: 0x1af10
124fe0.cac: NT Headers: 0xf0
125fe0.cac: Timestamp: 0x59485232
126fe0.cac: Machine: 0x8664 - amd64
127fe0.cac: Timestamp: 0x59485232
128fe0.cac: Image Version: 6.1
129fe0.cac: SizeOfImage: 0x1a000 (106496)
130fe0.cac: Resource Dir: 0x18000 LB 0x398
131fe0.cac: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
132fe0.cac: [Raw version resource data: 0x18060 LB 0x334, codepage 0x0 (reserved 0x0)]
133fe0.cac: ProductName: Avast Antivirus
134fe0.cac: ProductVersion: 17.5.3540.0
135fe0.cac: FileVersion: 17.5.3540.0 built by: WinDDK
136fe0.cac: FileDescription: Avast WFP Redirect Driver
137fe0.cac: \SystemRoot\System32\drivers\aswRvrt.sys:
138fe0.cac: CreationTime: 2017-06-29T23:00:17.458145600Z
139fe0.cac: LastWriteTime: 2017-06-29T23:00:14.930941200Z
140fe0.cac: ChangeTime: 2017-07-25T16:12:53.136855600Z
141fe0.cac: FileAttributes: 0x20
142fe0.cac: Size: 0x149a8
143fe0.cac: NT Headers: 0xf0
144fe0.cac: Timestamp: 0x5948521c
145fe0.cac: Machine: 0x8664 - amd64
146fe0.cac: Timestamp: 0x5948521c
147fe0.cac: Image Version: 6.0
148fe0.cac: SizeOfImage: 0x13000 (77824)
149fe0.cac: Resource Dir: 0x11000 LB 0x388
150fe0.cac: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
151fe0.cac: [Raw version resource data: 0x11060 LB 0x328, codepage 0x0 (reserved 0x0)]
152fe0.cac: ProductName: Avast Antivirus
153fe0.cac: ProductVersion: 17.5.3540.0
154fe0.cac: FileVersion: 17.5.3540.0
155fe0.cac: FileDescription: Avast Revert
156fe0.cac: \SystemRoot\System32\drivers\aswSnx.sys:
157fe0.cac: CreationTime: 2017-06-29T23:00:17.395745500Z
158fe0.cac: LastWriteTime: 2017-08-09T23:07:02.361309900Z
159fe0.cac: ChangeTime: 2017-08-09T23:07:02.361309900Z
160fe0.cac: FileAttributes: 0x20
161fe0.cac: Size: 0xf8048
162fe0.cac: NT Headers: 0xe8
163fe0.cac: Timestamp: 0x598357b2
164fe0.cac: Machine: 0x8664 - amd64
165fe0.cac: Timestamp: 0x598357b2
166fe0.cac: Image Version: 6.0
167fe0.cac: SizeOfImage: 0xf6000 (1007616)
168fe0.cac: Resource Dir: 0xee000 LB 0x380
169fe0.cac: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
170fe0.cac: [Raw version resource data: 0xee060 LB 0x31c, codepage 0x0 (reserved 0x0)]
171fe0.cac: ProductName: Avast Antivirus
172fe0.cac: ProductVersion: 17.5.3585.203
173fe0.cac: FileVersion: 17.5.3585.203
174fe0.cac: FileDescription: Avast Virtualization Driver
175fe0.cac: \SystemRoot\System32\drivers\aswsp.sys:
176fe0.cac: CreationTime: 2017-06-29T23:00:17.473745600Z
177fe0.cac: LastWriteTime: 2017-06-29T23:00:14.946541200Z
178fe0.cac: ChangeTime: 2017-07-25T16:12:53.136855600Z
179fe0.cac: FileAttributes: 0x20
180fe0.cac: Size: 0x8ef88
181fe0.cac: NT Headers: 0xe0
182fe0.cac: Timestamp: 0x594c4886
183fe0.cac: Machine: 0x8664 - amd64
184fe0.cac: Timestamp: 0x594c4886
185fe0.cac: Image Version: 6.0
186fe0.cac: SizeOfImage: 0xb1000 (724992)
187fe0.cac: Resource Dir: 0xaf000 LB 0x370
188fe0.cac: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
189fe0.cac: [Raw version resource data: 0xaf060 LB 0x310, codepage 0x0 (reserved 0x0)]
190fe0.cac: ProductName: Avast Antivirus
191fe0.cac: ProductVersion: 17.5.3556.0
192fe0.cac: FileVersion: 17.5.3556.0
193fe0.cac: FileDescription: Avast self protection module
194fe0.cac: \SystemRoot\System32\drivers\aswStm.sys:
195fe0.cac: CreationTime: 2017-06-29T23:00:17.520545700Z
196fe0.cac: LastWriteTime: 2017-06-29T23:00:14.977741300Z
197fe0.cac: ChangeTime: 2017-07-25T16:12:53.136855600Z
198fe0.cac: FileAttributes: 0x20
199fe0.cac: Size: 0x30870
200fe0.cac: NT Headers: 0x100
201fe0.cac: Timestamp: 0x59485687
202fe0.cac: Machine: 0x8664 - amd64
203fe0.cac: Timestamp: 0x59485687
204fe0.cac: Image Version: 10.0
205fe0.cac: SizeOfImage: 0x31000 (200704)
206fe0.cac: Resource Dir: 0x2f000 LB 0x350
207fe0.cac: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x405)]
208fe0.cac: [Raw version resource data: 0x2f060 LB 0x2f0, codepage 0x0 (reserved 0x0)]
209fe0.cac: ProductName: Avast Antivirus
210fe0.cac: ProductVersion: 17.5.3540.0
211fe0.cac: FileVersion: 17.5.3540.0
212fe0.cac: FileDescription: Stream Filter
213fe0.cac: \SystemRoot\System32\drivers\aswVmm.sys:
214fe0.cac: CreationTime: 2017-06-29T23:00:17.504945700Z
215fe0.cac: LastWriteTime: 2017-07-01T00:41:58.681791100Z
216fe0.cac: ChangeTime: 2017-07-25T16:12:53.136855600Z
217fe0.cac: FileAttributes: 0x20
218fe0.cac: Size: 0x58378
219fe0.cac: NT Headers: 0xe8
220fe0.cac: Timestamp: 0x59551244
221fe0.cac: Machine: 0x8664 - amd64
222fe0.cac: Timestamp: 0x59551244
223fe0.cac: Image Version: 6.0
224fe0.cac: SizeOfImage: 0x56000 (352256)
225fe0.cac: Resource Dir: 0x53000 LB 0x398
226fe0.cac: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
227fe0.cac: [Raw version resource data: 0x53060 LB 0x338, codepage 0x0 (reserved 0x0)]
228fe0.cac: ProductName: Avast Antivirus
229fe0.cac: ProductVersion: 17.5.3559.170
230fe0.cac: FileVersion: 17.5.3559.170
231fe0.cac: FileDescription: Avast VM Monitor
232fe0.cac: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
233fe0.cac: Calling main()
234fe0.cac: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
235fe0.cac: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
236fe0.cac: SUPR3HardenedMain: Respawn #1
237fe0.cac: System32: \Device\HarddiskVolume2\Windows\System32
238fe0.cac: WinSxS: \Device\HarddiskVolume2\Windows\winsxs
239fe0.cac: KnownDllPath: C:\Windows\system32
240fe0.cac: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
241fe0.cac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe)
242fe0.cac: supR3HardNtEnableThreadCreation:
243fe0.cac: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00000000772aa360 pvNtTerminateThread=00000000772cc260
244fe0.cac: supR3HardenedWinDoReSpawn(1): New child aa4.f90 [kernel32].
245fe0.cac: supR3HardNtChildGatherData: PebBaseAddress=000007fffffdf000 cbPeb=0x380
246fe0.cac: supR3HardNtPuChFindNtdll: uNtDllParentAddr=0000000077280000 uNtDllChildAddr=0000000077280000
247fe0.cac: supR3HardenedWinSetupChildInit: uLdrInitThunk=00000000772aa360
248fe0.cac: supR3HardenedWinSetupChildInit: Start child.
249fe0.cac: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
250fe0.cac: supR3HardNtChildPurify: Startup delay kludge #1/0: 514 ms, 33 sleeps
251fe0.cac: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
252fe0.cac: *0000000000000000-000000000000ffff 0x0001/0x0000 0x0000000
253fe0.cac: *0000000000010000-000000000002ffff 0x0004/0x0004 0x0020000
254fe0.cac: *0000000000030000-0000000000033fff 0x0002/0x0002 0x0040000
255fe0.cac: 0000000000034000-000000000003ffff 0x0001/0x0000 0x0000000
256fe0.cac: *0000000000040000-0000000000040fff 0x0004/0x0004 0x0020000
257fe0.cac: 0000000000041000-000000000019ffff 0x0001/0x0000 0x0000000
258fe0.cac: *00000000001a0000-000000000029bfff 0x0000/0x0004 0x0020000
259fe0.cac: 000000000029c000-000000000029dfff 0x0104/0x0004 0x0020000
260fe0.cac: 000000000029e000-000000000029ffff 0x0004/0x0004 0x0020000
261fe0.cac: 00000000002a0000-000000007727ffff 0x0001/0x0000 0x0000000
262fe0.cac: *0000000077280000-0000000077280fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
263fe0.cac: 0000000077281000-000000007737dfff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
264fe0.cac: 000000007737e000-00000000773acfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
265fe0.cac: 00000000773ad000-00000000773b6fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
266fe0.cac: 00000000773b7000-00000000773b7fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
267fe0.cac: 00000000773b8000-00000000773bafff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
268fe0.cac: 00000000773bb000-0000000077429fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
269fe0.cac: 000000007742a000-000000007efdffff 0x0001/0x0000 0x0000000
270fe0.cac: *000000007efe0000-000000007ffdffff 0x0000/0x0002 0x0020000
271fe0.cac: *000000007ffe0000-000000007ffe0fff 0x0002/0x0002 0x0020000
272fe0.cac: 000000007ffe1000-000000007ffeffff 0x0000/0x0002 0x0020000
273fe0.cac: 000000007fff0000-000000013ffdffff 0x0001/0x0000 0x0000000
274fe0.cac: *000000013ffe0000-000000013ffe0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
275fe0.cac: 000000013ffe1000-0000000140050fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
276fe0.cac: 0000000140051000-0000000140051fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
277fe0.cac: 0000000140052000-0000000140096fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
278fe0.cac: 0000000140097000-0000000140097fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
279fe0.cac: 0000000140098000-0000000140098fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
280fe0.cac: 0000000140099000-000000014009dfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
281fe0.cac: 000000014009e000-000000014009efff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
282fe0.cac: 000000014009f000-000000014009ffff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
283fe0.cac: 00000001400a0000-00000001400a3fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
284fe0.cac: 00000001400a4000-00000001400ebfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
285fe0.cac: 00000001400ec000-000007feff59ffff 0x0001/0x0000 0x0000000
286fe0.cac: *000007feff5a0000-000007feff5a0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\apisetschema.dll
287fe0.cac: 000007feff5a1000-000007fffffaffff 0x0001/0x0000 0x0000000
288fe0.cac: *000007fffffb0000-000007fffffd2fff 0x0002/0x0002 0x0040000
289fe0.cac: 000007fffffd3000-000007fffffdcfff 0x0001/0x0000 0x0000000
290fe0.cac: *000007fffffdd000-000007fffffdefff 0x0004/0x0004 0x0020000
291fe0.cac: *000007fffffdf000-000007fffffdffff 0x0004/0x0004 0x0020000
292fe0.cac: *000007fffffe0000-000007fffffeffff 0x0001/0x0002 0x0020000
293fe0.cac: apisetschema.dll: timestamp 0x595fa921 (rc=VINF_SUCCESS)
294fe0.cac: VirtualBox.exe: timestamp 0x5903619d (rc=VINF_SUCCESS)
295fe0.cac: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
296fe0.cac: '\Device\HarddiskVolume2\Windows\System32\apisetschema.dll' has no imports
297fe0.cac: '\Device\HarddiskVolume2\Windows\System32\ntdll.dll' has no imports
298fe0.cac: supR3HardNtChildPurify: Done after 546 ms and 0 fixes (loop #0).
299aa4.f90: Log file opened: 5.1.22r115126 g_hStartupLog=0000000000000004 g_uNtVerCombined=0x611db100
300aa4.f90: supR3HardenedVmProcessInit: uNtDllAddr=0000000077280000 g_uNtVerCombined=0x611db100
301fe0.cac: supR3HardNtEnableThreadCreation:
302aa4.f90: ntdll.dll: timestamp 0x595fa942 (rc=VINF_SUCCESS)
303aa4.f90: New simple heap: #1 00000000002a0000 LB 0x400000 (for 1744896 allocation)
304aa4.f90: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
305aa4.f90: System32: \Device\HarddiskVolume2\Windows\System32
306aa4.f90: WinSxS: \Device\HarddiskVolume2\Windows\winsxs
307aa4.f90: KnownDllPath: C:\Windows\system32
308aa4.f90: supR3HardenedVmProcessInit: Opening vboxdrv stub...
309aa4.f90: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
310aa4.f90: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
311aa4.f90: Registered Dll notification callback with NTDLL.
312aa4.f90: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\kernel32.dll)
313aa4.f90: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\kernel32.dll
314aa4.f90: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
315aa4.f90: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
316aa4.f90: supR3HardenedDllNotificationCallback: load 0000000077060000 LB 0x0011f000 C:\Windows\system32\kernel32.dll [fFlags=0x0]
317aa4.f90: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
318aa4.f90: supR3HardenedDllNotificationCallback: load 000007fefcff0000 LB 0x0006a000 C:\Windows\system32\KERNELBASE.dll [fFlags=0x0]
319aa4.f90: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\KernelBase.dll)
320aa4.f90: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\KernelBase.dll
321aa4.f90: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077060000 'C:\Windows\system32\kernel32.dll'
322aa4.f90: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00000000772aa360 pvNtTerminateThread=00000000772cc260
323fe0.cac: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 46 ms.
324aa4.f90: \SystemRoot\System32\ntdll.dll:
325aa4.f90: CreationTime: 2017-08-08T23:30:52.086684000Z
326aa4.f90: LastWriteTime: 2017-07-07T15:31:14.558275200Z
327aa4.f90: ChangeTime: 2017-08-09T23:19:40.530998500Z
328aa4.f90: FileAttributes: 0x20
329aa4.f90: Size: 0x1a7100
330aa4.f90: NT Headers: 0xe0
331aa4.f90: Timestamp: 0x595fa942
332aa4.f90: Machine: 0x8664 - amd64
333aa4.f90: Timestamp: 0x595fa942
334aa4.f90: Image Version: 6.1
335aa4.f90: SizeOfImage: 0x1aa000 (1744896)
336aa4.f90: Resource Dir: 0x14e000 LB 0x5a028
337aa4.f90: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
338aa4.f90: [Raw version resource data: 0x14e0f0 LB 0x380, codepage 0x0 (reserved 0x0)]
339aa4.f90: ProductName: Microsoft® Windows® Operating System
340aa4.f90: ProductVersion: 6.1.7601.23864
341aa4.f90: FileVersion: 6.1.7601.23864 (win7sp1_ldr.170707-0600)
342aa4.f90: FileDescription: NT Layer DLL
343aa4.f90: \SystemRoot\System32\kernel32.dll:
344aa4.f90: CreationTime: 2017-08-08T23:30:50.869881900Z
345aa4.f90: LastWriteTime: 2017-07-07T15:29:33.479000000Z
346aa4.f90: ChangeTime: 2017-08-09T23:19:40.780598900Z
347aa4.f90: FileAttributes: 0x20
348aa4.f90: Size: 0x11c000
349aa4.f90: NT Headers: 0xe0
350aa4.f90: Timestamp: 0x595fa987
351aa4.f90: Machine: 0x8664 - amd64
352aa4.f90: Timestamp: 0x595fa987
353aa4.f90: Image Version: 6.1
354aa4.f90: SizeOfImage: 0x11f000 (1175552)
355aa4.f90: Resource Dir: 0x116000 LB 0x528
356aa4.f90: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
357aa4.f90: [Raw version resource data: 0x1160b0 LB 0x3a4, codepage 0x0 (reserved 0x0)]
358aa4.f90: ProductName: Microsoft® Windows® Operating System
359aa4.f90: ProductVersion: 6.1.7601.23864
360aa4.f90: FileVersion: 6.1.7601.23864 (win7sp1_ldr.170707-0600)
361aa4.f90: FileDescription: Windows NT BASE API Client DLL
362aa4.f90: \SystemRoot\System32\KernelBase.dll:
363aa4.f90: CreationTime: 2017-08-08T23:30:50.760681700Z
364aa4.f90: LastWriteTime: 2017-07-07T15:29:33.479000000Z
365aa4.f90: ChangeTime: 2017-08-09T23:19:40.780598900Z
366aa4.f90: FileAttributes: 0x20
367aa4.f90: Size: 0x66800
368aa4.f90: NT Headers: 0xe8
369aa4.f90: Timestamp: 0x595fa988
370aa4.f90: Machine: 0x8664 - amd64
371aa4.f90: Timestamp: 0x595fa988
372aa4.f90: Image Version: 6.1
373aa4.f90: SizeOfImage: 0x6a000 (434176)
374aa4.f90: Resource Dir: 0x68000 LB 0x530
375aa4.f90: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
376aa4.f90: [Raw version resource data: 0x680b0 LB 0x3ac, codepage 0x0 (reserved 0x0)]
377aa4.f90: ProductName: Microsoft® Windows® Operating System
378aa4.f90: ProductVersion: 6.1.7601.23864
379aa4.f90: FileVersion: 6.1.7601.23864 (win7sp1_ldr.170707-0600)
380aa4.f90: FileDescription: Windows NT BASE API Client DLL
381aa4.f90: \SystemRoot\System32\apisetschema.dll:
382aa4.f90: CreationTime: 2017-08-08T23:30:50.386281000Z
383aa4.f90: LastWriteTime: 2017-07-07T15:29:28.923000000Z
384aa4.f90: ChangeTime: 2017-08-09T23:19:40.515398500Z
385aa4.f90: FileAttributes: 0x20
386aa4.f90: Size: 0x1a00
387aa4.f90: NT Headers: 0xc0
388aa4.f90: Timestamp: 0x595fa921
389aa4.f90: Machine: 0x8664 - amd64
390aa4.f90: Timestamp: 0x595fa921
391aa4.f90: Image Version: 6.1
392aa4.f90: SizeOfImage: 0x50000 (327680)
393aa4.f90: Resource Dir: 0x30000 LB 0x3f8
394aa4.f90: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
395aa4.f90: [Raw version resource data: 0x30060 LB 0x398, codepage 0x0 (reserved 0x0)]
396aa4.f90: ProductName: Microsoft® Windows® Operating System
397aa4.f90: ProductVersion: 6.1.7601.23864
398aa4.f90: FileVersion: 6.1.7601.23864 (win7sp1_ldr.170707-0600)
399aa4.f90: FileDescription: ApiSet Schema DLL
400aa4.f90: NtOpenDirectoryObject failed on \Driver: 0xc0000022
401aa4.f90: supR3HardenedWinFindAdversaries: 0x4
402aa4.f90: \SystemRoot\System32\drivers\aswHwid.sys:
403aa4.f90: CreationTime: 2017-06-29T23:00:17.426945600Z
404aa4.f90: LastWriteTime: 2017-06-29T23:00:14.915341100Z
405aa4.f90: ChangeTime: 2017-07-25T16:12:53.136855600Z
406aa4.f90: FileAttributes: 0x20
407aa4.f90: Size: 0xb788
408aa4.f90: NT Headers: 0xe8
409aa4.f90: Timestamp: 0x5948521a
410aa4.f90: Machine: 0x8664 - amd64
411aa4.f90: Timestamp: 0x5948521a
412aa4.f90: Image Version: 6.0
413aa4.f90: SizeOfImage: 0xa000 (40960)
414aa4.f90: Resource Dir: 0x8000 LB 0x388
415aa4.f90: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
416aa4.f90: [Raw version resource data: 0x8060 LB 0x324, codepage 0x0 (reserved 0x0)]
417aa4.f90: ProductName: Avast Antivirus
418aa4.f90: ProductVersion: 17.5.3540.0
419aa4.f90: FileVersion: 17.5.3540.0
420aa4.f90: FileDescription: Avast HWID
421aa4.f90: \SystemRoot\System32\drivers\aswMonFlt.sys:
422aa4.f90: CreationTime: 2017-06-29T23:00:17.442545600Z
423aa4.f90: LastWriteTime: 2017-08-09T23:07:02.319304500Z
424aa4.f90: ChangeTime: 2017-08-09T23:07:02.319304500Z
425aa4.f90: FileAttributes: 0x20
426aa4.f90: Size: 0x23d10
427aa4.f90: NT Headers: 0xe0
428aa4.f90: Timestamp: 0x59835a6c
429aa4.f90: Machine: 0x8664 - amd64
430aa4.f90: Timestamp: 0x59835a6c
431aa4.f90: Image Version: 6.0
432aa4.f90: SizeOfImage: 0x27000 (159744)
433aa4.f90: Resource Dir: 0x25000 LB 0x3b8
434aa4.f90: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
435aa4.f90: [Raw version resource data: 0x25060 LB 0x354, codepage 0x0 (reserved 0x0)]
436aa4.f90: ProductName: Avast Antivirus
437aa4.f90: ProductVersion: 17.5.3585.203
438aa4.f90: FileVersion: 17.5.3585.203
439aa4.f90: FileDescription: Avast File System Minifilter for Windows 2003/Vista
440aa4.f90: \SystemRoot\System32\drivers\aswRdr2.sys:
441aa4.f90: CreationTime: 2017-06-29T23:00:17.411345500Z
442aa4.f90: LastWriteTime: 2017-06-29T23:00:14.852941000Z
443aa4.f90: ChangeTime: 2017-07-25T16:12:53.136855600Z
444aa4.f90: FileAttributes: 0x20
445aa4.f90: Size: 0x1af10
446aa4.f90: NT Headers: 0xf0
447aa4.f90: Timestamp: 0x59485232
448aa4.f90: Machine: 0x8664 - amd64
449aa4.f90: Timestamp: 0x59485232
450aa4.f90: Image Version: 6.1
451aa4.f90: SizeOfImage: 0x1a000 (106496)
452aa4.f90: Resource Dir: 0x18000 LB 0x398
453aa4.f90: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
454aa4.f90: [Raw version resource data: 0x18060 LB 0x334, codepage 0x0 (reserved 0x0)]
455aa4.f90: ProductName: Avast Antivirus
456aa4.f90: ProductVersion: 17.5.3540.0
457aa4.f90: FileVersion: 17.5.3540.0 built by: WinDDK
458aa4.f90: FileDescription: Avast WFP Redirect Driver
459aa4.f90: \SystemRoot\System32\drivers\aswRvrt.sys:
460aa4.f90: CreationTime: 2017-06-29T23:00:17.458145600Z
461aa4.f90: LastWriteTime: 2017-06-29T23:00:14.930941200Z
462aa4.f90: ChangeTime: 2017-07-25T16:12:53.136855600Z
463aa4.f90: FileAttributes: 0x20
464aa4.f90: Size: 0x149a8
465aa4.f90: NT Headers: 0xf0
466aa4.f90: Timestamp: 0x5948521c
467aa4.f90: Machine: 0x8664 - amd64
468aa4.f90: Timestamp: 0x5948521c
469aa4.f90: Image Version: 6.0
470aa4.f90: SizeOfImage: 0x13000 (77824)
471aa4.f90: Resource Dir: 0x11000 LB 0x388
472aa4.f90: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
473aa4.f90: [Raw version resource data: 0x11060 LB 0x328, codepage 0x0 (reserved 0x0)]
474aa4.f90: ProductName: Avast Antivirus
475aa4.f90: ProductVersion: 17.5.3540.0
476aa4.f90: FileVersion: 17.5.3540.0
477aa4.f90: FileDescription: Avast Revert
478aa4.f90: \SystemRoot\System32\drivers\aswSnx.sys:
479aa4.f90: CreationTime: 2017-06-29T23:00:17.395745500Z
480aa4.f90: LastWriteTime: 2017-08-09T23:07:02.361309900Z
481aa4.f90: ChangeTime: 2017-08-09T23:07:02.361309900Z
482aa4.f90: FileAttributes: 0x20
483aa4.f90: Size: 0xf8048
484aa4.f90: NT Headers: 0xe8
485aa4.f90: Timestamp: 0x598357b2
486aa4.f90: Machine: 0x8664 - amd64
487aa4.f90: Timestamp: 0x598357b2
488aa4.f90: Image Version: 6.0
489aa4.f90: SizeOfImage: 0xf6000 (1007616)
490aa4.f90: Resource Dir: 0xee000 LB 0x380
491aa4.f90: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
492aa4.f90: [Raw version resource data: 0xee060 LB 0x31c, codepage 0x0 (reserved 0x0)]
493aa4.f90: ProductName: Avast Antivirus
494aa4.f90: ProductVersion: 17.5.3585.203
495aa4.f90: FileVersion: 17.5.3585.203
496aa4.f90: FileDescription: Avast Virtualization Driver
497aa4.f90: \SystemRoot\System32\drivers\aswsp.sys:
498aa4.f90: CreationTime: 2017-06-29T23:00:17.473745600Z
499aa4.f90: LastWriteTime: 2017-06-29T23:00:14.946541200Z
500aa4.f90: ChangeTime: 2017-07-25T16:12:53.136855600Z
501aa4.f90: FileAttributes: 0x20
502aa4.f90: Size: 0x8ef88
503aa4.f90: NT Headers: 0xe0
504aa4.f90: Timestamp: 0x594c4886
505aa4.f90: Machine: 0x8664 - amd64
506aa4.f90: Timestamp: 0x594c4886
507aa4.f90: Image Version: 6.0
508aa4.f90: SizeOfImage: 0xb1000 (724992)
509aa4.f90: Resource Dir: 0xaf000 LB 0x370
510aa4.f90: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
511aa4.f90: [Raw version resource data: 0xaf060 LB 0x310, codepage 0x0 (reserved 0x0)]
512aa4.f90: ProductName: Avast Antivirus
513aa4.f90: ProductVersion: 17.5.3556.0
514aa4.f90: FileVersion: 17.5.3556.0
515aa4.f90: FileDescription: Avast self protection module
516aa4.f90: \SystemRoot\System32\drivers\aswStm.sys:
517aa4.f90: CreationTime: 2017-06-29T23:00:17.520545700Z
518aa4.f90: LastWriteTime: 2017-06-29T23:00:14.977741300Z
519aa4.f90: ChangeTime: 2017-07-25T16:12:53.136855600Z
520aa4.f90: FileAttributes: 0x20
521aa4.f90: Size: 0x30870
522aa4.f90: NT Headers: 0x100
523aa4.f90: Timestamp: 0x59485687
524aa4.f90: Machine: 0x8664 - amd64
525aa4.f90: Timestamp: 0x59485687
526aa4.f90: Image Version: 10.0
527aa4.f90: SizeOfImage: 0x31000 (200704)
528aa4.f90: Resource Dir: 0x2f000 LB 0x350
529aa4.f90: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x405)]
530aa4.f90: [Raw version resource data: 0x2f060 LB 0x2f0, codepage 0x0 (reserved 0x0)]
531aa4.f90: ProductName: Avast Antivirus
532aa4.f90: ProductVersion: 17.5.3540.0
533aa4.f90: FileVersion: 17.5.3540.0
534aa4.f90: FileDescription: Stream Filter
535aa4.f90: \SystemRoot\System32\drivers\aswVmm.sys:
536aa4.f90: CreationTime: 2017-06-29T23:00:17.504945700Z
537aa4.f90: LastWriteTime: 2017-07-01T00:41:58.681791100Z
538aa4.f90: ChangeTime: 2017-07-25T16:12:53.136855600Z
539aa4.f90: FileAttributes: 0x20
540aa4.f90: Size: 0x58378
541aa4.f90: NT Headers: 0xe8
542aa4.f90: Timestamp: 0x59551244
543aa4.f90: Machine: 0x8664 - amd64
544aa4.f90: Timestamp: 0x59551244
545aa4.f90: Image Version: 6.0
546aa4.f90: SizeOfImage: 0x56000 (352256)
547aa4.f90: Resource Dir: 0x53000 LB 0x398
548aa4.f90: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
549aa4.f90: [Raw version resource data: 0x53060 LB 0x338, codepage 0x0 (reserved 0x0)]
550aa4.f90: ProductName: Avast Antivirus
551aa4.f90: ProductVersion: 17.5.3559.170
552aa4.f90: FileVersion: 17.5.3559.170
553aa4.f90: FileDescription: Avast VM Monitor
554aa4.f90: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
555aa4.f90: Calling main()
556aa4.f90: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
557aa4.f90: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
558aa4.f90: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
559aa4.f90: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe)
560aa4.f90: SUPR3HardenedMain: Respawn #2
561aa4.f90: supR3HardNtEnableThreadCreation:
562aa4.f90: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\apphelp.dll)
563aa4.f90: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\apphelp.dll
564aa4.f90: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\apphelp.dll (rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
565aa4.f90: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\apphelp.dll [lacks WinVerifyTrust]
566aa4.f90: supR3HardenedDllNotificationCallback: load 000007fefcdb0000 LB 0x00057000 C:\Windows\system32\apphelp.dll [fFlags=0x0]
567aa4.f90: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\apphelp.dll [lacks WinVerifyTrust]
568aa4.f90: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcdb0000 'C:\Windows\system32\apphelp.dll'
569aa4.f90: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00000000772aa360 pvNtTerminateThread=00000000772cc260
570aa4.f90: supR3HardenedWinDoReSpawn(2): New child 1694.598 [kernel32].
571aa4.f90: supR3HardNtChildGatherData: PebBaseAddress=000007fffffdf000 cbPeb=0x380
572aa4.f90: supR3HardNtPuChFindNtdll: uNtDllParentAddr=0000000077280000 uNtDllChildAddr=0000000077280000
573aa4.f90: supR3HardenedWinSetupChildInit: uLdrInitThunk=00000000772aa360
574aa4.f90: supR3HardenedWinSetupChildInit: Start child.
575aa4.f90: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
576aa4.f90: supR3HardNtChildPurify: Startup delay kludge #1/0: 515 ms, 33 sleeps
577aa4.f90: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
578aa4.f90: *0000000000000000-000000000000ffff 0x0001/0x0000 0x0000000
579aa4.f90: *0000000000010000-000000000002ffff 0x0004/0x0004 0x0020000
580aa4.f90: *0000000000030000-0000000000033fff 0x0002/0x0002 0x0040000
581aa4.f90: 0000000000034000-000000000003ffff 0x0001/0x0000 0x0000000
582aa4.f90: *0000000000040000-0000000000040fff 0x0004/0x0004 0x0020000
583aa4.f90: 0000000000041000-00000000000affff 0x0001/0x0000 0x0000000
584aa4.f90: *00000000000b0000-00000000001abfff 0x0000/0x0004 0x0020000
585aa4.f90: 00000000001ac000-00000000001adfff 0x0104/0x0004 0x0020000
586aa4.f90: 00000000001ae000-00000000001affff 0x0004/0x0004 0x0020000
587aa4.f90: 00000000001b0000-000000007727ffff 0x0001/0x0000 0x0000000
588aa4.f90: *0000000077280000-0000000077280fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
589aa4.f90: 0000000077281000-000000007737dfff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
590aa4.f90: 000000007737e000-00000000773acfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
591aa4.f90: 00000000773ad000-00000000773b6fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
592aa4.f90: 00000000773b7000-00000000773b7fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
593aa4.f90: 00000000773b8000-00000000773bafff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
594aa4.f90: 00000000773bb000-0000000077429fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
595aa4.f90: 000000007742a000-000000007efdffff 0x0001/0x0000 0x0000000
596aa4.f90: *000000007efe0000-000000007ffdffff 0x0000/0x0002 0x0020000
597aa4.f90: *000000007ffe0000-000000007ffe0fff 0x0002/0x0002 0x0020000
598aa4.f90: 000000007ffe1000-000000007ffeffff 0x0000/0x0002 0x0020000
599aa4.f90: 000000007fff0000-000000013ffdffff 0x0001/0x0000 0x0000000
600aa4.f90: *000000013ffe0000-000000013ffe0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
601aa4.f90: 000000013ffe1000-0000000140050fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
602aa4.f90: 0000000140051000-0000000140051fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
603aa4.f90: 0000000140052000-0000000140096fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
604aa4.f90: 0000000140097000-0000000140097fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
605aa4.f90: 0000000140098000-0000000140098fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
606aa4.f90: 0000000140099000-000000014009dfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
607aa4.f90: 000000014009e000-000000014009efff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
608aa4.f90: 000000014009f000-000000014009ffff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
609aa4.f90: 00000001400a0000-00000001400a3fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
610aa4.f90: 00000001400a4000-00000001400ebfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
611aa4.f90: 00000001400ec000-000007feff59ffff 0x0001/0x0000 0x0000000
612aa4.f90: *000007feff5a0000-000007feff5a0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\apisetschema.dll
613aa4.f90: 000007feff5a1000-000007fffffaffff 0x0001/0x0000 0x0000000
614aa4.f90: *000007fffffb0000-000007fffffd2fff 0x0002/0x0002 0x0040000
615aa4.f90: 000007fffffd3000-000007fffffdcfff 0x0001/0x0000 0x0000000
616aa4.f90: *000007fffffdd000-000007fffffdefff 0x0004/0x0004 0x0020000
617aa4.f90: *000007fffffdf000-000007fffffdffff 0x0004/0x0004 0x0020000
618aa4.f90: *000007fffffe0000-000007fffffeffff 0x0001/0x0002 0x0020000
619aa4.f90: apisetschema.dll: timestamp 0x595fa921 (rc=VINF_SUCCESS)
620aa4.f90: VirtualBox.exe: timestamp 0x5903619d (rc=VINF_SUCCESS)
621aa4.f90: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
622aa4.f90: '\Device\HarddiskVolume2\Windows\System32\apisetschema.dll' has no imports
623aa4.f90: '\Device\HarddiskVolume2\Windows\System32\ntdll.dll' has no imports
624aa4.f90: supR3HardNtChildPurify: Done after 546 ms and 0 fixes (loop #0).
6251694.598: Log file opened: 5.1.22r115126 g_hStartupLog=0000000000000004 g_uNtVerCombined=0x611db100
6261694.598: supR3HardenedVmProcessInit: uNtDllAddr=0000000077280000 g_uNtVerCombined=0x611db100
627aa4.f90: supR3HardenedEarlyCompact: Removed heap 1 (0x000000002a0000 LB 0x400000)
628aa4.f90: supR3HardNtEnableThreadCreation:
6291694.598: ntdll.dll: timestamp 0x595fa942 (rc=VINF_SUCCESS)
6301694.598: New simple heap: #1 00000000002b0000 LB 0x400000 (for 1744896 allocation)
6311694.598: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
6321694.598: System32: \Device\HarddiskVolume2\Windows\System32
6331694.598: WinSxS: \Device\HarddiskVolume2\Windows\winsxs
6341694.598: KnownDllPath: C:\Windows\system32
6351694.598: supR3HardenedVmProcessInit: Opening vboxdrv...
6361694.598: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
6371694.598: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
6381694.598: Registered Dll notification callback with NTDLL.
6391694.598: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\kernel32.dll)
6401694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\kernel32.dll
6411694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
6421694.598: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
6431694.598: supR3HardenedDllNotificationCallback: load 0000000077060000 LB 0x0011f000 C:\Windows\system32\kernel32.dll [fFlags=0x0]
6441694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
6451694.598: supR3HardenedDllNotificationCallback: load 000007fefcff0000 LB 0x0006a000 C:\Windows\system32\KERNELBASE.dll [fFlags=0x0]
6461694.598: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\KernelBase.dll)
6471694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\KernelBase.dll
6481694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077060000 'C:\Windows\system32\kernel32.dll'
6491694.598: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00000000772aa360 pvNtTerminateThread=00000000772cc260
650aa4.f90: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 47 ms.
6511694.598: \SystemRoot\System32\ntdll.dll:
6521694.598: CreationTime: 2017-08-08T23:30:52.086684000Z
6531694.598: LastWriteTime: 2017-07-07T15:31:14.558275200Z
6541694.598: ChangeTime: 2017-08-09T23:19:40.530998500Z
6551694.598: FileAttributes: 0x20
6561694.598: Size: 0x1a7100
6571694.598: NT Headers: 0xe0
6581694.598: Timestamp: 0x595fa942
6591694.598: Machine: 0x8664 - amd64
6601694.598: Timestamp: 0x595fa942
6611694.598: Image Version: 6.1
6621694.598: SizeOfImage: 0x1aa000 (1744896)
6631694.598: Resource Dir: 0x14e000 LB 0x5a028
6641694.598: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
6651694.598: [Raw version resource data: 0x14e0f0 LB 0x380, codepage 0x0 (reserved 0x0)]
6661694.598: ProductName: Microsoft® Windows® Operating System
6671694.598: ProductVersion: 6.1.7601.23864
6681694.598: FileVersion: 6.1.7601.23864 (win7sp1_ldr.170707-0600)
6691694.598: FileDescription: NT Layer DLL
6701694.598: \SystemRoot\System32\kernel32.dll:
6711694.598: CreationTime: 2017-08-08T23:30:50.869881900Z
6721694.598: LastWriteTime: 2017-07-07T15:29:33.479000000Z
6731694.598: ChangeTime: 2017-08-09T23:19:40.780598900Z
6741694.598: FileAttributes: 0x20
6751694.598: Size: 0x11c000
6761694.598: NT Headers: 0xe0
6771694.598: Timestamp: 0x595fa987
6781694.598: Machine: 0x8664 - amd64
6791694.598: Timestamp: 0x595fa987
6801694.598: Image Version: 6.1
6811694.598: SizeOfImage: 0x11f000 (1175552)
6821694.598: Resource Dir: 0x116000 LB 0x528
6831694.598: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
6841694.598: [Raw version resource data: 0x1160b0 LB 0x3a4, codepage 0x0 (reserved 0x0)]
6851694.598: ProductName: Microsoft® Windows® Operating System
6861694.598: ProductVersion: 6.1.7601.23864
6871694.598: FileVersion: 6.1.7601.23864 (win7sp1_ldr.170707-0600)
6881694.598: FileDescription: Windows NT BASE API Client DLL
6891694.598: \SystemRoot\System32\KernelBase.dll:
6901694.598: CreationTime: 2017-08-08T23:30:50.760681700Z
6911694.598: LastWriteTime: 2017-07-07T15:29:33.479000000Z
6921694.598: ChangeTime: 2017-08-09T23:19:40.780598900Z
6931694.598: FileAttributes: 0x20
6941694.598: Size: 0x66800
6951694.598: NT Headers: 0xe8
6961694.598: Timestamp: 0x595fa988
6971694.598: Machine: 0x8664 - amd64
6981694.598: Timestamp: 0x595fa988
6991694.598: Image Version: 6.1
7001694.598: SizeOfImage: 0x6a000 (434176)
7011694.598: Resource Dir: 0x68000 LB 0x530
7021694.598: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
7031694.598: [Raw version resource data: 0x680b0 LB 0x3ac, codepage 0x0 (reserved 0x0)]
7041694.598: ProductName: Microsoft® Windows® Operating System
7051694.598: ProductVersion: 6.1.7601.23864
7061694.598: FileVersion: 6.1.7601.23864 (win7sp1_ldr.170707-0600)
7071694.598: FileDescription: Windows NT BASE API Client DLL
7081694.598: \SystemRoot\System32\apisetschema.dll:
7091694.598: CreationTime: 2017-08-08T23:30:50.386281000Z
7101694.598: LastWriteTime: 2017-07-07T15:29:28.923000000Z
7111694.598: ChangeTime: 2017-08-09T23:19:40.515398500Z
7121694.598: FileAttributes: 0x20
7131694.598: Size: 0x1a00
7141694.598: NT Headers: 0xc0
7151694.598: Timestamp: 0x595fa921
7161694.598: Machine: 0x8664 - amd64
7171694.598: Timestamp: 0x595fa921
7181694.598: Image Version: 6.1
7191694.598: SizeOfImage: 0x50000 (327680)
7201694.598: Resource Dir: 0x30000 LB 0x3f8
7211694.598: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
7221694.598: [Raw version resource data: 0x30060 LB 0x398, codepage 0x0 (reserved 0x0)]
7231694.598: ProductName: Microsoft® Windows® Operating System
7241694.598: ProductVersion: 6.1.7601.23864
7251694.598: FileVersion: 6.1.7601.23864 (win7sp1_ldr.170707-0600)
7261694.598: FileDescription: ApiSet Schema DLL
7271694.598: NtOpenDirectoryObject failed on \Driver: 0xc0000022
7281694.598: supR3HardenedWinFindAdversaries: 0x4
7291694.598: \SystemRoot\System32\drivers\aswHwid.sys:
7301694.598: CreationTime: 2017-06-29T23:00:17.426945600Z
7311694.598: LastWriteTime: 2017-06-29T23:00:14.915341100Z
7321694.598: ChangeTime: 2017-07-25T16:12:53.136855600Z
7331694.598: FileAttributes: 0x20
7341694.598: Size: 0xb788
7351694.598: NT Headers: 0xe8
7361694.598: Timestamp: 0x5948521a
7371694.598: Machine: 0x8664 - amd64
7381694.598: Timestamp: 0x5948521a
7391694.598: Image Version: 6.0
7401694.598: SizeOfImage: 0xa000 (40960)
7411694.598: Resource Dir: 0x8000 LB 0x388
7421694.598: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
7431694.598: [Raw version resource data: 0x8060 LB 0x324, codepage 0x0 (reserved 0x0)]
7441694.598: ProductName: Avast Antivirus
7451694.598: ProductVersion: 17.5.3540.0
7461694.598: FileVersion: 17.5.3540.0
7471694.598: FileDescription: Avast HWID
7481694.598: \SystemRoot\System32\drivers\aswMonFlt.sys:
7491694.598: CreationTime: 2017-06-29T23:00:17.442545600Z
7501694.598: LastWriteTime: 2017-08-09T23:07:02.319304500Z
7511694.598: ChangeTime: 2017-08-09T23:07:02.319304500Z
7521694.598: FileAttributes: 0x20
7531694.598: Size: 0x23d10
7541694.598: NT Headers: 0xe0
7551694.598: Timestamp: 0x59835a6c
7561694.598: Machine: 0x8664 - amd64
7571694.598: Timestamp: 0x59835a6c
7581694.598: Image Version: 6.0
7591694.598: SizeOfImage: 0x27000 (159744)
7601694.598: Resource Dir: 0x25000 LB 0x3b8
7611694.598: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
7621694.598: [Raw version resource data: 0x25060 LB 0x354, codepage 0x0 (reserved 0x0)]
7631694.598: ProductName: Avast Antivirus
7641694.598: ProductVersion: 17.5.3585.203
7651694.598: FileVersion: 17.5.3585.203
7661694.598: FileDescription: Avast File System Minifilter for Windows 2003/Vista
7671694.598: \SystemRoot\System32\drivers\aswRdr2.sys:
7681694.598: CreationTime: 2017-06-29T23:00:17.411345500Z
7691694.598: LastWriteTime: 2017-06-29T23:00:14.852941000Z
7701694.598: ChangeTime: 2017-07-25T16:12:53.136855600Z
7711694.598: FileAttributes: 0x20
7721694.598: Size: 0x1af10
7731694.598: NT Headers: 0xf0
7741694.598: Timestamp: 0x59485232
7751694.598: Machine: 0x8664 - amd64
7761694.598: Timestamp: 0x59485232
7771694.598: Image Version: 6.1
7781694.598: SizeOfImage: 0x1a000 (106496)
7791694.598: Resource Dir: 0x18000 LB 0x398
7801694.598: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
7811694.598: [Raw version resource data: 0x18060 LB 0x334, codepage 0x0 (reserved 0x0)]
7821694.598: ProductName: Avast Antivirus
7831694.598: ProductVersion: 17.5.3540.0
7841694.598: FileVersion: 17.5.3540.0 built by: WinDDK
7851694.598: FileDescription: Avast WFP Redirect Driver
7861694.598: \SystemRoot\System32\drivers\aswRvrt.sys:
7871694.598: CreationTime: 2017-06-29T23:00:17.458145600Z
7881694.598: LastWriteTime: 2017-06-29T23:00:14.930941200Z
7891694.598: ChangeTime: 2017-07-25T16:12:53.136855600Z
7901694.598: FileAttributes: 0x20
7911694.598: Size: 0x149a8
7921694.598: NT Headers: 0xf0
7931694.598: Timestamp: 0x5948521c
7941694.598: Machine: 0x8664 - amd64
7951694.598: Timestamp: 0x5948521c
7961694.598: Image Version: 6.0
7971694.598: SizeOfImage: 0x13000 (77824)
7981694.598: Resource Dir: 0x11000 LB 0x388
7991694.598: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
8001694.598: [Raw version resource data: 0x11060 LB 0x328, codepage 0x0 (reserved 0x0)]
8011694.598: ProductName: Avast Antivirus
8021694.598: ProductVersion: 17.5.3540.0
8031694.598: FileVersion: 17.5.3540.0
8041694.598: FileDescription: Avast Revert
8051694.598: \SystemRoot\System32\drivers\aswSnx.sys:
8061694.598: CreationTime: 2017-06-29T23:00:17.395745500Z
8071694.598: LastWriteTime: 2017-08-09T23:07:02.361309900Z
8081694.598: ChangeTime: 2017-08-09T23:07:02.361309900Z
8091694.598: FileAttributes: 0x20
8101694.598: Size: 0xf8048
8111694.598: NT Headers: 0xe8
8121694.598: Timestamp: 0x598357b2
8131694.598: Machine: 0x8664 - amd64
8141694.598: Timestamp: 0x598357b2
8151694.598: Image Version: 6.0
8161694.598: SizeOfImage: 0xf6000 (1007616)
8171694.598: Resource Dir: 0xee000 LB 0x380
8181694.598: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
8191694.598: [Raw version resource data: 0xee060 LB 0x31c, codepage 0x0 (reserved 0x0)]
8201694.598: ProductName: Avast Antivirus
8211694.598: ProductVersion: 17.5.3585.203
8221694.598: FileVersion: 17.5.3585.203
8231694.598: FileDescription: Avast Virtualization Driver
8241694.598: \SystemRoot\System32\drivers\aswsp.sys:
8251694.598: CreationTime: 2017-06-29T23:00:17.473745600Z
8261694.598: LastWriteTime: 2017-06-29T23:00:14.946541200Z
8271694.598: ChangeTime: 2017-07-25T16:12:53.136855600Z
8281694.598: FileAttributes: 0x20
8291694.598: Size: 0x8ef88
8301694.598: NT Headers: 0xe0
8311694.598: Timestamp: 0x594c4886
8321694.598: Machine: 0x8664 - amd64
8331694.598: Timestamp: 0x594c4886
8341694.598: Image Version: 6.0
8351694.598: SizeOfImage: 0xb1000 (724992)
8361694.598: Resource Dir: 0xaf000 LB 0x370
8371694.598: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
8381694.598: [Raw version resource data: 0xaf060 LB 0x310, codepage 0x0 (reserved 0x0)]
8391694.598: ProductName: Avast Antivirus
8401694.598: ProductVersion: 17.5.3556.0
8411694.598: FileVersion: 17.5.3556.0
8421694.598: FileDescription: Avast self protection module
8431694.598: \SystemRoot\System32\drivers\aswStm.sys:
8441694.598: CreationTime: 2017-06-29T23:00:17.520545700Z
8451694.598: LastWriteTime: 2017-06-29T23:00:14.977741300Z
8461694.598: ChangeTime: 2017-07-25T16:12:53.136855600Z
8471694.598: FileAttributes: 0x20
8481694.598: Size: 0x30870
8491694.598: NT Headers: 0x100
8501694.598: Timestamp: 0x59485687
8511694.598: Machine: 0x8664 - amd64
8521694.598: Timestamp: 0x59485687
8531694.598: Image Version: 10.0
8541694.598: SizeOfImage: 0x31000 (200704)
8551694.598: Resource Dir: 0x2f000 LB 0x350
8561694.598: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x405)]
8571694.598: [Raw version resource data: 0x2f060 LB 0x2f0, codepage 0x0 (reserved 0x0)]
8581694.598: ProductName: Avast Antivirus
8591694.598: ProductVersion: 17.5.3540.0
8601694.598: FileVersion: 17.5.3540.0
8611694.598: FileDescription: Stream Filter
8621694.598: \SystemRoot\System32\drivers\aswVmm.sys:
8631694.598: CreationTime: 2017-06-29T23:00:17.504945700Z
8641694.598: LastWriteTime: 2017-07-01T00:41:58.681791100Z
8651694.598: ChangeTime: 2017-07-25T16:12:53.136855600Z
8661694.598: FileAttributes: 0x20
8671694.598: Size: 0x58378
8681694.598: NT Headers: 0xe8
8691694.598: Timestamp: 0x59551244
8701694.598: Machine: 0x8664 - amd64
8711694.598: Timestamp: 0x59551244
8721694.598: Image Version: 6.0
8731694.598: SizeOfImage: 0x56000 (352256)
8741694.598: Resource Dir: 0x53000 LB 0x398
8751694.598: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
8761694.598: [Raw version resource data: 0x53060 LB 0x338, codepage 0x0 (reserved 0x0)]
8771694.598: ProductName: Avast Antivirus
8781694.598: ProductVersion: 17.5.3559.170
8791694.598: FileVersion: 17.5.3559.170
8801694.598: FileDescription: Avast VM Monitor
8811694.598: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
8821694.598: Calling main()
8831694.598: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
8841694.598: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
8851694.598: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
8861694.598: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe)
8871694.598: SUPR3HardenedMain: Final process, opening VBoxDrv...
8881694.598: supR3HardenedEarlyCompact: Removed heap 1 (0x000000002b0000 LB 0x400000)
8891694.598: supR3HardNtEnableThreadCreation:
8901694.598: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll)
8911694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll
8921694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ab7b1:<flags> [calling]
8931694.598: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
8941694.598: supR3HardenedDllNotificationCallback: load 000007fef5f80000 LB 0x00005000 C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL [fFlags=0x0]
8951694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
8961694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
8971694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001a8f31:<flags> [calling]
8981694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef5f80000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
8991694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
9001694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001a8f31:<flags> [calling]
9011694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef5f80000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
9021694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef5f80000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
9031694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
9041694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'crypt32.dll'.
9051694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msasn1.dll'.
9061694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
9071694.598: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\wintrust.dll)
9081694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wintrust.dll
9091694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
9101694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
9111694.598: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll)
9121694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
9131694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
9141694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume2\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
9151694.598: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\msasn1.dll)
9161694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msasn1.dll
9171694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
9181694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume2\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
9191694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
9201694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msasn1.dll'.
9211694.598: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\crypt32.dll)
9221694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\crypt32.dll
9231694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
9241694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
9251694.598: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\msvcrt.dll)
9261694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
9271694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
9281694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume2\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
9291694.598: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
9301694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
9311694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
9321694.598: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
9331694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ad5c1:<flags> [calling]
9341694.598: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
9351694.598: supR3HardenedDllNotificationCallback: load 000007fefcfb0000 LB 0x0003b000 C:\Windows\system32\Wintrust.dll [fFlags=0x0]
9361694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
9371694.598: supR3HardenedDllNotificationCallback: load 000007fefd610000 LB 0x0009f000 C:\Windows\system32\msvcrt.dll [fFlags=0x0]
9381694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
9391694.598: supR3HardenedDllNotificationCallback: load 000007fefd150000 LB 0x0016d000 C:\Windows\system32\CRYPT32.dll [fFlags=0x0]
9401694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
9411694.598: supR3HardenedDllNotificationCallback: load 000007fefcf70000 LB 0x0000f000 C:\Windows\system32\MSASN1.dll [fFlags=0x0]
9421694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
9431694.598: supR3HardenedDllNotificationCallback: load 000007feff070000 LB 0x0012d000 C:\Windows\system32\RPCRT4.dll [fFlags=0x0]
9441694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
9451694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcfb0000 'C:\Windows\system32\Wintrust.dll'
9461694.598: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\bcrypt.dll)
9471694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\bcrypt.dll
9481694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcrypt.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ad5c1:<flags> [calling]
9491694.598: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
9501694.598: supR3HardenedDllNotificationCallback: load 000007fefc8f0000 LB 0x00022000 C:\Windows\system32\bcrypt.dll [fFlags=0x0]
9511694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
9521694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc8f0000 'C:\Windows\system32\bcrypt.dll'
9531694.598: bcrypt.dll loaded at 000007fefc8f0000, BCryptOpenAlgorithmProvider at 000007fefc8f2460, preloading providers:
9541694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
9551694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'bcrypt.dll'.
9561694.598: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll)
9571694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll
9581694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
9591694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume2\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
9601694.598: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
9611694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
9621694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
9631694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
9641694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'rpcrt4.dll'.
9651694.598: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\advapi32.dll)
9661694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\advapi32.dll
9671694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
9681694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
9691694.598: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
9701694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
9711694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
9721694.598: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
9731694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcryptprimitives.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ad5a1:<flags> [calling]
9741694.598: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
9751694.598: supR3HardenedDllNotificationCallback: load 000007fefc3e0000 LB 0x0004c000 C:\Windows\system32\bcryptprimitives.dll [fFlags=0x0]
9761694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
9771694.598: supR3HardenedDllNotificationCallback: load 000007fefd450000 LB 0x000db000 C:\Windows\system32\ADVAPI32.dll [fFlags=0x0]
9781694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
9791694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msvcrt.dll'.
9801694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'rpcrt4.dll'.
9811694.598: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\sechost.dll)
9821694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\sechost.dll
9831694.598: supR3HardenedDllNotificationCallback: load 000007fefe7f0000 LB 0x0001f000 C:\Windows\SYSTEM32\sechost.dll [fFlags=0x0]
9841694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\sechost.dll [lacks WinVerifyTrust]
9851694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc3e0000 'C:\Windows\system32\bcryptprimitives.dll'
9861694.598: BCryptOpenAlgorithmProvider(,'MD2',0,0) -> 0x0 (hAlgo=000000000089c090)
9871694.598: BCryptOpenAlgorithmProvider(,'MD4',0,0) -> 0x0 (hAlgo=000000000089df50)
9881694.598: BCryptOpenAlgorithmProvider(,'MD5',0,0) -> 0x0 (hAlgo=000000000089e080)
9891694.598: BCryptOpenAlgorithmProvider(,'SHA1',0,0) -> 0x0 (hAlgo=000000000089e2a0)
9901694.598: BCryptOpenAlgorithmProvider(,'SHA256',0,0) -> 0x0 (hAlgo=000000000089e3d0)
9911694.598: BCryptOpenAlgorithmProvider(,'SHA512',0,0) -> 0x0 (hAlgo=000000000089e500)
9921694.598: BCryptOpenAlgorithmProvider(,'RSA',0,0) -> 0x0 (hAlgo=000000000089e750)
9931694.598: BCryptOpenAlgorithmProvider(,'DSA',0,0) -> 0x0 (hAlgo=000000000089e880)
9941694.598: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\cryptsp.dll)
9951694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cryptsp.dll
9961694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
9971694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
9981694.598: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
9991694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
10001694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
10011694.598: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
10021694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTSP.dll (Input=CRYPTSP.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ad111:<flags> [calling]
10031694.598: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
10041694.598: supR3HardenedDllNotificationCallback: load 000007fefc7a0000 LB 0x00018000 C:\Windows\system32\CRYPTSP.dll [fFlags=0x0]
10051694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
10061694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc7a0000 'C:\Windows\system32\CRYPTSP.dll'
10071694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
10081694.598: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\rsaenh.dll)
10091694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\rsaenh.dll
10101694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
10111694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
10121694.598: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
10131694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ad0a1:<flags> [calling]
10141694.598: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
10151694.598: supR3HardenedDllNotificationCallback: load 000007fefc4a0000 LB 0x00047000 C:\Windows\system32\rsaenh.dll [fFlags=0x0]
10161694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
10171694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc4a0000 'C:\Windows\system32\rsaenh.dll'
10181694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
10191694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ADVAPI32.dll (Input=ADVAPI32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ac931:<flags> [calling]
10201694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd450000 'C:\Windows\system32\ADVAPI32.dll'
10211694.598: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\cryptbase.dll)
10221694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cryptbase.dll
10231694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTBASE.dll (Input=CRYPTBASE.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001accb1:<flags> [calling]
10241694.598: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptbase.dll [lacks WinVerifyTrust]
10251694.598: supR3HardenedDllNotificationCallback: load 000007fefce10000 LB 0x0000f000 C:\Windows\system32\CRYPTBASE.dll [fFlags=0x0]
10261694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptbase.dll [lacks WinVerifyTrust]
10271694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefce10000 'C:\Windows\system32\CRYPTBASE.dll'
10281694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
10291694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ac6e1:<flags> [calling]
10301694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077060000 'C:\Windows\system32\kernel32.dll'
10311694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
10321694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\WINTRUST.DLL (Input=WINTRUST.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ad071:<flags> [calling]
10331694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcfb0000 'C:\Windows\system32\WINTRUST.DLL'
10341694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
10351694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPT32.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=00000000001acea1:<flags> [calling]
10361694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd150000 'C:\Windows\system32\CRYPT32.dll'
10371694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
10381694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'advapi32.dll'.
10391694.598: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\imagehlp.dll)
10401694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\imagehlp.dll
10411694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
10421694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
10431694.598: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
10441694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
10451694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
10461694.598: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
10471694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\imagehlp.dll (Input=imagehlp.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001acef1:<flags> [calling]
10481694.598: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\imagehlp.dll [lacks WinVerifyTrust]
10491694.598: supR3HardenedDllNotificationCallback: load 000007feff570000 LB 0x00019000 C:\Windows\system32\imagehlp.dll [fFlags=0x0]
10501694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\imagehlp.dll [lacks WinVerifyTrust]
10511694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff570000 'C:\Windows\system32\imagehlp.dll'
10521694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
10531694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTSP.dll (Input=CRYPTSP.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ad041:<flags> [calling]
10541694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc7a0000 'C:\Windows\system32\CRYPTSP.dll'
10551694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
10561694.598: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\user32.dll)
10571694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\user32.dll
10581694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
10591694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
10601694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
10611694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'lpk.dll'.
10621694.598: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\gdi32.dll)
10631694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\gdi32.dll
10641694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'lpk.dll'...
10651694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'lpk.dll' -> '\Device\HarddiskVolume2\Windows\System32\lpk.dll' [rcNtRedir=0xc0150008]
10661694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'gdi32.dll'.
10671694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'user32.dll'.
10681694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'usp10.dll'.
10691694.598: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\lpk.dll)
10701694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\lpk.dll
10711694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
10721694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
10731694.598: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
10741694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'usp10.dll'...
10751694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'usp10.dll' -> '\Device\HarddiskVolume2\Windows\System32\usp10.dll' [rcNtRedir=0xc0150008]
10761694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
10771694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
10781694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'gdi32.dll'.
10791694.598: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\usp10.dll)
10801694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\usp10.dll
10811694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
10821694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
10831694.598: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
10841694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
10851694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
10861694.598: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
10871694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
10881694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
10891694.598: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
10901694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
10911694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
10921694.598: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
10931694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
10941694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
10951694.598: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
10961694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\USER32.dll (Input=USER32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001acb71:<flags> [calling]
10971694.598: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
10981694.598: supR3HardenedDllNotificationCallback: load 0000000077180000 LB 0x000fa000 C:\Windows\system32\USER32.dll [fFlags=0x0]
10991694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
11001694.598: supR3HardenedDllNotificationCallback: load 000007fefd780000 LB 0x00067000 C:\Windows\system32\GDI32.dll [fFlags=0x0]
11011694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
11021694.598: supR3HardenedDllNotificationCallback: load 000007fefd7f0000 LB 0x0000e000 C:\Windows\system32\LPK.dll [fFlags=0x0]
11031694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\lpk.dll [lacks WinVerifyTrust]
11041694.598: supR3HardenedDllNotificationCallback: load 000007fefeec0000 LB 0x000cb000 C:\Windows\system32\USP10.dll [fFlags=0x0]
11051694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\usp10.dll [lacks WinVerifyTrust]
11061694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
11071694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\gdi32.dll (Input=gdi32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ac071:<flags> [calling]
11081694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd780000 'C:\Windows\system32\gdi32.dll'
11091694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'user32.dll'.
11101694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
11111694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msctf.dll'.
11121694.598: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\imm32.dll)
11131694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\imm32.dll
11141694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msctf.dll'...
11151694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'msctf.dll' -> '\Device\HarddiskVolume2\Windows\System32\msctf.dll' [rcNtRedir=0xc0150008]
11161694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
11171694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
11181694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'gdi32.dll'.
11191694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'imm32.dll'.
11201694.598: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\msctf.dll)
11211694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msctf.dll
11221694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
11231694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
11241694.598: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
11251694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
11261694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
11271694.598: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
11281694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
11291694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume2\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
11301694.598: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\imm32.dll [lacks WinVerifyTrust]
11311694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
11321694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
11331694.598: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
11341694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
11351694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
11361694.598: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
11371694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
11381694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
11391694.598: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
11401694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\IMM32.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ab9b1:<flags> [calling]
11411694.598: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\imm32.dll [lacks WinVerifyTrust]
11421694.598: supR3HardenedDllNotificationCallback: load 000007fefd750000 LB 0x0002e000 C:\Windows\system32\IMM32.DLL [fFlags=0x0]
11431694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\imm32.dll [lacks WinVerifyTrust]
11441694.598: supR3HardenedDllNotificationCallback: load 000007fefd330000 LB 0x00109000 C:\Windows\system32\MSCTF.dll [fFlags=0x0]
11451694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msctf.dll [lacks WinVerifyTrust]
11461694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd750000 'C:\Windows\system32\IMM32.DLL'
11471694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077180000 'C:\Windows\system32\USER32.dll'
11481694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'bcrypt.dll'.
11491694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
11501694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msasn1.dll'.
11511694.598: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\ncrypt.dll)
11521694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ncrypt.dll
11531694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
11541694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume2\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
11551694.598: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
11561694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
11571694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
11581694.598: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
11591694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
11601694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume2\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
11611694.598: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
11621694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ncrypt.dll (Input=ncrypt.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ace71:<flags> [calling]
11631694.598: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\ncrypt.dll [lacks WinVerifyTrust]
11641694.598: supR3HardenedDllNotificationCallback: load 000007fefc920000 LB 0x00050000 C:\Windows\system32\ncrypt.dll [fFlags=0x0]
11651694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\ncrypt.dll [lacks WinVerifyTrust]
11661694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc920000 'C:\Windows\system32\ncrypt.dll'
11671694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
11681694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcrypt.dll (Input=bcrypt.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001acc61:<flags> [calling]
11691694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc8f0000 'C:\Windows\system32\bcrypt.dll'
11701694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
11711694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'rpcrt4.dll'.
11721694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'profapi.dll'.
11731694.598: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\userenv.dll)
11741694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\userenv.dll
11751694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'profapi.dll'...
11761694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'profapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\profapi.dll' [rcNtRedir=0xc0150008]
11771694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
11781694.598: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\profapi.dll)
11791694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\profapi.dll
11801694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
11811694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
11821694.598: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
11831694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
11841694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
11851694.598: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
11861694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
11871694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
11881694.598: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
11891694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\USERENV.dll (Input=USERENV.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ac5f1:<flags> [calling]
11901694.598: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\userenv.dll [lacks WinVerifyTrust]
11911694.598: supR3HardenedDllNotificationCallback: load 000007fefd100000 LB 0x0001e000 C:\Windows\system32\USERENV.dll [fFlags=0x0]
11921694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\userenv.dll [lacks WinVerifyTrust]
11931694.598: supR3HardenedDllNotificationCallback: load 000007fefcf80000 LB 0x0000f000 C:\Windows\system32\profapi.dll [fFlags=0x0]
11941694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\profapi.dll [lacks WinVerifyTrust]
11951694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd100000 'C:\Windows\system32\USERENV.dll'
11961694.598: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000001ac351:<flags> [calling]
11971694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe7f0000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
11981694.598: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000001ac6e1:<flags> [calling]
11991694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe7f0000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
12001694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
12011694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'rpcrt4.dll'.
12021694.598: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\gpapi.dll)
12031694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\gpapi.dll
12041694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
12051694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
12061694.598: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
12071694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
12081694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
12091694.598: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
12101694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\GPAPI.dll (Input=GPAPI.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ac911:<flags> [calling]
12111694.598: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gpapi.dll [lacks WinVerifyTrust]
12121694.598: supR3HardenedDllNotificationCallback: load 000007fefc210000 LB 0x0001b000 C:\Windows\system32\GPAPI.dll [fFlags=0x0]
12131694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gpapi.dll [lacks WinVerifyTrust]
12141694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc210000 'C:\Windows\system32\GPAPI.dll'
12151694.598: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-Management-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000001ac861:<flags> [calling]
12161694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe7f0000 'API-MS-WIN-Service-Management-L1-1-0.dll'
12171694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
12181694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rpcrt4.dll (Input=rpcrt4.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001abf61:<flags> [calling]
12191694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff070000 'C:\Windows\system32\rpcrt4.dll'
12201694.598: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-Management-L2-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000001ac841:<flags> [calling]
12211694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe7f0000 'API-MS-WIN-Service-Management-L2-1-0.dll'
12221694.598: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000001ac851:<flags> [calling]
12231694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe7f0000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
12241694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
12251694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'advapi32.dll'.
12261694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'crypt32.dll'.
12271694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'wldap32.dll'.
12281694.598: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\cryptnet.dll)
12291694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cryptnet.dll
12301694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wldap32.dll'...
12311694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'wldap32.dll' -> '\Device\HarddiskVolume2\Windows\System32\wldap32.dll' [rcNtRedir=0xc0150008]
12321694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
12331694.598: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\Wldap32.dll)
12341694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\Wldap32.dll
12351694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
12361694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume2\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
12371694.598: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
12381694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
12391694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
12401694.598: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
12411694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
12421694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
12431694.598: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
12441694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
12451694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
12461694.598: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
12471694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (Input=cryptnet.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ac351:<flags> [calling]
12481694.598: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
12491694.598: supR3HardenedDllNotificationCallback: load 000007fef8c40000 LB 0x00027000 C:\Windows\system32\cryptnet.dll [fFlags=0x0]
12501694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
12511694.598: supR3HardenedDllNotificationCallback: load 000007fefd5b0000 LB 0x00052000 C:\Windows\system32\WLDAP32.dll [fFlags=0x0]
12521694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\Wldap32.dll [lacks WinVerifyTrust]
12531694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
12541694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=00000000001ab581:<flags> [calling]
12551694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef8c40000 'C:\Windows\system32\cryptnet.dll'
12561694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
12571694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=00000000001ab581:<flags> [calling]
12581694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef8c40000 'C:\Windows\system32\cryptnet.dll'
12591694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
12601694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=00000000001ab581:<flags> [calling]
12611694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef8c40000 'C:\Windows\system32\cryptnet.dll'
12621694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
12631694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=00000000001ab581:<flags> [calling]
12641694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef8c40000 'C:\Windows\system32\cryptnet.dll'
12651694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
12661694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=00000000001ab581:<flags> [calling]
12671694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef8c40000 'C:\Windows\system32\cryptnet.dll'
12681694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
12691694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=00000000001ab581:<flags> [calling]
12701694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef8c40000 'C:\Windows\system32\cryptnet.dll'
12711694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
12721694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef8c40000 'C:\Windows\system32\cryptnet.dll'
12731694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
12741694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef8c40000 'C:\Windows\system32\cryptnet.dll'
12751694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
12761694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef8c40000 'C:\Windows\system32\cryptnet.dll'
12771694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
12781694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef8c40000 'C:\Windows\system32\cryptnet.dll'
12791694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
12801694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef8c40000 'C:\Windows\system32\cryptnet.dll'
12811694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef8c40000 'C:\Windows\system32\cryptnet.dll'
12821694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
12831694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef8c40000 'C:\Windows\system32\cryptnet.dll'
12841694.598: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000001abc71:<flags> [calling]
12851694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe7f0000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
12861694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\profapi.dll [lacks WinVerifyTrust]
12871694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\profapi.dll (Input=profapi.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001abc71:<flags> [calling]
12881694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcf80000 'C:\Windows\system32\profapi.dll'
12891694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
12901694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
12911694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msvcrt.dll'.
12921694.598: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\shlwapi.dll)
12931694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\shlwapi.dll
12941694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
12951694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
12961694.598: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
12971694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
12981694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
12991694.598: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
13001694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
13011694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
13021694.598: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
13031694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\SHLWAPI.dll (Input=SHLWAPI.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ab701:<flags> [calling]
13041694.598: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll [lacks WinVerifyTrust]
13051694.598: supR3HardenedDllNotificationCallback: load 000007fefd530000 LB 0x00071000 C:\Windows\system32\SHLWAPI.dll [fFlags=0x0]
13061694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll [lacks WinVerifyTrust]
13071694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd530000 'C:\Windows\system32\SHLWAPI.dll'
13081694.598: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000000 pwszName=\SystemRoot\System32\ntdll.dll
13091694.598: supR3HardNtViCallWinVerifyTrustCatFile: New context 000000000091b250
13101694.598: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
13111694.598: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=8D1E7AF77C8E31C723E97ADD378C1707C0ED4D09
13121694.598: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000001ac631:<flags> [calling]
13131694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe7f0000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
13141694.598: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-Management-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000001ac191:<flags> [calling]
13151694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe7f0000 'API-MS-WIN-Service-Management-L1-1-0.dll'
13161694.598: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-winsvc-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000001ac191:<flags> [calling]
13171694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe7f0000 'API-MS-WIN-Service-winsvc-L1-1-0.dll'
13181694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
13191694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ADVAPI32.dll (Input=ADVAPI32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ac631:<flags> [calling]
13201694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd450000 'C:\Windows\system32\ADVAPI32.dll'
13211694.598: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-LSALookup-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000001ac5e1:<flags> [calling]
13221694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe7f0000 'API-MS-Win-Security-LSALookup-L1-1-0.dll'
13231694.598: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-LSALookup-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000001ac2d1:<flags> [calling]
13241694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe7f0000 'API-MS-Win-Security-LSALookup-L1-1-0.dll'
13251694.598: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_413_for_KB4034664~31bf3856ad364e35~amd64~~6.1.1.4.cat'; file='\SystemRoot\System32\ntdll.dll'
13261694.598: g_pfnWinVerifyTrust=000007fefcfb1010
13271694.598: supR3HardenedScreenImage/preload: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [redoing WinVerifyTrust]
13281694.598: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000e0 pwszName=\Device\HarddiskVolume2\Windows\System32\crypt32.dll
13291694.598: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
13301694.598: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
13311694.598: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F77D21FA60E897144706C54D4A369C8DA3A96EDC
13321694.598: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_413_for_KB4034664~31bf3856ad364e35~amd64~~6.1.1.4.cat'; file='\Device\HarddiskVolume2\Windows\System32\crypt32.dll'
13331694.598: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
13341694.598: supR3HardenedScreenImage/preload: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\crypt32.dll'
13351694.598: supR3HardenedScreenImage/preload: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [redoing WinVerifyTrust]
13361694.598: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000d4 pwszName=\Device\HarddiskVolume2\Windows\System32\wintrust.dll
13371694.598: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
13381694.598: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
13391694.598: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=64DB0BCE4F2D99E4624F5476790FB954117C96EF
13401694.598: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_413_for_KB4034664~31bf3856ad364e35~amd64~~6.1.1.4.cat'; file='\Device\HarddiskVolume2\Windows\System32\wintrust.dll'
13411694.598: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
13421694.598: supR3HardenedScreenImage/preload: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\wintrust.dll'
13431694.598: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000003bc pwszName=\Device\HarddiskVolume2\Windows\System32\shlwapi.dll
13441694.598: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
13451694.598: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
13461694.598: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=0AB8D9C9D3E1FC95D01F9A984B16ED031BB40CD8
13471694.598: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\shlwapi.dll'
13481694.598: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
13491694.598: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll'
13501694.598: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000003b4 pwszName=\Device\HarddiskVolume2\Windows\System32\Wldap32.dll
13511694.598: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
13521694.598: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
13531694.598: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=C98DA6A5C5D40E628701C3AAF8EA5A40DD2689D2
13541694.598: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_413_for_KB4034664~31bf3856ad364e35~amd64~~6.1.1.4.cat'; file='\Device\HarddiskVolume2\Windows\System32\Wldap32.dll'
13551694.598: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
13561694.598: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\Wldap32.dll'
13571694.598: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000003b0 pwszName=\Device\HarddiskVolume2\Windows\System32\cryptnet.dll
13581694.598: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
13591694.598: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
13601694.598: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=39AF46E16CB63BADF4DB0AE7F539D8C4373E13BA
13611694.598: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_413_for_KB4034664~31bf3856ad364e35~amd64~~6.1.1.4.cat'; file='\Device\HarddiskVolume2\Windows\System32\cryptnet.dll'
13621694.598: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
13631694.598: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\cryptnet.dll'
13641694.598: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000026c pwszName=\Device\HarddiskVolume2\Windows\System32\gpapi.dll
13651694.598: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
13661694.598: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
13671694.598: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=EBDAA16C3FD93DFF9C20BA3B2689DFF4C8D31061
13681694.598: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_115_for_KB3159398~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\gpapi.dll'
13691694.598: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
13701694.598: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\gpapi.dll'
13711694.598: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000001d8 pwszName=\Device\HarddiskVolume2\Windows\System32\profapi.dll
13721694.598: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
13731694.598: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
13741694.598: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2449672745D9BA339420451D13FA0380AA768231
13751694.598: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\profapi.dll'
13761694.598: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
13771694.598: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\profapi.dll'
13781694.598: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000001d4 pwszName=\Device\HarddiskVolume2\Windows\System32\userenv.dll
13791694.598: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
13801694.598: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
13811694.598: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=D3E1A2CC7367F751C19EBF4E6EDF5E9A10E47313
13821694.598: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\userenv.dll'
13831694.598: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
13841694.598: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\userenv.dll'
13851694.598: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000001c0 pwszName=\Device\HarddiskVolume2\Windows\System32\ncrypt.dll
13861694.598: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
13871694.598: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
13881694.598: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=3F62B9D98E1DE7981ECBEA8B3F88C873F925211D
13891694.598: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_413_for_KB4034664~31bf3856ad364e35~amd64~~6.1.1.4.cat'; file='\Device\HarddiskVolume2\Windows\System32\ncrypt.dll'
13901694.598: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
13911694.598: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\ncrypt.dll'
13921694.598: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000001a8 pwszName=\Device\HarddiskVolume2\Windows\System32\msctf.dll
13931694.598: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
13941694.598: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
13951694.598: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=6D141A0C50E469CDD81DC8293CF8B3635FE0240E
13961694.598: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_413_for_KB4034664~31bf3856ad364e35~amd64~~6.1.1.4.cat'; file='\Device\HarddiskVolume2\Windows\System32\msctf.dll'
13971694.598: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
13981694.598: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\msctf.dll'
13991694.598: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000001a4 pwszName=\Device\HarddiskVolume2\Windows\System32\imm32.dll
14001694.598: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
14011694.598: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
14021694.598: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=6EEE1AB3B6D79AFF857940FF5F51ED27698153EC
14031694.598: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\imm32.dll'
14041694.598: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
14051694.598: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\imm32.dll'
14061694.598: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000001a0 pwszName=\Device\HarddiskVolume2\Windows\System32\usp10.dll
14071694.598: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
14081694.598: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
14091694.598: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=EFAF060D43CBE108CC0D9F19F7A46C65B71782E8
14101694.598: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_413_for_KB4034664~31bf3856ad364e35~amd64~~6.1.1.4.cat'; file='\Device\HarddiskVolume2\Windows\System32\usp10.dll'
14111694.598: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
14121694.598: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\usp10.dll'
14131694.598: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000019c pwszName=\Device\HarddiskVolume2\Windows\System32\lpk.dll
14141694.598: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
14151694.598: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
14161694.598: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=54204179B88581EFC0328D16D151171EADAA7023
14171694.598: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_413_for_KB4034664~31bf3856ad364e35~amd64~~6.1.1.4.cat'; file='\Device\HarddiskVolume2\Windows\System32\lpk.dll'
14181694.598: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
14191694.598: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\lpk.dll'
14201694.598: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000198 pwszName=\Device\HarddiskVolume2\Windows\System32\gdi32.dll
14211694.598: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
14221694.598: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
14231694.598: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=C825E345B3737457F9C8CE8AE46B101F3EE4F2D4
14241694.598: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_413_for_KB4034664~31bf3856ad364e35~amd64~~6.1.1.4.cat'; file='\Device\HarddiskVolume2\Windows\System32\gdi32.dll'
14251694.598: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
14261694.598: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\gdi32.dll'
14271694.598: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000194 pwszName=\Device\HarddiskVolume2\Windows\System32\user32.dll
14281694.598: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
14291694.598: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
14301694.598: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=03BB259EC2F9D61B0941E0635513FFA135E07009
14311694.598: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_413_for_KB4034664~31bf3856ad364e35~amd64~~6.1.1.4.cat'; file='\Device\HarddiskVolume2\Windows\System32\user32.dll'
14321694.598: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
14331694.598: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\user32.dll'
14341694.598: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000190 pwszName=\Device\HarddiskVolume2\Windows\System32\imagehlp.dll
14351694.598: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
14361694.598: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
14371694.598: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2702EE05F1B717B0F2CE0FBE32784A47B8419DCA
14381694.598: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_2_for_KB2893294~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\imagehlp.dll'
14391694.598: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
14401694.598: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\imagehlp.dll'
14411694.598: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000134 pwszName=\Device\HarddiskVolume2\Windows\System32\cryptbase.dll
14421694.598: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
14431694.598: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
14441694.598: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=0F801CACE85738226CF0FE6E874CCC0F19833A9E
14451694.598: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_413_for_KB4034664~31bf3856ad364e35~amd64~~6.1.1.4.cat'; file='\Device\HarddiskVolume2\Windows\System32\cryptbase.dll'
14461694.598: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
14471694.598: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\cryptbase.dll'
14481694.598: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\rsaenh.dll'
14491694.598: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000130 pwszName=\Device\HarddiskVolume2\Windows\System32\cryptsp.dll
14501694.598: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
14511694.598: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
14521694.598: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=CECCA98E04985A576883E9A9AD8AF2140526B576
14531694.598: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_413_for_KB4034664~31bf3856ad364e35~amd64~~6.1.1.4.cat'; file='\Device\HarddiskVolume2\Windows\System32\cryptsp.dll'
14541694.598: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
14551694.598: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\cryptsp.dll'
14561694.598: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000120 pwszName=\Device\HarddiskVolume2\Windows\System32\sechost.dll
14571694.598: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
14581694.598: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
14591694.598: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=3FA2A014BF360CDC0E203A174FFC9DC5343C5323
14601694.598: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\sechost.dll'
14611694.598: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
14621694.598: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\sechost.dll'
14631694.598: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000011c pwszName=\Device\HarddiskVolume2\Windows\System32\advapi32.dll
14641694.598: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
14651694.598: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
14661694.598: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=EB1FE2F561CE20B9DFBA19009F4A05AF3D449D52
14671694.598: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_413_for_KB4034664~31bf3856ad364e35~amd64~~6.1.1.4.cat'; file='\Device\HarddiskVolume2\Windows\System32\advapi32.dll'
14681694.598: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
14691694.598: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\advapi32.dll'
14701694.598: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll'
14711694.598: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000104 pwszName=\Device\HarddiskVolume2\Windows\System32\bcrypt.dll
14721694.598: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
14731694.598: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
14741694.598: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=52F202663F9DED85B54F9D01490BBEDACE8A7787
14751694.598: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_413_for_KB4034664~31bf3856ad364e35~amd64~~6.1.1.4.cat'; file='\Device\HarddiskVolume2\Windows\System32\bcrypt.dll'
14761694.598: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
14771694.598: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\bcrypt.dll'
14781694.598: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000e4 pwszName=\Device\HarddiskVolume2\Windows\System32\msvcrt.dll
14791694.598: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
14801694.598: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
14811694.598: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2CA2FD632B264C063162F71474266E3615B6420C
14821694.598: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB2654428~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\Windows\System32\msvcrt.dll'
14831694.598: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
14841694.598: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll'
14851694.598: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000dc pwszName=\Device\HarddiskVolume2\Windows\System32\msasn1.dll
14861694.598: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
14871694.598: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
14881694.598: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F2FF57DC30D774F93061607060DAA0DD15E39CCE
14891694.598: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\msasn1.dll'
14901694.598: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
14911694.598: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\msasn1.dll'
14921694.598: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000d8 pwszName=\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
14931694.598: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
14941694.598: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
14951694.598: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=0EF7B4F59A4CAFF4E8B7CE99D7498EADCCFB39FE
14961694.598: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_413_for_KB4034664~31bf3856ad364e35~amd64~~6.1.1.4.cat'; file='\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll'
14971694.598: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
14981694.598: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll'
14991694.598: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll'
15001694.598: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000028 pwszName=\Device\HarddiskVolume2\Windows\System32\KernelBase.dll
15011694.598: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
15021694.598: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
15031694.598: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=C9917E80D1AAEFAAFEDE6EDA805A8F2995480127
15041694.598: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_413_for_KB4034664~31bf3856ad364e35~amd64~~6.1.1.4.cat'; file='\Device\HarddiskVolume2\Windows\System32\KernelBase.dll'
15051694.598: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
15061694.598: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\KernelBase.dll'
15071694.598: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000020 pwszName=\Device\HarddiskVolume2\Windows\System32\kernel32.dll
15081694.598: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
15091694.598: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
15101694.598: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=75CCD2778844D148B2A8A128FB2D1691A441A7FA
15111694.598: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_413_for_KB4034664~31bf3856ad364e35~amd64~~6.1.1.4.cat'; file='\Device\HarddiskVolume2\Windows\System32\kernel32.dll'
15121694.598: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
15131694.598: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\kernel32.dll'
15141694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll
15151694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\crypt32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ac0d1:<flags> [calling]
15161694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd150000 'C:\Windows\system32\crypt32.dll'
15171694.598: supR3HardenedWinIsDesiredRootCA: Adding 0x9372cefd77d5d300 OU=generated by avast! antivirus for SSL/TLS scanning, O=avast! Web/Mail Shield, CN=avast! Web/Mail Shield Root
15181694.598: supR3HardenedWinIsDesiredRootCA: Adding 0x5ad46780fa5df300 DC=com, DC=microsoft, CN=Microsoft Root Certificate Authority
15191694.598: supR3HardenedWinIsDesiredRootCA: Adding 0xea5386456178582b C=ZA, ST=Western Cape, L=Durbanville, O=Thawte, OU=Thawte Certification, CN=Thawte Timestamping CA
15201694.598: supR3HardenedWinIsDesiredRootCA: Adding 0x3be670c1bd02a900 OU=Copyright (c) 1997 Microsoft Corp., OU=Microsoft Corporation, CN=Microsoft Root Authority
15211694.598: supR3HardenedWinIsDesiredRootCA: Adding 0x4d3835aa4180b200 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2011
15221694.598: supR3HardenedWinIsDesiredRootCA: Adding 0x646e3fe3ba08df00 C=US, O=MSFT, CN=Microsoft Authenticode(tm) Root Authority
15231694.598: supR3HardenedWinIsDesiredRootCA: Adding 0xd27ca3602f37c200 OU=generated by Avast Antivirus for SSL/TLS scanning, O=Avast Web/Mail Shield, CN=Avast Web/Mail Shield Root
15241694.598: supR3HardenedWinIsDesiredRootCA: Adding 0xece4e4289e08b900 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010
15251694.598: supR3HardenedWinIsDesiredRootCA: Adding 0x43a9cc371ff5385a O=Microsoft Trust Network, OU=Microsoft Corporation, OU=Microsoft Time Stamping Service Root, OU=Copyright (c) 1997 Microsoft Corp.
15261694.598: supR3HardenedWinIsDesiredRootCA: Adding 0x2e2d2c7c68f0202e O=VeriSign Trust Network, OU=VeriSign, Inc., OU=VeriSign Time Stamping Service Root, OU=NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.
15271694.598: supR3HardenedWinIsDesiredRootCA: Adding 0xd8dbfb2c27bfb200 C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2008 thawte, Inc. - For authorized use only, CN=thawte Primary Root CA - G3
15281694.598: supR3HardenedWinIsDesiredRootCA: Adding 0x61a3a33f81aace00 C=US, ST=UT, L=Salt Lake City, O=The USERTRUST Network, OU=http://www.usertrust.com, CN=UTN-USERFirst-Object
15291694.598: supR3HardenedWinIsDesiredRootCA: Adding 0xf4fd306318ccda00 C=US, O=GeoTrust Inc., CN=GeoTrust Global CA
15301694.598: supR3HardenedWinIsDesiredRootCA: Adding 0x83085097e9afdf00 O=Digital Signature Trust Co., CN=DST Root CA X3
15311694.598: supR3HardenedWinIsDesiredRootCA: Adding 0x780679907625cc00 OU=GlobalSign Root CA - R3, O=GlobalSign, CN=GlobalSign
15321694.598: supR3HardenedWinIsDesiredRootCA: Adding 0x3d98ab22bb04a300 C=IE, O=Baltimore, OU=CyberTrust, CN=Baltimore CyberTrust Root
15331694.598: supR3HardenedWinIsDesiredRootCA: Adding 0xa0ee62086758b15d C=US, O=Equifax, OU=Equifax Secure Certificate Authority
15341694.598: supR3HardenedWinIsDesiredRootCA: Adding 0x8ff6fc03c1edbd00 C=US, ST=Arizona, L=Scottsdale, O=Starfield Technologies, Inc., CN=Starfield Root Certificate Authority - G2
15351694.598: supR3HardenedWinIsDesiredRootCA: Adding 0xc6fa4243b695b600 C=US, O=Entrust, Inc., OU=www.entrust.net/CPS is incorporated by reference, OU=(c) 2006 Entrust, Inc., CN=Entrust Root Certification Authority
15361694.598: supR3HardenedWinIsDesiredRootCA: Adding 0xa3ce8d99e60eda00 C=BE, O=GlobalSign nv-sa, OU=Root CA, CN=GlobalSign Root CA
15371694.598: supR3HardenedWinIsDesiredRootCA: Adding 0xa671e9fec832b700 C=US, O=Starfield Technologies, Inc., OU=Starfield Class 2 Certification Authority
15381694.598: supR3HardenedWinIsDesiredRootCA: Adding 0xa8de7211e13be200 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root CA
15391694.598: supR3HardenedWinIsDesiredRootCA: Adding 0x7ae89c50f0b6a00f C=US, O=GTE Corporation, OU=GTE CyberTrust Solutions, Inc., CN=GTE CyberTrust Global Root
15401694.598: supR3HardenedWinIsDesiredRootCA: Adding 0xd45980fbf0a0ac00 C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2006 thawte, Inc. - For authorized use only, CN=thawte Primary Root CA
15411694.598: supR3HardenedWinIsDesiredRootCA: Adding 0xc9edb72b684ba00 C=US, O=Entrust, Inc., OU=See www.entrust.net/legal-terms, OU=(c) 2009 Entrust, Inc. - for authorized use only, CN=Entrust Root Certification Authority - G2
15421694.598: supR3HardenedWinIsDesiredRootCA: Adding 0xf5cd95e581a4ab00 C=US, O=SecureTrust Corporation, CN=SecureTrust CA
15431694.598: supR3HardenedWinIsDesiredRootCA: Adding 0x14018a1bf29e595c C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority
15441694.598: supR3HardenedWinIsDesiredRootCA: Adding 0x9e5bc2d78b6a3636 C=ZA, ST=Western Cape, L=Cape Town, O=Thawte Consulting cc, OU=Certification Services Division, CN=Thawte Premium Server CA, [email protected]
15451694.598: supR3HardenedWinIsDesiredRootCA: Adding 0x7c4fd32ec1b1ce00 C=PL, O=Unizeto Sp. z o.o., CN=Certum CA
15461694.598: supR3HardenedWinIsDesiredRootCA: Adding 0xd4fbe673e5ccc600 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA
15471694.598: supR3HardenedWinIsDesiredRootCA: Adding 0x357a29080824af00 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2006 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G5
15481694.598: supR3HardenedWinIsDesiredRootCA: Adding 0x59faf1086271bf00 C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com, Inc., CN=Go Daddy Root Certificate Authority - G2
15491694.598: supR3HardenedWinIsDesiredRootCA: Adding 0x466cbc09db88c100 C=IL, O=StartCom Ltd., OU=Secure Digital Certificate Signing, CN=StartCom Certification Authority
15501694.598: supR3HardenedWinIsDesiredRootCA: Adding 0x3401b15e3761c700 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2008 VeriSign, Inc. - For authorized use only, CN=VeriSign Universal Root Certification Authority
15511694.598: supR3HardenedWinIsDesiredRootCA: Adding 0x491857ead79dde00 C=US, O=The Go Daddy Group, Inc., OU=Go Daddy Class 2 Certification Authority
15521694.598: supR3HardenedWinIsDesiredRootCA: Adding 0xc2ba72a37dfbe300 C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Trusted Network CA
15531694.598: supR3HardenedWinIsDesiredRootCA: Adding 0x8043e4ce150ead00 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID Root CA
15541694.598: supR3HardenedWinIsDesiredRootCA: Adding 0x331d58625ee2dc00 C=US, O=GeoTrust Inc., OU=(c) 2008 GeoTrust Inc. - For authorized use only, CN=GeoTrust Primary Certification Authority - G3
15551694.598: supR3HardenedWinIsDesiredRootCA: Adding 0xf2e6331af7b700 C=SE, O=AddTrust AB, OU=AddTrust External TTP Network, CN=AddTrust External CA Root
15561694.598: supR3HardenedWinRetrieveTrustedRootCAs: cAdded=39
15571694.598: SUPR3HardenedMain: Load Runtime...
15581694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
15591694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
15601694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ws2_32.dll'.
15611694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'rpcrt4.dll'.
15621694.598: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll) WinVerifyTrust
15631694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
15641694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
15651694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
15661694.598: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
15671694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
15681694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
15691694.598: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000043c pwszName=\Device\HarddiskVolume2\Windows\System32\ws2_32.dll
15701694.598: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
15711694.598: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
15721694.598: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=901DCB8172024F14E25295BF5692180F12FC8C18
15731694.598: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3161949~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\Windows\System32\ws2_32.dll'
15741694.598: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
15751694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
15761694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'rpcrt4.dll'.
15771694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'nsi.dll'.
15781694.598: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ws2_32.dll) WinVerifyTrust
15791694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
15801694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
15811694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
15821694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
15831694.598: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll) WinVerifyTrust
15841694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
15851694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
15861694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
15871694.598: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll) WinVerifyTrust
15881694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
15891694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
15901694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
15911694.598: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
15921694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
15931694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume2\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
15941694.598: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000044c pwszName=\Device\HarddiskVolume2\Windows\System32\nsi.dll
15951694.598: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
15961694.598: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
15971694.598: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=7AFD8538945F2D05BC1AF949B9B19B7D2D9FBBF8
15981694.598: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\nsi.dll'
15991694.598: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
16001694.598: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\nsi.dll) WinVerifyTrust
16011694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\nsi.dll
16021694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
16031694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
16041694.598: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
16051694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
16061694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
16071694.598: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
16081694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ac401:<flags> [calling]
16091694.598: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
16101694.598: supR3HardenedDllNotificationCallback: load 000007feed840000 LB 0x0053d000 C:\Program Files\Oracle\VirtualBox\VBoxRT.dll [fFlags=0x0]
16111694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
16121694.598: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
16131694.598: supR3HardenedDllNotificationCallback: load 000000005df20000 LB 0x000d2000 C:\Program Files\Oracle\VirtualBox\MSVCR100.dll [fFlags=0x0]
16141694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
16151694.598: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
16161694.598: supR3HardenedDllNotificationCallback: load 000000005e040000 LB 0x00098000 C:\Program Files\Oracle\VirtualBox\MSVCP100.dll [fFlags=0x0]
16171694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
16181694.598: supR3HardenedDllNotificationCallback: load 000007fefee70000 LB 0x0004d000 C:\Windows\system32\WS2_32.dll [fFlags=0x0]
16191694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
16201694.598: supR3HardenedDllNotificationCallback: load 000007fefd440000 LB 0x00008000 C:\Windows\system32\NSI.dll [fFlags=0x0]
16211694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\nsi.dll
16221694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
16231694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001a9b41:<flags> [calling]
16241694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed840000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
16251694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
16261694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001a9b41:<flags> [calling]
16271694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed840000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
16281694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
16291694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001a9b41:<flags> [calling]
16301694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed840000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
16311694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
16321694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001a9b41:<flags> [calling]
16331694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed840000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
16341694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
16351694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001a9b41:<flags> [calling]
16361694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed840000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
16371694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
16381694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001a9b41:<flags> [calling]
16391694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed840000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
16401694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed840000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
16411694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed840000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
16421694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed840000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
16431694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed840000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
16441694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed840000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
16451694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed840000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
16461694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed840000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
16471694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
16481694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001a9b41:<flags> [calling]
16491694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed840000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
16501694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed840000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
16511694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed840000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
16521694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed840000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
16531694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed840000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
16541694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed840000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
16551694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed840000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
16561694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed840000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
16571694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed840000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
16581694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed840000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
16591694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed840000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
16601694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed840000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
16611694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed840000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
16621694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed840000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
16631694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed840000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
16641694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed840000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
16651694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
16661694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001a9b41:<flags> [calling]
16671694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed840000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
16681694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed840000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
16691694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed840000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
16701694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed840000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
16711694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll
16721694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001adf61:<flags> [calling]
16731694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcfb0000 'C:\Windows\system32\Wintrust.dll'
16741694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll
16751694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\crypt32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001acab1:<flags> [calling]
16761694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd150000 'C:\Windows\system32\crypt32.dll'
16771694.598: SUPR3HardenedMain: Load TrustedMain...
16781694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'opengl32.dll'.
16791694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
16801694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcp100.dll'.
16811694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcr100.dll'.
16821694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qt5corevbox.dll'.
16831694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'qt5guivbox.dll'.
16841694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'qt5widgetsvbox.dll'.
16851694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'qt5printsupportvbox.dll'.
16861694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'qt5openglvbox.dll'.
16871694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'user32.dll'.
16881694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'advapi32.dll'.
16891694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'shell32.dll'.
16901694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'ole32.dll'.
16911694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'oleaut32.dll'.
16921694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #15 'winmm.dll'.
16931694.598: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.dll) WinVerifyTrust
16941694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.dll
16951694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
16961694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
16971694.598: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000494 pwszName=\Device\HarddiskVolume2\Windows\System32\winmm.dll
16981694.598: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
16991694.598: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
17001694.598: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=82E2B2A7826F88BEB98FFF0540C9BDB0A12F001A
17011694.598: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\winmm.dll'
17021694.598: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
17031694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
17041694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
17051694.598: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\winmm.dll) WinVerifyTrust
17061694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\winmm.dll
17071694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
17081694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
17091694.598: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000047c pwszName=\Device\HarddiskVolume2\Windows\System32\oleaut32.dll
17101694.598: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
17111694.598: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
17121694.598: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=6E76105B511B0668122629A2554FAFBBE17CD6DF
17131694.598: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_413_for_KB4034664~31bf3856ad364e35~amd64~~6.1.1.4.cat'; file='\Device\HarddiskVolume2\Windows\System32\oleaut32.dll'
17141694.598: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
17151694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ole32.dll'.
17161694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
17171694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
17181694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'user32.dll'.
17191694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'gdi32.dll'.
17201694.598: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\oleaut32.dll) WinVerifyTrust
17211694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
17221694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
17231694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
17241694.598: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004a0 pwszName=\Device\HarddiskVolume2\Windows\System32\ole32.dll
17251694.598: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
17261694.598: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
17271694.598: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=E3D6DA21FECCBC3CFB6FD4597280DC013ADD2D59
17281694.598: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_413_for_KB4034664~31bf3856ad364e35~amd64~~6.1.1.4.cat'; file='\Device\HarddiskVolume2\Windows\System32\ole32.dll'
17291694.598: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
17301694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
17311694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
17321694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'user32.dll'.
17331694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'rpcrt4.dll'.
17341694.598: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ole32.dll) WinVerifyTrust
17351694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ole32.dll
17361694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
17371694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
17381694.598: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000046c pwszName=\Device\HarddiskVolume2\Windows\System32\shell32.dll
17391694.598: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
17401694.598: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
17411694.598: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=DBC6DA834E0DA642E3A7EB4466EBDC7921EDD667
17421694.598: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_413_for_KB4034664~31bf3856ad364e35~amd64~~6.1.1.4.cat'; file='\Device\HarddiskVolume2\Windows\System32\shell32.dll'
17431694.598: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
17441694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
17451694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #21 'shlwapi.dll'.
17461694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'user32.dll'.
17471694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #24 'gdi32.dll'.
17481694.598: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\shell32.dll) WinVerifyTrust
17491694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\shell32.dll
17501694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
17511694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
17521694.598: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
17531694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
17541694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
17551694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5openglvbox.dll'...
17561694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5openglvbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5openglvbox.dll' [rcNtRedir=0xc0150008]
17571694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'qt5widgetsvbox.dll'.
17581694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'qt5guivbox.dll'.
17591694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5corevbox.dll'.
17601694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcr100.dll'.
17611694.598: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll) WinVerifyTrust
17621694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll
17631694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5printsupportvbox.dll'...
17641694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5printsupportvbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5printsupportvbox.dll' [rcNtRedir=0xc0150008]
17651694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
17661694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
17671694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5widgetsvbox.dll'.
17681694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qt5guivbox.dll'.
17691694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qt5corevbox.dll'.
17701694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'winspool.drv'.
17711694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'comdlg32.dll'.
17721694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'msvcr100.dll'.
17731694.598: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5PrintSupportVBox.dll) WinVerifyTrust
17741694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5PrintSupportVBox.dll
17751694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
17761694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
17771694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
17781694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
17791694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5guivbox.dll'.
17801694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qt5corevbox.dll'.
17811694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'shell32.dll'.
17821694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcp100.dll'.
17831694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcr100.dll'.
17841694.598: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll) WinVerifyTrust
17851694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll
17861694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
17871694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
17881694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ole32.dll'.
17891694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'opengl32.dll'.
17901694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
17911694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
17921694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qt5corevbox.dll'.
17931694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcp100.dll'.
17941694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcr100.dll'.
17951694.598: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll) WinVerifyTrust
17961694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
17971694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
17981694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
17991694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
18001694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'shell32.dll'.
18011694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ole32.dll'.
18021694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
18031694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ws2_32.dll'.
18041694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'mpr.dll'.
18051694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'msvcp100.dll'.
18061694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'msvcr100.dll'.
18071694.598: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll) WinVerifyTrust
18081694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
18091694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
18101694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
18111694.598: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
18121694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
18131694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
18141694.598: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
18151694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
18161694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
18171694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
18181694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
18191694.598: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000048c pwszName=\Device\HarddiskVolume2\Windows\System32\opengl32.dll
18201694.598: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
18211694.598: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
18221694.598: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=608AC397FCC42B9FBAE25CB8C25EAF4C19AA384D
18231694.598: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\opengl32.dll'
18241694.598: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
18251694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
18261694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
18271694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'gdi32.dll'.
18281694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'glu32.dll'.
18291694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ddraw.dll'.
18301694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'user32.dll'.
18311694.598: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\opengl32.dll) WinVerifyTrust
18321694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\opengl32.dll
18331694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
18341694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
18351694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ddraw.dll'...
18361694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'ddraw.dll' -> '\Device\HarddiskVolume2\Windows\System32\ddraw.dll' [rcNtRedir=0xc0150008]
18371694.598: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004a4 pwszName=\Device\HarddiskVolume2\Windows\System32\ddraw.dll
18381694.598: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
18391694.598: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
18401694.598: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=24C763EA54CD792A0F1618411061DC356EE31FF6
18411694.598: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\ddraw.dll'
18421694.598: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
18431694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
18441694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
18451694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'dciman32.dll'.
18461694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
18471694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'setupapi.dll'.
18481694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'dwmapi.dll'.
18491694.598: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ddraw.dll) WinVerifyTrust
18501694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ddraw.dll
18511694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'glu32.dll'...
18521694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'glu32.dll' -> '\Device\HarddiskVolume2\Windows\System32\glu32.dll' [rcNtRedir=0xc0150008]
18531694.598: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000490 pwszName=\Device\HarddiskVolume2\Windows\System32\glu32.dll
18541694.598: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
18551694.598: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
18561694.598: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=60E45AB914E06A11F44EA76C6EF750AF892F9EA2
18571694.598: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\glu32.dll'
18581694.598: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
18591694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
18601694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'opengl32.dll'.
18611694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
18621694.598: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\glu32.dll) WinVerifyTrust
18631694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\glu32.dll
18641694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
18651694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
18661694.598: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll
18671694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
18681694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
18691694.598: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
18701694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
18711694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
18721694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
18731694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
18741694.598: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
18751694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
18761694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
18771694.598: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
18781694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mpr.dll'...
18791694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'mpr.dll' -> '\Device\HarddiskVolume2\Windows\System32\mpr.dll' [rcNtRedir=0xc0150008]
18801694.598: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004c4 pwszName=\Device\HarddiskVolume2\Windows\System32\mpr.dll
18811694.598: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
18821694.598: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
18831694.598: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F84FE9BA047B24E7694C9E0C349B48B9FD5F925B
18841694.598: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\mpr.dll'
18851694.598: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
18861694.598: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\mpr.dll) WinVerifyTrust
18871694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\mpr.dll
18881694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
18891694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
18901694.598: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
18911694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
18921694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
18931694.598: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
18941694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
18951694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
18961694.598: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
18971694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
18981694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
18991694.598: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
19001694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
19011694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
19021694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
19031694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
19041694.598: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
19051694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
19061694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
19071694.598: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
19081694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
19091694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
19101694.598: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
19111694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
19121694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
19131694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
19141694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
19151694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
19161694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
19171694.598: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
19181694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
19191694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
19201694.598: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
19211694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
19221694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
19231694.598: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
19241694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
19251694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
19261694.598: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
19271694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
19281694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
19291694.598: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
19301694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
19311694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
19321694.598: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
19331694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
19341694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
19351694.598: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
19361694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
19371694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
19381694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
19391694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
19401694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
19411694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
19421694.598: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
19431694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comdlg32.dll'...
19441694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'comdlg32.dll' -> '\Device\HarddiskVolume2\Windows\System32\comdlg32.dll' [rcNtRedir=0xc0150008]
19451694.598: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004b4 pwszName=\Device\HarddiskVolume2\Windows\System32\comdlg32.dll
19461694.598: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
19471694.598: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
19481694.598: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=66EE5BDFFA413AEA9E1FE7838A08646E94136DA5
19491694.598: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\comdlg32.dll'
19501694.598: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
19511694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
19521694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'shlwapi.dll'.
19531694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
19541694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'gdi32.dll'.
19551694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'comctl32.dll'.
19561694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'shell32.dll'.
19571694.598: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\comdlg32.dll) WinVerifyTrust
19581694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\comdlg32.dll
19591694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winspool.drv'...
19601694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'winspool.drv' -> '\Device\HarddiskVolume2\Windows\System32\winspool.drv' [rcNtRedir=0xc0150008]
19611694.598: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004bc pwszName=\Device\HarddiskVolume2\Windows\System32\winspool.drv
19621694.598: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
19631694.598: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
19641694.598: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=C89A2ED7B99A056D78CA6BAC9CCAB8B1FF119A14
19651694.598: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\winspool.drv'
19661694.598: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
19671694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
19681694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
19691694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
19701694.598: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\winspool.drv) WinVerifyTrust
19711694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\winspool.drv
19721694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
19731694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
19741694.598: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
19751694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
19761694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
19771694.598: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
19781694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
19791694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
19801694.598: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll
19811694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
19821694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
19831694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
19841694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
19851694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
19861694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
19871694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
19881694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
19891694.598: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
19901694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
19911694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
19921694.598: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
19931694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
19941694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
19951694.598: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll
19961694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
19971694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
19981694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
19991694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
20001694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
20011694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
20021694.598: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll
20031694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
20041694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
20051694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
20061694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
20071694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
20081694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
20091694.598: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll
20101694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
20111694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
20121694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
20131694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
20141694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
20151694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
20161694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
20171694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
20181694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
20191694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
20201694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
20211694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
20221694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
20231694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
20241694.598: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
20251694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
20261694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
20271694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
20281694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
20291694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
20301694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
20311694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
20321694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
20331694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
20341694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
20351694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
20361694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
20371694.598: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
20381694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comctl32.dll'...
20391694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'comctl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\comctl32.dll' [rcNtRedir=0x0]
20401694.598: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004dc pwszName=\Device\HarddiskVolume2\Windows\System32\comctl32.dll
20411694.598: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
20421694.598: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
20431694.598: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=761964761EE466757E306124E042F4C2ACBEA092
20441694.598: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3059317~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\Windows\System32\comctl32.dll'
20451694.598: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
20461694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'advapi32.dll'.
20471694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
20481694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
20491694.598: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\comctl32.dll) WinVerifyTrust
20501694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\comctl32.dll
20511694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
20521694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
20531694.598: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll
20541694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
20551694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
20561694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
20571694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
20581694.598: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll
20591694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
20601694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
20611694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
20621694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
20631694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
20641694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
20651694.598: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
20661694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
20671694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
20681694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dwmapi.dll'...
20691694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'dwmapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\dwmapi.dll' [rcNtRedir=0xc0150008]
20701694.598: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004c8 pwszName=\Device\HarddiskVolume2\Windows\System32\dwmapi.dll
20711694.598: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
20721694.598: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
20731694.598: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B79EE7B5AD74EF51A849809202E043183A2C727E
20741694.598: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\dwmapi.dll'
20751694.598: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
20761694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
20771694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
20781694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
20791694.598: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\dwmapi.dll) WinVerifyTrust
20801694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\dwmapi.dll
20811694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
20821694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
20831694.598: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004e8 pwszName=\Device\HarddiskVolume2\Windows\System32\setupapi.dll
20841694.598: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
20851694.598: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
20861694.598: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=1499C4FEA6E143F9BEC35B4FFA098917D3A6EBF2
20871694.598: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\setupapi.dll'
20881694.598: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
20891694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'cfgmgr32.dll'.
20901694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcrt.dll'.
20911694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'gdi32.dll'.
20921694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
20931694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'user32.dll'.
20941694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'oleaut32.dll'.
20951694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'devobj.dll'.
20961694.598: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\setupapi.dll) WinVerifyTrust
20971694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\setupapi.dll
20981694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
20991694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
21001694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dciman32.dll'...
21011694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'dciman32.dll' -> '\Device\HarddiskVolume2\Windows\System32\dciman32.dll' [rcNtRedir=0xc0150008]
21021694.598: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004cc pwszName=\Device\HarddiskVolume2\Windows\System32\dciman32.dll
21031694.598: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
21041694.598: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
21051694.598: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=66AD59F39F40705A9BA47254FA40331C3501DB8F
21061694.598: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_413_for_KB4034664~31bf3856ad364e35~amd64~~6.1.1.4.cat'; file='\Device\HarddiskVolume2\Windows\System32\dciman32.dll'
21071694.598: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
21081694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
21091694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'gdi32.dll'.
21101694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
21111694.598: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\dciman32.dll) WinVerifyTrust
21121694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\dciman32.dll
21131694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
21141694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
21151694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
21161694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
21171694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
21181694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
21191694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
21201694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
21211694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
21221694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
21231694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'devobj.dll'...
21241694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'devobj.dll' -> '\Device\HarddiskVolume2\Windows\System32\devobj.dll' [rcNtRedir=0xc0150008]
21251694.598: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004d4 pwszName=\Device\HarddiskVolume2\Windows\System32\devobj.dll
21261694.598: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
21271694.598: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
21281694.598: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B410A095222E69F0ECE7D66E4AC27A7125D2EB5A
21291694.598: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\devobj.dll'
21301694.598: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
21311694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
21321694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'cfgmgr32.dll'.
21331694.598: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\devobj.dll) WinVerifyTrust
21341694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\devobj.dll
21351694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
21361694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
21371694.598: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
21381694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
21391694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
21401694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
21411694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
21421694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
21431694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
21441694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
21451694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
21461694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
21471694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
21481694.598: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004f4 pwszName=\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll
21491694.598: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
21501694.598: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
21511694.598: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=8F731777EFC4BC982C1E1467FBF29A74CC14D93A
21521694.598: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll'
21531694.598: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
21541694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
21551694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'rpcrt4.dll'.
21561694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
21571694.598: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll) WinVerifyTrust
21581694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll
21591694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
21601694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
21611694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
21621694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
21631694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
21641694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
21651694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
21661694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
21671694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
21681694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
21691694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
21701694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
21711694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
21721694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
21731694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
21741694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
21751694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
21761694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
21771694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
21781694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
21791694.598: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll
21801694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
21811694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
21821694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VirtualBox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ac411:<flags> [calling]
21831694.598: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.dll
21841694.598: supR3HardenedDllNotificationCallback: load 000007feecf50000 LB 0x008ea000 C:\Program Files\Oracle\VirtualBox\VirtualBox.dll [fFlags=0x0]
21851694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.dll
21861694.598: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
21871694.598: supR3HardenedDllNotificationCallback: load 000007feece30000 LB 0x0011d000 C:\Windows\system32\OPENGL32.dll [fFlags=0x0]
21881694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
21891694.598: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\glu32.dll
21901694.598: supR3HardenedDllNotificationCallback: load 000007fef5930000 LB 0x0002d000 C:\Windows\system32\GLU32.dll [fFlags=0x0]
21911694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\glu32.dll
21921694.598: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ddraw.dll
21931694.598: supR3HardenedDllNotificationCallback: load 000007feecd30000 LB 0x000f1000 C:\Windows\system32\DDRAW.dll [fFlags=0x0]
21941694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ddraw.dll
21951694.598: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dciman32.dll
21961694.598: supR3HardenedDllNotificationCallback: load 000007fef5dd0000 LB 0x00008000 C:\Windows\system32\DCIMAN32.dll [fFlags=0x0]
21971694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dciman32.dll
21981694.598: supR3HardenedDllNotificationCallback: load 000007fefd800000 LB 0x001d7000 C:\Windows\system32\SETUPAPI.dll [fFlags=0x0]
21991694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\setupapi.dll
22001694.598: supR3HardenedDllNotificationCallback: load 000007fefd2e0000 LB 0x00036000 C:\Windows\system32\CFGMGR32.dll [fFlags=0x0]
22011694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll
22021694.598: supR3HardenedDllNotificationCallback: load 000007fefef90000 LB 0x000da000 C:\Windows\system32\OLEAUT32.dll [fFlags=0x0]
22031694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
22041694.598: supR3HardenedDllNotificationCallback: load 000007fefe810000 LB 0x001fc000 C:\Windows\system32\ole32.dll [fFlags=0x0]
22051694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
22061694.598: supR3HardenedDllNotificationCallback: load 000007fefd120000 LB 0x0001a000 C:\Windows\system32\DEVOBJ.dll [fFlags=0x0]
22071694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\devobj.dll
22081694.598: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dwmapi.dll
22091694.598: supR3HardenedDllNotificationCallback: load 000007fefb120000 LB 0x00018000 C:\Windows\system32\dwmapi.dll [fFlags=0x0]
22101694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dwmapi.dll
22111694.598: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
22121694.598: supR3HardenedDllNotificationCallback: load 000000005d9b0000 LB 0x00565000 C:\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [fFlags=0x0]
22131694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
22141694.598: supR3HardenedDllNotificationCallback: load 000007fefd9e0000 LB 0x00d8b000 C:\Windows\system32\SHELL32.dll [fFlags=0x0]
22151694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
22161694.598: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\mpr.dll
22171694.598: supR3HardenedDllNotificationCallback: load 000007fef47c0000 LB 0x00018000 C:\Windows\system32\MPR.dll [fFlags=0x0]
22181694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\mpr.dll
22191694.598: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
22201694.598: supR3HardenedDllNotificationCallback: load 000007feec730000 LB 0x005f7000 C:\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll [fFlags=0x0]
22211694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
22221694.598: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll
22231694.598: supR3HardenedDllNotificationCallback: load 000000005d440000 LB 0x00561000 C:\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll [fFlags=0x0]
22241694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll
22251694.598: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5PrintSupportVBox.dll
22261694.598: supR3HardenedDllNotificationCallback: load 000007feec6d0000 LB 0x00051000 C:\Program Files\Oracle\VirtualBox\Qt5PrintSupportVBox.dll [fFlags=0x0]
22271694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5PrintSupportVBox.dll
22281694.598: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winspool.drv
22291694.598: supR3HardenedDllNotificationCallback: load 000007fef9cd0000 LB 0x00071000 C:\Windows\system32\WINSPOOL.DRV [fFlags=0x0]
22301694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winspool.drv
22311694.598: supR3HardenedDllNotificationCallback: load 000007fefd6b0000 LB 0x00097000 C:\Windows\system32\COMDLG32.dll [fFlags=0x0]
22321694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\comdlg32.dll
22331694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'advapi32.dll'.
22341694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
22351694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
22361694.598: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll)
22371694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll
22381694.598: supR3HardenedDllNotificationCallback: load 000007fef9d50000 LB 0x000a0000 C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\COMCTL32.dll [fFlags=0x0]
22391694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll [avoiding WinVerifyTrust]
22401694.598: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll
22411694.598: supR3HardenedDllNotificationCallback: load 000000005ce30000 LB 0x00054000 C:\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll [fFlags=0x0]
22421694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll
22431694.598: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
22441694.598: supR3HardenedDllNotificationCallback: load 000007fefafa0000 LB 0x0003b000 C:\Windows\system32\WINMM.dll [fFlags=0x0]
22451694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
22461694.598: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume2\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll'.
22471694.598: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll' [rescheduled]
22481694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\imm32.dll
22491694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
22501694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
22511694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
22521694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
22531694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
22541694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
22551694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\imm32.dll (Input=imm32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ab9e1:<flags> [calling]
22561694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd750000 'C:\Windows\system32\imm32.dll'
22571694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd450000 'C:\Windows\system32\ADVAPI32.DLL'
22581694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cryptbase.dll
22591694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptbase.dll (Input=cryptbase.dll, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
22601694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefce10000 'C:\Windows\system32\cryptbase.dll'
22611694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feecf50000 'C:\Program Files\Oracle\VirtualBox\VirtualBox.dll'
22621694.598: SUPR3HardenedMain: Calling TrustedMain (000007feecf51610)...
22631694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
22641694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ole32.dll (Input=ole32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001add51:<flags> [calling]
22651694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe810000 'C:\Windows\system32\ole32.dll'
22661694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd450000 'C:\Windows\system32\ADVAPI32.dll'
22671694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\profapi.dll
22681694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\profapi.dll (Input=profapi.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ac431:<flags> [calling]
22691694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcf80000 'C:\Windows\system32\profapi.dll'
22701694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
22711694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'ole32.dll'.
22721694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
22731694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'imm32.dll'.
22741694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'winmm.dll'.
22751694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
22761694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'shell32.dll'.
22771694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'advapi32.dll'.
22781694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'qt5guivbox.dll'.
22791694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'qt5corevbox.dll'.
22801694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'msvcr100.dll'.
22811694.598: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\platforms\qwindows.dll) WinVerifyTrust
22821694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\platforms\qwindows.dll
22831694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
22841694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
22851694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
22861694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
22871694.598: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
22881694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
22891694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
22901694.598: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
22911694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
22921694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
22931694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
22941694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
22951694.598: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
22961694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
22971694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
22981694.598: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
22991694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
23001694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
23011694.598: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
23021694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
23031694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume2\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
23041694.598: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\imm32.dll
23051694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
23061694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
23071694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
23081694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
23091694.598: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
23101694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
23111694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
23121694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\platforms\qwindows.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ae721:<flags> [calling]
23131694.598: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\platforms\qwindows.dll
23141694.598: supR3HardenedDllNotificationCallback: load 000007feec5a0000 LB 0x0012e000 C:\Program Files\Oracle\VirtualBox\platforms\qwindows.dll [fFlags=0x0]
23151694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\platforms\qwindows.dll
23161694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec5a0000 'C:\Program Files\Oracle\VirtualBox\platforms\qwindows.dll'
23171694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cryptbase.dll
23181694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTBASE.dll (Input=CRYPTBASE.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ae651:<flags> [calling]
23191694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefce10000 'C:\Windows\system32\CRYPTBASE.dll'
23201694.598: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000588 pwszName=\Device\HarddiskVolume2\Windows\System32\uxtheme.dll
23211694.598: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
23221694.598: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
23231694.598: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=936D45CC7026757A151F62882B557DD75D5FCB21
23241694.598: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\uxtheme.dll'
23251694.598: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
23261694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
23271694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
23281694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'gdi32.dll'.
23291694.598: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\uxtheme.dll) WinVerifyTrust
23301694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
23311694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
23321694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
23331694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
23341694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
23351694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
23361694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
23371694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ae121:<flags> [calling]
23381694.598: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
23391694.598: supR3HardenedDllNotificationCallback: load 000007fefb530000 LB 0x00056000 C:\Windows\system32\uxtheme.dll [fFlags=0x0]
23401694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
23411694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefb530000 'C:\Windows\system32\uxtheme.dll'
23421694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
23431694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001adb61:<flags> [calling]
23441694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefb530000 'C:\Windows\system32\uxtheme.dll'
23451694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
23461694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ad8d1:<flags> [calling]
23471694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefb530000 'C:\Windows\system32\uxtheme.dll'
23481694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
23491694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ad8d1:<flags> [calling]
23501694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefb530000 'C:\Windows\system32\uxtheme.dll'
23511694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077180000 'C:\Windows\system32\user32.dll'
23521694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
23531694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ae961:<flags> [calling]
23541694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd9e0000 'C:\Windows\system32\shell32.dll'
23551694.598: supR3HardenedMonitor_LdrLoadDll: error opening 'C:\Windows\system32\wintab32.dll': 0 (NtPath=\??\C:\Windows\system32\wintab32.dll; Input=C:\Windows\system32\wintab32.dll; rcNtGetDll=0x0
23561694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wintab32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ae841:<flags> [calling]
23571694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000135 'C:\Windows\system32\wintab32.dll'
23581694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dwmapi.dll
23591694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\dwmapi.dll (Input=dwmapi.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ae001:<flags> [calling]
23601694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefb120000 'C:\Windows\system32\dwmapi.dll'
23611694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
23621694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\winmm.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001aed81:<flags> [calling]
23631694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefafa0000 'C:\Windows\system32\winmm.dll'
23641694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
23651694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\winmm.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001aed81:<flags> [calling]
23661694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefafa0000 'C:\Windows\system32\winmm.dll'
23671694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
23681694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001af061:<flags> [calling]
23691694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd9e0000 'C:\Windows\system32\shell32.dll'
23701694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
23711694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001af031:<flags> [calling]
23721694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefb530000 'C:\Windows\system32\uxtheme.dll'
23731694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd450000 'C:\Windows\system32\advapi32.dll'
23741694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\userenv.dll
23751694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\userenv.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001aef91:<flags> [calling]
23761694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd100000 'C:\Windows\system32\userenv.dll'
23771694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll
23781694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (Input=kernel32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001af071:<flags> [calling]
23791694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077060000 'C:\Windows\system32\kernel32.dll'
23801694.598: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000005a0 pwszName=\Device\HarddiskVolume2\Windows\System32\clbcatq.dll
23811694.598: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
23821694.598: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
23831694.598: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B01469787CE9D8C6FEE98FB207652B88B8494526
23841694.598: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\clbcatq.dll'
23851694.598: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
23861694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
23871694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'ole32.dll'.
23881694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
23891694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
23901694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
23911694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'rpcrt4.dll'.
23921694.598: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\clbcatq.dll) WinVerifyTrust
23931694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\clbcatq.dll
23941694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
23951694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
23961694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
23971694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
23981694.598: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
23991694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
24001694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
24011694.598: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
24021694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
24031694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
24041694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
24051694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
24061694.598: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
24071694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
24081694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
24091694.598: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
24101694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CLBCatQ.DLL (Input=CLBCatQ.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001abd41:<flags> [calling]
24111694.598: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\clbcatq.dll
24121694.598: supR3HardenedDllNotificationCallback: load 000007feff4d0000 LB 0x00099000 C:\Windows\system32\CLBCatQ.DLL [fFlags=0x0]
24131694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\clbcatq.dll
24141694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff4d0000 'C:\Windows\system32\CLBCatQ.DLL'
24151694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd450000 'C:\Windows\system32\ADVAPI32.dll'
24161694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cryptsp.dll
24171694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTSP.dll (Input=CRYPTSP.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001aab91:<flags> [calling]
24181694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc7a0000 'C:\Windows\system32\CRYPTSP.dll'
24191694.598: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000005d8 pwszName=\Device\HarddiskVolume2\Windows\System32\RpcRtRemote.dll
24201694.598: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
24211694.598: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
24221694.598: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=DFC4A7C7E103D324218E6EF5D219B953746D6EC1
24231694.598: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\RpcRtRemote.dll'
24241694.598: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
24251694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'rpcrt4.dll'.
24261694.598: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\RpcRtRemote.dll) WinVerifyTrust
24271694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\RpcRtRemote.dll
24281694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
24291694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
24301694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\RpcRtRemote.dll (Input=RpcRtRemote.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001aa751:<flags> [calling]
24311694.598: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\RpcRtRemote.dll
24321694.598: supR3HardenedDllNotificationCallback: load 000007fefcec0000 LB 0x00014000 C:\Windows\system32\RpcRtRemote.dll [fFlags=0x0]
24331694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\RpcRtRemote.dll
24341694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcec0000 'C:\Windows\system32\RpcRtRemote.dll'
24351694.1138: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
24361694.1138: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
24371694.1138: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
24381694.1138: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
24391694.1138: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ole32.dll'.
24401694.1138: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'oleaut32.dll'.
24411694.1138: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxC.dll) WinVerifyTrust
24421694.1138: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxC.dll
24431694.1138: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
24441694.1138: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
24451694.1138: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
24461694.1138: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
24471694.1138: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
24481694.1138: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
24491694.1138: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
24501694.1138: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
24511694.1138: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
24521694.1138: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
24531694.1138: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
24541694.1138: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
24551694.1138: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
24561694.1138: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
24571694.1138: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
24581694.1138: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxC.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000497e4f1:<flags> [calling]
24591694.1138: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxC.dll
24601694.1138: supR3HardenedDllNotificationCallback: load 000007feebfe0000 LB 0x004f6000 C:\Program Files\Oracle\VirtualBox\VBoxC.dll [fFlags=0x0]
24611694.1138: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxC.dll
24621694.1138: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feebfe0000 'C:\Program Files\Oracle\VirtualBox\VBoxC.dll'
24631694.1138: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
24641694.1138: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
24651694.1138: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
24661694.1138: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'shlwapi.dll'.
24671694.1138: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ole32.dll'.
24681694.1138: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'oleaut32.dll'.
24691694.1138: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
24701694.1138: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll) WinVerifyTrust
24711694.1138: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll
24721694.1138: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
24731694.1138: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
24741694.1138: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
24751694.1138: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
24761694.1138: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
24771694.1138: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
24781694.1138: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
24791694.1138: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
24801694.1138: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
24811694.1138: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll
24821694.1138: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
24831694.1138: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
24841694.1138: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
24851694.1138: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
24861694.1138: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
24871694.1138: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
24881694.1138: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000497cf91:<flags> [calling]
24891694.1138: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll
24901694.1138: supR3HardenedDllNotificationCallback: load 000007feec4e0000 LB 0x000b5000 C:\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll [fFlags=0x0]
24911694.1138: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll
24921694.1138: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec4e0000 'C:\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll'
24931694.1138: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
24941694.1138: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\oleaut32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000497ce21:<flags> [calling]
24951694.1138: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefef90000 'C:\Windows\system32\oleaut32.dll'
24961694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd450000 'C:\Windows\system32\ADVAPI32.dll'
24971694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd780000 'C:\Windows\system32\gdi32.dll'
24981694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
24991694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001aab51:<flags> [calling]
25001694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd9e0000 'C:\Windows\system32\shell32.dll'
25011694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd450000 'C:\Windows\system32\ADVAPI32.dll'
25021694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe810000 'C:\Windows\system32\ole32.dll'
25031694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd9e0000 'C:\Windows\system32\shell32.dll'
25041694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd9e0000 'C:\Windows\system32\shell32.dll'
25051694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe810000 'C:\Windows\system32\ole32.dll'
25061694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
25071694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\OLEAUT32.dll (Input=OLEAUT32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001a7f61:<flags> [calling]
25081694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefef90000 'C:\Windows\system32\OLEAUT32.dll'
25091694.598: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000092c pwszName=\Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll
25101694.598: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
25111694.598: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
25121694.598: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=41D7AA7A9ECA84ABF6801478BA3134174B21C472
25131694.598: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll'
25141694.598: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
25151694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
25161694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'wbemcomn.dll'.
25171694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
25181694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
25191694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ole32.dll'.
25201694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'ws2_32.dll'.
25211694.598: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll) WinVerifyTrust
25221694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll
25231694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
25241694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
25251694.598: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
25261694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
25271694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
25281694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
25291694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
25301694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
25311694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
25321694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wbemcomn.dll'...
25331694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'wbemcomn.dll' -> '\Device\HarddiskVolume2\Windows\System32\wbemcomn.dll' [rcNtRedir=0xc0150008]
25341694.598: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000930 pwszName=\Device\HarddiskVolume2\Windows\System32\wbemcomn.dll
25351694.598: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
25361694.598: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
25371694.598: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=03D0A77E5195AA70198FDE6C2FAC2C76FF200674
25381694.598: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\wbemcomn.dll'
25391694.598: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
25401694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
25411694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'oleaut32.dll'.
25421694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'ole32.dll'.
25431694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
25441694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ws2_32.dll'.
25451694.598: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\wbemcomn.dll) WinVerifyTrust
25461694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wbemcomn.dll
25471694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
25481694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
25491694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
25501694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
25511694.598: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
25521694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
25531694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
25541694.598: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll
25551694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
25561694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
25571694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
25581694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
25591694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
25601694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
25611694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wbem\wbemprox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001a67f1:<flags> [calling]
25621694.598: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll
25631694.598: supR3HardenedDllNotificationCallback: load 000007fef7d80000 LB 0x0000f000 C:\Windows\system32\wbem\wbemprox.dll [fFlags=0x0]
25641694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll
25651694.598: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbemcomn.dll
25661694.598: supR3HardenedDllNotificationCallback: load 000007fef7f30000 LB 0x00086000 C:\Windows\system32\wbemcomn.dll [fFlags=0x0]
25671694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbemcomn.dll
25681694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef7d80000 'C:\Windows\system32\wbem\wbemprox.dll'
25691694.598: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000958 pwszName=\Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll
25701694.598: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
25711694.598: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
25721694.598: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=83AB88529BF28CFF670EA617E0B9C376CFE28B0F
25731694.598: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll'
25741694.598: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
25751694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
25761694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'rpcrt4.dll'.
25771694.598: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll) WinVerifyTrust
25781694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll
25791694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
25801694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
25811694.598: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
25821694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
25831694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
25841694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wbem\wbemsvc.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001a6431:<flags> [calling]
25851694.598: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll
25861694.598: supR3HardenedDllNotificationCallback: load 000007fef7390000 LB 0x00014000 C:\Windows\system32\wbem\wbemsvc.dll [fFlags=0x0]
25871694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll
25881694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef7390000 'C:\Windows\system32\wbem\wbemsvc.dll'
25891694.598: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000964 pwszName=\Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll
25901694.598: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
25911694.598: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
25921694.598: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=391AD7580DBA8EA6A4190F5A010E834B8C320D79
25931694.598: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll'
25941694.598: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
25951694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
25961694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'wbemcomn.dll'.
25971694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
25981694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'oleaut32.dll'.
25991694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ole32.dll'.
26001694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ntdsapi.dll'.
26011694.598: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll) WinVerifyTrust
26021694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll
26031694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntdsapi.dll'...
26041694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntdsapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\ntdsapi.dll' [rcNtRedir=0xc0150008]
26051694.598: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000094c pwszName=\Device\HarddiskVolume2\Windows\System32\ntdsapi.dll
26061694.598: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
26071694.598: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
26081694.598: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=67C74E045820FCAB3FC8AD5C180928A20C1F11CE
26091694.598: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\ntdsapi.dll'
26101694.598: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
26111694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
26121694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'rpcrt4.dll'.
26131694.598: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'ws2_32.dll'.
26141694.598: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ntdsapi.dll) WinVerifyTrust
26151694.598: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ntdsapi.dll
26161694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
26171694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
26181694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
26191694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
26201694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
26211694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
26221694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wbemcomn.dll'...
26231694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'wbemcomn.dll' -> '\Device\HarddiskVolume2\Windows\System32\wbemcomn.dll' [rcNtRedir=0xc0150008]
26241694.598: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbemcomn.dll
26251694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
26261694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
26271694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
26281694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
26291694.598: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
26301694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
26311694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
26321694.598: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
26331694.598: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
26341694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wbem\fastprox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001a6471:<flags> [calling]
26351694.598: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll
26361694.598: supR3HardenedDllNotificationCallback: load 000007fef7dc0000 LB 0x000e2000 C:\Windows\system32\wbem\fastprox.dll [fFlags=0x0]
26371694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll
26381694.598: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ntdsapi.dll
26391694.598: supR3HardenedDllNotificationCallback: load 000007fef7d90000 LB 0x00027000 C:\Windows\system32\NTDSAPI.dll [fFlags=0x0]
26401694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ntdsapi.dll
26411694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef7dc0000 'C:\Windows\system32\wbem\fastprox.dll'
26421694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefef90000 'C:\Windows\system32\OLEAUT32.dll'
26431694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
26441694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\WINMM.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001a6261:<flags> [calling]
26451694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefafa0000 'C:\Windows\system32\WINMM.dll'
26461694.1160: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
26471694.1160: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrem.dll'.
26481694.1160: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
26491694.1160: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll) WinVerifyTrust
26501694.1160: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
26511694.1160: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
26521694.1160: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
26531694.1160: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrem.dll'...
26541694.1160: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrem.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrem.dll' [rcNtRedir=0xc0150008]
26551694.1160: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'vboxrt.dll'.
26561694.1160: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
26571694.1160: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcrt.dll'.
26581694.1160: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxREM.dll) WinVerifyTrust
26591694.1160: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxREM.dll
26601694.1160: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
26611694.1160: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
26621694.1160: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
26631694.1160: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
26641694.1160: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
26651694.1160: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
26661694.1160: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
26671694.1160: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
26681694.1160: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
26691694.1160: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000079ce421:<flags> [calling]
26701694.1160: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
26711694.1160: supR3HardenedDllNotificationCallback: load 000007feea510000 LB 0x002b5000 C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL [fFlags=0x0]
26721694.1160: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
26731694.1160: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxREM.dll
26741694.1160: supR3HardenedDllNotificationCallback: load 000000005c730000 LB 0x0010b000 C:\Program Files\Oracle\VirtualBox\VBoxREM.dll [fFlags=0x0]
26751694.1160: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxREM.dll
26761694.1160: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feea510000 'C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL'
26771694.654: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
26781694.654: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
26791694.654: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
26801694.654: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
26811694.654: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll) WinVerifyTrust
26821694.654: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll
26831694.654: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
26841694.654: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
26851694.654: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
26861694.654: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
26871694.654: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
26881694.654: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
26891694.654: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
26901694.654: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
26911694.654: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
26921694.654: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000007d7d9c1:<flags> [calling]
26931694.654: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll
26941694.654: supR3HardenedDllNotificationCallback: load 000007fef5dc0000 LB 0x0000b000 C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL [fFlags=0x0]
26951694.654: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll
26961694.654: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef5dc0000 'C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL'
26971694.654: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077180000 'C:\Windows\system32\User32.dll'
26981694.ec4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
26991694.ec4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
27001694.ec4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
27011694.ec4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll) WinVerifyTrust
27021694.ec4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll
27031694.ec4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
27041694.ec4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
27051694.ec4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
27061694.ec4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
27071694.ec4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
27081694.ec4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
27091694.ec4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
27101694.ec4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000828dad1:<flags> [calling]
27111694.ec4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll
27121694.ec4: supR3HardenedDllNotificationCallback: load 000007fef5d70000 LB 0x0000d000 C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL [fFlags=0x0]
27131694.ec4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll
27141694.ec4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef5d70000 'C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL'
27151694.378: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
27161694.378: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
27171694.378: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
27181694.378: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll) WinVerifyTrust
27191694.378: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll
27201694.378: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
27211694.378: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
27221694.378: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
27231694.378: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
27241694.378: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
27251694.378: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
27261694.378: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
27271694.378: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000084edbd1:<flags> [calling]
27281694.378: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll
27291694.378: supR3HardenedDllNotificationCallback: load 000007fef5d60000 LB 0x0000c000 C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL [fFlags=0x0]
27301694.378: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll
27311694.378: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef5d60000 'C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL'
27321694.f94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
27331694.f94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
27341694.f94: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
27351694.f94: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll) WinVerifyTrust
27361694.f94: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll
27371694.f94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
27381694.f94: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
27391694.f94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
27401694.f94: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
27411694.f94: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
27421694.f94: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
27431694.f94: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000087adb31:<flags> [calling]
27441694.f94: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll
27451694.f94: supR3HardenedDllNotificationCallback: load 000007fef58e0000 LB 0x0000b000 C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL [fFlags=0x0]
27461694.f94: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll
27471694.f94: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef58e0000 'C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL'
27481694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd9e0000 'C:\Windows\system32\Shell32.dll'
27491694.124c: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000007b59371:<flags> [calling]
27501694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe7f0000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
27511694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
27521694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
27531694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
27541694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vboxddu.dll'.
27551694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'vboxdd2.dll'.
27561694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
27571694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'setupapi.dll'.
27581694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'ws2_32.dll'.
27591694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'ole32.dll'.
27601694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'iphlpapi.dll'.
27611694.124c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD.dll) WinVerifyTrust
27621694.124c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD.dll
27631694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'iphlpapi.dll'...
27641694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'iphlpapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\iphlpapi.dll' [rcNtRedir=0xc0150008]
27651694.124c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000be4 pwszName=\Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL
27661694.124c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
27671694.124c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
27681694.124c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=3BDC72529DA09BA841BE702C4C902C8AA1242642
27691694.124c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL'
27701694.124c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
27711694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
27721694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'nsi.dll'.
27731694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'winnsi.dll'.
27741694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'rpcrt4.dll'.
27751694.124c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL) WinVerifyTrust
27761694.124c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL
27771694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
27781694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
27791694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
27801694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
27811694.124c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
27821694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
27831694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
27841694.124c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\setupapi.dll
27851694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
27861694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
27871694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxdd2.dll'...
27881694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxdd2.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxdd2.dll' [rcNtRedir=0xc0150008]
27891694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
27901694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
27911694.124c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD2.dll) WinVerifyTrust
27921694.124c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD2.dll
27931694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxddu.dll'...
27941694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxddu.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxddu.dll' [rcNtRedir=0xc0150008]
27951694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
27961694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
27971694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
27981694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'setupapi.dll'.
27991694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'advapi32.dll'.
28001694.124c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDDU.dll) WinVerifyTrust
28011694.124c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDDU.dll
28021694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
28031694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
28041694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
28051694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
28061694.124c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
28071694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
28081694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
28091694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
28101694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
28111694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
28121694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
28131694.124c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\setupapi.dll
28141694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
28151694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
28161694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
28171694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
28181694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
28191694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
28201694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
28211694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
28221694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
28231694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
28241694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
28251694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
28261694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winnsi.dll'...
28271694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'winnsi.dll' -> '\Device\HarddiskVolume2\Windows\System32\winnsi.dll' [rcNtRedir=0xc0150008]
28281694.124c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000bec pwszName=\Device\HarddiskVolume2\Windows\System32\winnsi.dll
28291694.124c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
28301694.124c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
28311694.124c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B28F3E0DF5586B9FB3AEAC48E4ECCA0AFB6ABD91
28321694.124c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\winnsi.dll'
28331694.124c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
28341694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
28351694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'rpcrt4.dll'.
28361694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'nsi.dll'.
28371694.124c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\winnsi.dll) WinVerifyTrust
28381694.124c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\winnsi.dll
28391694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
28401694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume2\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
28411694.124c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\nsi.dll
28421694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
28431694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
28441694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
28451694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume2\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
28461694.124c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\nsi.dll
28471694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
28481694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
28491694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
28501694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
28511694.124c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxDD.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000007b5d861:<flags> [calling]
28521694.124c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD.dll
28531694.124c: supR3HardenedDllNotificationCallback: load 000007fee9b60000 LB 0x009ae000 C:\Program Files\Oracle\VirtualBox\VBoxDD.DLL [fFlags=0x0]
28541694.124c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD.dll
28551694.124c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDDU.dll
28561694.124c: supR3HardenedDllNotificationCallback: load 000007feebf80000 LB 0x00058000 C:\Program Files\Oracle\VirtualBox\VBoxDDU.dll [fFlags=0x0]
28571694.124c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDDU.dll
28581694.124c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD2.dll
28591694.124c: supR3HardenedDllNotificationCallback: load 000007feeba70000 LB 0x0005d000 C:\Program Files\Oracle\VirtualBox\VBoxDD2.dll [fFlags=0x0]
28601694.124c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD2.dll
28611694.124c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL
28621694.124c: supR3HardenedDllNotificationCallback: load 000007fef98e0000 LB 0x00027000 C:\Windows\system32\IPHLPAPI.DLL [fFlags=0x0]
28631694.124c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL
28641694.124c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winnsi.dll
28651694.124c: supR3HardenedDllNotificationCallback: load 000007fef98d0000 LB 0x0000b000 C:\Windows\system32\WINNSI.DLL [fFlags=0x0]
28661694.124c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winnsi.dll
28671694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee9b60000 'C:\Program Files\Oracle\VirtualBox\VBoxDD.DLL'
28681694.124c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxC.dll
28691694.124c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxC.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000007b5d861:<flags> [calling]
28701694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feebfe0000 'C:\Program Files\Oracle\VirtualBox\VBoxC.DLL'
28711694.124c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD2.dll
28721694.124c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxDD2.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000007b5d771:<flags> [calling]
28731694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeba70000 'C:\Program Files\Oracle\VirtualBox\VBoxDD2.DLL'
28741694.17b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
28751694.17b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
28761694.17b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
28771694.17b0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll) WinVerifyTrust
28781694.17b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll
28791694.17b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
28801694.17b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
28811694.17b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
28821694.17b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
28831694.17b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
28841694.17b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
28851694.17b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
28861694.17b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000cfbdb91:<flags> [calling]
28871694.17b0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll
28881694.17b0: supR3HardenedDllNotificationCallback: load 000007fef58d0000 LB 0x0000d000 C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL [fFlags=0x0]
28891694.17b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll
28901694.17b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef58d0000 'C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL'
28911694.124c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL
28921694.124c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\Iphlpapi.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000007b5d6a1:<flags> [calling]
28931694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef98e0000 'C:\Windows\system32\Iphlpapi.dll'
28941694.124c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000cfc pwszName=\Device\HarddiskVolume2\Windows\System32\dhcpcsvc.dll
28951694.124c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
28961694.124c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
28971694.124c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=D89E2D6AED9A19082ECA108BEEF81A904C7A9756
28981694.124c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\dhcpcsvc.dll'
28991694.124c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
29001694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
29011694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'rpcrt4.dll'.
29021694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ws2_32.dll'.
29031694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'nsi.dll'.
29041694.124c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\dhcpcsvc.dll) WinVerifyTrust
29051694.124c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\dhcpcsvc.dll
29061694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
29071694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume2\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
29081694.124c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\nsi.dll
29091694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
29101694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
29111694.124c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
29121694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
29131694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
29141694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
29151694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
29161694.124c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\dhcpcsvc.DLL (Input=dhcpcsvc.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000007b5e841:<flags> [calling]
29171694.124c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dhcpcsvc.dll
29181694.124c: supR3HardenedDllNotificationCallback: load 000007fef96e0000 LB 0x00018000 C:\Windows\system32\dhcpcsvc.DLL [fFlags=0x0]
29191694.124c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dhcpcsvc.dll
29201694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef96e0000 'C:\Windows\system32\dhcpcsvc.DLL'
29211694.124c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL
29221694.124c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\IPHLPAPI.DLL (Input=IPHLPAPI.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000007b5e4a1:<flags> [calling]
29231694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef98e0000 'C:\Windows\system32\IPHLPAPI.DLL'
29241694.124c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000d14 pwszName=\Device\HarddiskVolume2\Windows\System32\dhcpcsvc6.dll
29251694.124c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
29261694.124c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
29271694.124c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=3B9B444EEE6F858BAE572BDDE53A4FA1A1E7957B
29281694.124c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\dhcpcsvc6.dll'
29291694.124c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
29301694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
29311694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'rpcrt4.dll'.
29321694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ws2_32.dll'.
29331694.124c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\dhcpcsvc6.dll) WinVerifyTrust
29341694.124c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\dhcpcsvc6.dll
29351694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
29361694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
29371694.124c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
29381694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
29391694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
29401694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
29411694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
29421694.124c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\dhcpcsvc6.DLL (Input=dhcpcsvc6.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000007b5e7f1:<flags> [calling]
29431694.124c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dhcpcsvc6.dll
29441694.124c: supR3HardenedDllNotificationCallback: load 000007fef96c0000 LB 0x00011000 C:\Windows\system32\dhcpcsvc6.DLL [fFlags=0x0]
29451694.124c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dhcpcsvc6.dll
29461694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef96c0000 'C:\Windows\system32\dhcpcsvc6.DLL'
29471694.124c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL
29481694.124c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\IPHLPAPI.DLL (Input=IPHLPAPI.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000007b5e511:<flags> [calling]
29491694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef98e0000 'C:\Windows\system32\IPHLPAPI.DLL'
29501694.124c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000d8c pwszName=\Device\HarddiskVolume2\Windows\System32\dsound.dll
29511694.124c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
29521694.124c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
29531694.124c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F6C3E3D9F8B48D816E52C31576FFFD4AF86AB813
29541694.124c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\dsound.dll'
29551694.124c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
29561694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
29571694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
29581694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
29591694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ole32.dll'.
29601694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'winmm.dll'.
29611694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'powrprof.dll'.
29621694.124c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\dsound.dll) WinVerifyTrust
29631694.124c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\dsound.dll
29641694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'powrprof.dll'...
29651694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'powrprof.dll' -> '\Device\HarddiskVolume2\Windows\System32\powrprof.dll' [rcNtRedir=0xc0150008]
29661694.124c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000d90 pwszName=\Device\HarddiskVolume2\Windows\System32\powrprof.dll
29671694.124c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
29681694.124c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
29691694.124c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=E0B7DE18787DB24DAD3580634869A9A8FF4AB48F
29701694.124c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\powrprof.dll'
29711694.124c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
29721694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
29731694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'rpcrt4.dll'.
29741694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'setupapi.dll'.
29751694.124c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\powrprof.dll) WinVerifyTrust
29761694.124c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\powrprof.dll
29771694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
29781694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
29791694.124c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
29801694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
29811694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
29821694.124c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
29831694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
29841694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
29851694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
29861694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
29871694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
29881694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
29891694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
29901694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
29911694.124c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\setupapi.dll
29921694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
29931694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
29941694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
29951694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
29961694.124c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000007b5d611:<flags> [calling]
29971694.124c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dsound.dll
29981694.124c: supR3HardenedDllNotificationCallback: load 000007feeb580000 LB 0x00088000 C:\Windows\System32\dsound.dll [fFlags=0x0]
29991694.124c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dsound.dll
30001694.124c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\powrprof.dll
30011694.124c: supR3HardenedDllNotificationCallback: load 000007fefbdb0000 LB 0x0002c000 C:\Windows\System32\POWRPROF.dll [fFlags=0x0]
30021694.124c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\powrprof.dll
30031694.124c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dsound.dll
30041694.124c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000007b5c981:<flags> [calling]
30051694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeb580000 'C:\Windows\System32\dsound.dll'
30061694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeb580000 'C:\Windows\System32\dsound.dll'
30071694.124c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dsound.dll
30081694.124c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000007b5d6f1:<flags> [calling]
30091694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeb580000 'C:\Windows\system32\dsound.dll'
30101694.124c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000d94 pwszName=\Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
30111694.124c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
30121694.124c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
30131694.124c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=704F97298D44B8146C54067788F597E0BF365197
30141694.124c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll'
30151694.124c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
30161694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
30171694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'user32.dll'.
30181694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'rpcrt4.dll'.
30191694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'propsys.dll'.
30201694.124c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll) WinVerifyTrust
30211694.124c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
30221694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'propsys.dll'...
30231694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'propsys.dll' -> '\Device\HarddiskVolume2\Windows\System32\propsys.dll' [rcNtRedir=0xc0150008]
30241694.124c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000db8 pwszName=\Device\HarddiskVolume2\Windows\System32\propsys.dll
30251694.124c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
30261694.124c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
30271694.124c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=6A1594E841359779EF7EA7EBCF775D89F55388D3
30281694.124c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\propsys.dll'
30291694.124c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
30301694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
30311694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ole32.dll'.
30321694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'oleaut32.dll'.
30331694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'user32.dll'.
30341694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'rpcrt4.dll'.
30351694.124c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\propsys.dll) WinVerifyTrust
30361694.124c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\propsys.dll
30371694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
30381694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
30391694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
30401694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
30411694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
30421694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
30431694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
30441694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
30451694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
30461694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
30471694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
30481694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
30491694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
30501694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
30511694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
30521694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
30531694.124c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\MMDevApi.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000007b5d0e1:<flags> [calling]
30541694.124c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
30551694.124c: supR3HardenedDllNotificationCallback: load 000007fefbd60000 LB 0x0004b000 C:\Windows\System32\MMDevApi.dll [fFlags=0x0]
30561694.124c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
30571694.124c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\propsys.dll
30581694.124c: supR3HardenedDllNotificationCallback: load 000007fefbc30000 LB 0x0012c000 C:\Windows\System32\PROPSYS.dll [fFlags=0x0]
30591694.124c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\propsys.dll
30601694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd450000 'C:\Windows\system32\ADVAPI32.dll'
30611694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbd60000 'C:\Windows\System32\MMDevApi.dll'
30621694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe810000 'C:\Windows\system32\ole32.dll'
30631694.124c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\setupapi.dll
30641694.124c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\SETUPAPI.dll (Input=SETUPAPI.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000007b5d411:<flags> [calling]
30651694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd800000 'C:\Windows\system32\SETUPAPI.dll'
30661694.124c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll
30671694.124c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\SHLWAPI.dll (Input=SHLWAPI.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000007b5e2f1:<flags> [calling]
30681694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd530000 'C:\Windows\system32\SHLWAPI.dll'
30691694.124c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
30701694.124c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\MMDEVAPI.DLL (Input=MMDEVAPI.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000007b5e511:<flags> [calling]
30711694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbd60000 'C:\Windows\system32\MMDEVAPI.DLL'
30721694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe810000 'C:\Windows\system32\ole32.dll'
30731694.1258: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll
30741694.1258: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CFGMGR32.dll (Input=CFGMGR32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000019aff6f1:<flags> [calling]
30751694.1258: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd2e0000 'C:\Windows\system32\CFGMGR32.dll'
30761694.124c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
30771694.124c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\winmm.dll (Input=winmm.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000007b5e141:<flags> [calling]
30781694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefafa0000 'C:\Windows\system32\winmm.dll'
30791694.124c: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-Management-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000007b5dfa1:<flags> [calling]
30801694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe7f0000 'API-MS-WIN-Service-Management-L1-1-0.dll'
30811694.124c: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-winsvc-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000007b5dfa1:<flags> [calling]
30821694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe7f0000 'API-MS-WIN-Service-winsvc-L1-1-0.dll'
30831694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff070000 'C:\Windows\system32\RPCRT4.dll'
30841694.124c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
30851694.124c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\MMDevAPI.DLL (Input=MMDevAPI.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000007b5e001:<flags> [calling]
30861694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbd60000 'C:\Windows\system32\MMDevAPI.DLL'
30871694.124c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000df0 pwszName=\Device\HarddiskVolume2\Windows\System32\wdmaud.drv
30881694.124c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
30891694.124c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
30901694.124c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=4B64306F5558D2DEC53CF11AAF17F02438929FDD
30911694.124c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\wdmaud.drv'
30921694.124c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
30931694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
30941694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
30951694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ole32.dll'.
30961694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'user32.dll'.
30971694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'winmm.dll'.
30981694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'ksuser.dll'.
30991694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'mmdevapi.dll'.
31001694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'avrt.dll'.
31011694.124c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\wdmaud.drv) WinVerifyTrust
31021694.124c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
31031694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'avrt.dll'...
31041694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'avrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\avrt.dll' [rcNtRedir=0xc0150008]
31051694.124c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000df4 pwszName=\Device\HarddiskVolume2\Windows\System32\avrt.dll
31061694.124c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
31071694.124c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
31081694.124c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=1362C343929DD08AB918B38DE195D1A11B1D1365
31091694.124c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\avrt.dll'
31101694.124c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
31111694.124c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\avrt.dll) WinVerifyTrust
31121694.124c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\avrt.dll
31131694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mmdevapi.dll'...
31141694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'mmdevapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\mmdevapi.dll' [rcNtRedir=0xc0150008]
31151694.124c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
31161694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ksuser.dll'...
31171694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ksuser.dll' -> '\Device\HarddiskVolume2\Windows\System32\ksuser.dll' [rcNtRedir=0xc0150008]
31181694.124c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000e10 pwszName=\Device\HarddiskVolume2\Windows\System32\ksuser.dll
31191694.124c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
31201694.124c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
31211694.124c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2D99CFB3BFCA1F454FC7109DB98D18923ABBA361
31221694.124c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_5_for_KB3110329~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\ksuser.dll'
31231694.124c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
31241694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
31251694.124c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ksuser.dll) WinVerifyTrust
31261694.124c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ksuser.dll
31271694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
31281694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
31291694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
31301694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
31311694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
31321694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
31331694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
31341694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
31351694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
31361694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
31371694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
31381694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
31391694.124c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000007b5db71:<flags> [calling]
31401694.124c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
31411694.124c: supR3HardenedDllNotificationCallback: load 000007fefaf40000 LB 0x0003b000 C:\Windows\system32\wdmaud.drv [fFlags=0x0]
31421694.124c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
31431694.124c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ksuser.dll
31441694.124c: supR3HardenedDllNotificationCallback: load 0000000074b00000 LB 0x00006000 C:\Windows\system32\ksuser.dll [fFlags=0x0]
31451694.124c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ksuser.dll
31461694.124c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\avrt.dll
31471694.124c: supR3HardenedDllNotificationCallback: load 000007fefbbe0000 LB 0x00009000 C:\Windows\system32\AVRT.dll [fFlags=0x0]
31481694.124c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\avrt.dll
31491694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefaf40000 'C:\Windows\system32\wdmaud.drv'
31501694.124c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
31511694.124c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000007b5db71:<flags> [calling]
31521694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefaf40000 'C:\Windows\system32\wdmaud.drv'
31531694.124c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
31541694.124c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000007b5dd21:<flags> [calling]
31551694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefaf40000 'C:\Windows\system32\wdmaud.drv'
31561694.124c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
31571694.124c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000007b5dd21:<flags> [calling]
31581694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefaf40000 'C:\Windows\system32\wdmaud.drv'
31591694.124c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
31601694.124c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000007b5dd21:<flags> [calling]
31611694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefaf40000 'C:\Windows\system32\wdmaud.drv'
31621694.124c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000e2c pwszName=\Device\HarddiskVolume2\Windows\System32\AudioSes.dll
31631694.124c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
31641694.124c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
31651694.124c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=6A3BDEC1E955295C342E14C90909598248B24E5B
31661694.124c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_109_for_KB4034664~31bf3856ad364e35~amd64~~6.1.1.4.cat'; file='\Device\HarddiskVolume2\Windows\System32\AudioSes.dll'
31671694.124c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
31681694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
31691694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
31701694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ole32.dll'.
31711694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
31721694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
31731694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
31741694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'mmdevapi.dll'.
31751694.124c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\AudioSes.dll) WinVerifyTrust
31761694.124c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\AudioSes.dll
31771694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mmdevapi.dll'...
31781694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'mmdevapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\mmdevapi.dll' [rcNtRedir=0xc0150008]
31791694.124c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
31801694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
31811694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
31821694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
31831694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
31841694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
31851694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
31861694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
31871694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
31881694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
31891694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
31901694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
31911694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
31921694.124c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\AUDIOSES.DLL (Input=AUDIOSES.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000007b5dd31:<flags> [calling]
31931694.124c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\AudioSes.dll
31941694.124c: supR3HardenedDllNotificationCallback: load 000007fefadd0000 LB 0x0004f000 C:\Windows\system32\AUDIOSES.DLL [fFlags=0x0]
31951694.124c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\AudioSes.dll
31961694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefadd0000 'C:\Windows\system32\AUDIOSES.DLL'
31971694.124c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
31981694.124c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000007b5dd21:<flags> [calling]
31991694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefaf40000 'C:\Windows\system32\wdmaud.drv'
32001694.124c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
32011694.124c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000007b5dd21:<flags> [calling]
32021694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefaf40000 'C:\Windows\system32\wdmaud.drv'
32031694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefaf40000 'C:\Windows\system32\wdmaud.drv'
32041694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefaf40000 'C:\Windows\system32\wdmaud.drv'
32051694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefaf40000 'C:\Windows\system32\wdmaud.drv'
32061694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefaf40000 'C:\Windows\system32\wdmaud.drv'
32071694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefaf40000 'C:\Windows\system32\wdmaud.drv'
32081694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefaf40000 'C:\Windows\system32\wdmaud.drv'
32091694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefaf40000 'C:\Windows\system32\wdmaud.drv'
32101694.124c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000e30 pwszName=\Device\HarddiskVolume2\Windows\System32\msacm32.drv
32111694.124c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
32121694.124c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
32131694.124c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=522563F5384AD4C93CF5CF4EEA899D3267552328
32141694.124c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\msacm32.drv'
32151694.124c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
32161694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
32171694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
32181694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'winmm.dll'.
32191694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msacm32.dll'.
32201694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'mmdevapi.dll'.
32211694.124c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\msacm32.drv) WinVerifyTrust
32221694.124c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msacm32.drv
32231694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mmdevapi.dll'...
32241694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'mmdevapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\mmdevapi.dll' [rcNtRedir=0xc0150008]
32251694.124c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
32261694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msacm32.dll'...
32271694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msacm32.dll' -> '\Device\HarddiskVolume2\Windows\System32\msacm32.dll' [rcNtRedir=0xc0150008]
32281694.124c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000e38 pwszName=\Device\HarddiskVolume2\Windows\System32\msacm32.dll
32291694.124c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
32301694.124c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
32311694.124c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=DCA0A8AEE81B82C402AA72A300B2C8D2DC17C1DA
32321694.124c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\msacm32.dll'
32331694.124c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
32341694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
32351694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
32361694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
32371694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
32381694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'winmm.dll'.
32391694.124c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\msacm32.dll) WinVerifyTrust
32401694.124c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msacm32.dll
32411694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
32421694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
32431694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
32441694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
32451694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
32461694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
32471694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
32481694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
32491694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
32501694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
32511694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
32521694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
32531694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
32541694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
32551694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
32561694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
32571694.124c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000007b5db21:<flags> [calling]
32581694.124c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
32591694.124c: supR3HardenedDllNotificationCallback: load 000007fefabd0000 LB 0x0000a000 C:\Windows\system32\msacm32.drv [fFlags=0x0]
32601694.124c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
32611694.124c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.dll
32621694.124c: supR3HardenedDllNotificationCallback: load 000007fefabb0000 LB 0x00018000 C:\Windows\system32\MSACM32.dll [fFlags=0x0]
32631694.124c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.dll
32641694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefabd0000 'C:\Windows\system32\msacm32.drv'
32651694.124c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
32661694.124c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000007b5d521:<flags> [calling]
32671694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefabd0000 'C:\Windows\system32\msacm32.drv'
32681694.124c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
32691694.124c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000007b5d521:<flags> [calling]
32701694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefabd0000 'C:\Windows\system32\msacm32.drv'
32711694.124c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
32721694.124c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000007b5d521:<flags> [calling]
32731694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefabd0000 'C:\Windows\system32\msacm32.drv'
32741694.124c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
32751694.124c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000007b5d521:<flags> [calling]
32761694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefabd0000 'C:\Windows\system32\msacm32.drv'
32771694.124c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
32781694.124c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000007b5d521:<flags> [calling]
32791694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefabd0000 'C:\Windows\system32\msacm32.drv'
32801694.124c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
32811694.124c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000007b5d521:<flags> [calling]
32821694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefabd0000 'C:\Windows\system32\msacm32.drv'
32831694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefabd0000 'C:\Windows\system32\msacm32.drv'
32841694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefabd0000 'C:\Windows\system32\msacm32.drv'
32851694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefabd0000 'C:\Windows\system32\msacm32.drv'
32861694.124c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000e18 pwszName=\Device\HarddiskVolume2\Windows\System32\midimap.dll
32871694.124c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
32881694.124c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
32891694.124c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=43116C5C719A4751DA70B12932084D73D7AACEA3
32901694.124c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\midimap.dll'
32911694.124c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
32921694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
32931694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
32941694.124c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'winmm.dll'.
32951694.124c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\midimap.dll) WinVerifyTrust
32961694.124c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\midimap.dll
32971694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
32981694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
32991694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
33001694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
33011694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
33021694.124c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
33031694.124c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000007b5db21:<flags> [calling]
33041694.124c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\midimap.dll
33051694.124c: supR3HardenedDllNotificationCallback: load 000007fefaba0000 LB 0x00009000 C:\Windows\system32\midimap.dll [fFlags=0x0]
33061694.124c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\midimap.dll
33071694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefaba0000 'C:\Windows\system32\midimap.dll'
33081694.124c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\midimap.dll
33091694.124c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000007b5d4f1:<flags> [calling]
33101694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefaba0000 'C:\Windows\system32\midimap.dll'
33111694.124c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\midimap.dll
33121694.124c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000007b5d4f1:<flags> [calling]
33131694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefaba0000 'C:\Windows\system32\midimap.dll'
33141694.124c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\midimap.dll
33151694.124c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000007b5db21:<flags> [calling]
33161694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefaba0000 'C:\Windows\system32\midimap.dll'
33171694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefafa0000 'C:\Windows\system32\winmm.dll'
33181694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefafa0000 'C:\Windows\system32\winmm.dll'
33191694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefafa0000 'C:\Windows\system32\winmm.dll'
33201694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe810000 'C:\Windows\system32\ole32.dll'
33211694.124c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
33221694.124c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\winmm.dll (Input=winmm.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000007b5e141:<flags> [calling]
33231694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefafa0000 'C:\Windows\system32\winmm.dll'
33241694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefafa0000 'C:\Windows\system32\winmm.dll'
33251694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefafa0000 'C:\Windows\system32\winmm.dll'
33261694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefafa0000 'C:\Windows\system32\winmm.dll'
33271694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefafa0000 'C:\Windows\system32\winmm.dll'
33281694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefafa0000 'C:\Windows\system32\winmm.dll'
33291694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefafa0000 'C:\Windows\system32\winmm.dll'
33301694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefafa0000 'C:\Windows\system32\winmm.dll'
33311694.124c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dsound.dll
33321694.124c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000007b5d6e1:<flags> [calling]
33331694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeb580000 'C:\Windows\system32\dsound.dll'
33341694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefafa0000 'C:\Windows\system32\winmm.dll'
33351694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefafa0000 'C:\Windows\system32\winmm.dll'
33361694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefafa0000 'C:\Windows\system32\winmm.dll'
33371694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefafa0000 'C:\Windows\system32\winmm.dll'
33381694.1380: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\AudioSes.dll
33391694.1380: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\audioses.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000001a57d9e1:<flags> [calling]
33401694.1380: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefadd0000 'C:\Windows\System32\audioses.dll'
33411694.124c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dsound.dll
33421694.124c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000007b5d8b1:<flags> [calling]
33431694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeb580000 'C:\Windows\system32\dsound.dll'
33441694.124c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefafa0000 'C:\Windows\system32\winmm.dll'
33451694.1160: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefef90000 'C:\Windows\system32\OLEAUT32.dll'
33461694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msctf.dll
33471694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\MSCTF.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001abbe1:<flags> [calling]
33481694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd330000 'C:\Windows\system32\MSCTF.dll'
33491694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe810000 'C:\Windows\system32\ole32.dll'
33501694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd9e0000 'C:\Windows\system32\shell32.dll'
33511694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd9e0000 'C:\Windows\system32\shell32.dll'
33521694.678: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000184 pwszName=\Device\HarddiskVolume2\Windows\System32\mswsock.dll
33531694.678: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
33541694.678: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
33551694.678: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll
33561694.678: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\WINTRUST.DLL (Input=WINTRUST.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000019c8d091:<flags> [calling]
33571694.678: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcfb0000 'C:\Windows\system32\WINTRUST.DLL'
33581694.678: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll
33591694.678: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPT32.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000019c8cec1:<flags> [calling]
33601694.678: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd150000 'C:\Windows\system32\CRYPT32.dll'
33611694.678: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=A0B91C962716871F5DE8282805DA288326E03A9F
33621694.678: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef8c40000 'C:\Windows\system32\cryptnet.dll'
33631694.678: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3161949~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\Windows\System32\mswsock.dll'
33641694.678: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
33651694.678: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
33661694.678: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
33671694.678: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rpcrt4.dll'.
33681694.678: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ws2_32.dll'.
33691694.678: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\mswsock.dll) WinVerifyTrust
33701694.678: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\mswsock.dll
33711694.678: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
33721694.678: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
33731694.678: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
33741694.678: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
33751694.678: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
33761694.678: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
33771694.678: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
33781694.678: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
33791694.678: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\mswsock.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000019c8f331:<flags> [calling]
33801694.678: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\mswsock.dll
33811694.678: supR3HardenedDllNotificationCallback: load 000007fefc740000 LB 0x00055000 C:\Windows\system32\mswsock.dll [fFlags=0x0]
33821694.678: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\mswsock.dll
33831694.678: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc740000 'C:\Windows\system32\mswsock.dll'
33841694.678: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000ff8 pwszName=\Device\HarddiskVolume2\Windows\System32\WSHTCPIP.DLL
33851694.678: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000091b250
33861694.678: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000091b250
33871694.678: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=1EFFE58BB9FD8A94FD1609B7F82A43C8E09D98AA
33881694.678: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\WSHTCPIP.DLL'
33891694.678: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
33901694.678: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'ws2_32.dll'.
33911694.678: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\WSHTCPIP.DLL) WinVerifyTrust
33921694.678: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\WSHTCPIP.DLL
33931694.678: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
33941694.678: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
33951694.678: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\wshtcpip.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000019c8f4d1:<flags> [calling]
33961694.678: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\WSHTCPIP.DLL
33971694.678: supR3HardenedDllNotificationCallback: load 000007fefc100000 LB 0x00007000 C:\Windows\System32\wshtcpip.dll [fFlags=0x0]
33981694.678: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\WSHTCPIP.DLL
33991694.678: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc100000 'C:\Windows\System32\wshtcpip.dll'
34001694.17b0: supR3HardenedDllNotificationCallback: Unload 000007fef58d0000 LB 0x0000d000 C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL [flags=0x0]
34011694.f94: supR3HardenedDllNotificationCallback: Unload 000007fef58e0000 LB 0x0000b000 C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL [flags=0x0]
34021694.378: supR3HardenedDllNotificationCallback: Unload 000007fef5d60000 LB 0x0000c000 C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL [flags=0x0]
34031694.ec4: supR3HardenedDllNotificationCallback: Unload 000007fef5d70000 LB 0x0000d000 C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL [flags=0x0]
34041694.654: supR3HardenedDllNotificationCallback: Unload 000007fef5dc0000 LB 0x0000b000 C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL [flags=0x0]
34051694.124c: supR3HardenedDllNotificationCallback: Unload 000007fefc100000 LB 0x00007000 C:\Windows\System32\wshtcpip.dll [flags=0x0]
34061694.124c: supR3HardenedDllNotificationCallback: Unload 000007fee9b60000 LB 0x009ae000 C:\Program Files\Oracle\VirtualBox\VBoxDD.DLL [flags=0x0]
34071694.124c: supR3HardenedDllNotificationCallback: Unload 000007feeba70000 LB 0x0005d000 C:\Program Files\Oracle\VirtualBox\VBoxDD2.dll [flags=0x0]
34081694.124c: supR3HardenedDllNotificationCallback: Unload 000007feebf80000 LB 0x00058000 C:\Program Files\Oracle\VirtualBox\VBoxDDU.dll [flags=0x0]
34091694.598: supR3HardenedDllNotificationCallback: Unload 000007fef7dc0000 LB 0x000e2000 C:\Windows\system32\wbem\fastprox.dll [flags=0x0]
34101694.598: supR3HardenedDllNotificationCallback: Unload 000007fef7d90000 LB 0x00027000 C:\Windows\system32\NTDSAPI.dll [flags=0x0]
34111694.598: supR3HardenedDllNotificationCallback: Unload 000007fef7390000 LB 0x00014000 C:\Windows\system32\wbem\wbemsvc.dll [flags=0x0]
34121694.598: supR3HardenedDllNotificationCallback: Unload 000007fef7d80000 LB 0x0000f000 C:\Windows\system32\wbem\wbemprox.dll [flags=0x0]
34131694.598: supR3HardenedDllNotificationCallback: Unload 000007fef7f30000 LB 0x00086000 C:\Windows\system32\wbemcomn.dll [flags=0x0]
34141694.598: supR3HardenedDllNotificationCallback: Unload 000007feec4e0000 LB 0x000b5000 C:\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll [flags=0x0]
34151694.598: supR3HardenedDllNotificationCallback: Unload 000007feebfe0000 LB 0x004f6000 C:\Program Files\Oracle\VirtualBox\VBoxC.dll [flags=0x0]
34161694.598: Terminating the normal way: rcExit=0
34171694.598: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll
34181694.598: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\WINTRUST.dll (Input=WINTRUST.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001aee01:<flags> [calling]
34191694.598: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcfb0000 'C:\Windows\system32\WINTRUST.dll'
3420aa4.f90: supR3HardNtChildWaitFor[2]: Quitting: ExitCode=0x0 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 208732 ms, the end);
3421fe0.cac: supR3HardNtChildWaitFor[1]: Quitting: ExitCode=0x0 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 209357 ms, the end);

© 2024 Oracle Support Privacy / Do Not Sell My Info Terms of Use Trademark Policy Automated Access Etiquette