VirtualBox

Ticket #17261: VBoxHardening.log

File VBoxHardening.log, 336.7 KB (added by ADEWIT, 7 years ago)

Log file

Line 
1f28.2afc: Log file opened: 5.2.0r118431 g_hStartupLog=0000000000000068 g_uNtVerCombined=0xa03fab00
2f28.2afc: \SystemRoot\System32\ntdll.dll:
3f28.2afc: CreationTime: 2017-09-29T13:41:43.343111100Z
4f28.2afc: LastWriteTime: 2017-09-29T13:41:43.358737200Z
5f28.2afc: ChangeTime: 2017-11-02T16:40:11.585266100Z
6f28.2afc: FileAttributes: 0x20
7f28.2afc: Size: 0x1dd100
8f28.2afc: NT Headers: 0xe0
9f28.2afc: Timestamp: 0x493793ea
10f28.2afc: Machine: 0x8664 - amd64
11f28.2afc: Timestamp: 0x493793ea
12f28.2afc: Image Version: 10.0
13f28.2afc: SizeOfImage: 0x1e0000 (1966080)
14f28.2afc: Resource Dir: 0x174000 LB 0x6a1d8
15f28.2afc: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
16f28.2afc: [Raw version resource data: 0x1740f0 LB 0x380, codepage 0x0 (reserved 0x0)]
17f28.2afc: ProductName: Microsoft® Windows® Operating System
18f28.2afc: ProductVersion: 10.0.16299.15
19f28.2afc: FileVersion: 10.0.16299.15 (WinBuild.160101.0800)
20f28.2afc: FileDescription: NT Layer DLL
21f28.2afc: \SystemRoot\System32\kernel32.dll:
22f28.2afc: CreationTime: 2017-09-29T13:42:04.954227600Z
23f28.2afc: LastWriteTime: 2017-09-29T13:42:04.954227600Z
24f28.2afc: ChangeTime: 2017-11-02T17:01:52.148856600Z
25f28.2afc: FileAttributes: 0x20
26f28.2afc: Size: 0xab868
27f28.2afc: NT Headers: 0xe8
28f28.2afc: Timestamp: 0xc2cf900
29f28.2afc: Machine: 0x8664 - amd64
30f28.2afc: Timestamp: 0xc2cf900
31f28.2afc: Image Version: 10.0
32f28.2afc: SizeOfImage: 0xae000 (712704)
33f28.2afc: Resource Dir: 0xac000 LB 0x520
34f28.2afc: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
35f28.2afc: [Raw version resource data: 0xac0b0 LB 0x3a4, codepage 0x0 (reserved 0x0)]
36f28.2afc: ProductName: Microsoft® Windows® Operating System
37f28.2afc: ProductVersion: 10.0.16299.15
38f28.2afc: FileVersion: 10.0.16299.15 (WinBuild.160101.0800)
39f28.2afc: FileDescription: Windows NT BASE API Client DLL
40f28.2afc: \SystemRoot\System32\KernelBase.dll:
41f28.2afc: CreationTime: 2017-09-29T13:41:43.124345500Z
42f28.2afc: LastWriteTime: 2017-09-29T13:41:43.124345500Z
43f28.2afc: ChangeTime: 2017-11-02T17:01:53.176154200Z
44f28.2afc: FileAttributes: 0x20
45f28.2afc: Size: 0x266000
46f28.2afc: NT Headers: 0xf0
47f28.2afc: Timestamp: 0x4736733c
48f28.2afc: Machine: 0x8664 - amd64
49f28.2afc: Timestamp: 0x4736733c
50f28.2afc: Image Version: 10.0
51f28.2afc: SizeOfImage: 0x266000 (2514944)
52f28.2afc: Resource Dir: 0x245000 LB 0x548
53f28.2afc: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
54f28.2afc: [Raw version resource data: 0x2450b0 LB 0x3bc, codepage 0x0 (reserved 0x0)]
55f28.2afc: ProductName: Microsoft® Windows® Operating System
56f28.2afc: ProductVersion: 10.0.16299.15
57f28.2afc: FileVersion: 10.0.16299.15 (WinBuild.160101.0800)
58f28.2afc: FileDescription: Windows NT BASE API Client DLL
59f28.2afc: \SystemRoot\System32\apisetschema.dll:
60f28.2afc: CreationTime: 2017-09-29T13:42:07.095026600Z
61f28.2afc: LastWriteTime: 2017-09-29T13:42:07.095026600Z
62f28.2afc: ChangeTime: 2017-11-02T16:40:08.742708400Z
63f28.2afc: FileAttributes: 0x20
64f28.2afc: Size: 0x1b398
65f28.2afc: NT Headers: 0xc8
66f28.2afc: Timestamp: 0xf30abf31
67f28.2afc: Machine: 0x8664 - amd64
68f28.2afc: Timestamp: 0xf30abf31
69f28.2afc: Image Version: 10.0
70f28.2afc: SizeOfImage: 0x1c000 (114688)
71f28.2afc: Resource Dir: 0x1b000 LB 0x408
72f28.2afc: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
73f28.2afc: [Raw version resource data: 0x1b060 LB 0x3a8, codepage 0x0 (reserved 0x0)]
74f28.2afc: ProductName: Microsoft® Windows® Operating System
75f28.2afc: ProductVersion: 10.0.16299.15
76f28.2afc: FileVersion: 10.0.16299.15 (WinBuild.160101.0800)
77f28.2afc: FileDescription: ApiSet Schema DLL
78f28.2afc: NtOpenDirectoryObject failed on \Driver: 0xc0000022
79f28.2afc: supR3HardenedWinFindAdversaries: 0x0
80f28.2afc: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox'
81f28.2afc: Calling main()
82f28.2afc: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
83f28.2afc: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox'
84f28.2afc: SUPR3HardenedMain: Respawn #1
85f28.2afc: System32: \Device\HarddiskVolume3\Windows\System32
86f28.2afc: WinSxS: \Device\HarddiskVolume3\Windows\WinSxS
87f28.2afc: KnownDllPath: C:\WINDOWS\System32
88f28.2afc: '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
89f28.2afc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe)
90f28.2afc: supR3HardNtEnableThreadCreation:
91f28.2afc: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffb450f91b0 pvNtTerminateThread=00007ffb45120890
92f28.2afc: supR3HardenedWinDoReSpawn(1): New child 17a4.1c08 [kernel32].
93f28.2afc: supR3HardNtChildGatherData: PebBaseAddress=00000000006dd000 cbPeb=0x388
94f28.2afc: supR3HardNtPuChFindNtdll: uNtDllParentAddr=00007ffb45080000 uNtDllChildAddr=00007ffb45080000
95f28.2afc: supR3HardenedWinSetupChildInit: uLdrInitThunk=00007ffb450f91b0
96f28.2afc: supR3HardenedWinSetupChildInit: Start child.
97f28.2afc: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
98f28.2afc: supR3HardNtChildPurify: Startup delay kludge #1/0: 259 ms, 31 sleeps
99f28.2afc: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
100f28.2afc: *0000000000000000-000000000050ffff 0x0001/0x0000 0x0000000
101f28.2afc: *0000000000510000-000000000052ffff 0x0004/0x0004 0x0020000
102f28.2afc: *0000000000530000-0000000000548fff 0x0002/0x0002 0x0040000
103f28.2afc: 0000000000549000-000000000054ffff 0x0001/0x0000 0x0000000
104f28.2afc: *0000000000550000-0000000000553fff 0x0002/0x0002 0x0040000
105f28.2afc: 0000000000554000-000000000055ffff 0x0001/0x0000 0x0000000
106f28.2afc: *0000000000560000-0000000000560fff 0x0004/0x0004 0x0020000
107f28.2afc: 0000000000561000-00000000005fffff 0x0001/0x0000 0x0000000
108f28.2afc: *0000000000600000-00000000006dcfff 0x0000/0x0004 0x0020000
109f28.2afc: 00000000006dd000-00000000006dffff 0x0004/0x0004 0x0020000
110f28.2afc: 00000000006e0000-00000000007fffff 0x0000/0x0004 0x0020000
111f28.2afc: *0000000000800000-00000000008fafff 0x0000/0x0004 0x0020000
112f28.2afc: 00000000008fb000-00000000008fdfff 0x0104/0x0004 0x0020000
113f28.2afc: 00000000008fe000-00000000008fffff 0x0004/0x0004 0x0020000
114f28.2afc: 0000000000900000-000000007ffdffff 0x0001/0x0000 0x0000000
115f28.2afc: *000000007ffe0000-000000007ffe0fff 0x0002/0x0002 0x0020000
116f28.2afc: *000000007ffe1000-000000007ffeffff 0x0000/0x0002 0x0020000
117f28.2afc: 000000007fff0000-00007ff6dbe1ffff 0x0001/0x0000 0x0000000
118f28.2afc: *00007ff6dbe20000-00007ff6dbe42fff 0x0002/0x0002 0x0040000
119f28.2afc: 00007ff6dbe43000-00007ff6dca7ffff 0x0001/0x0000 0x0000000
120f28.2afc: *00007ff6dca80000-00007ff6dca80fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
121f28.2afc: 00007ff6dca81000-00007ff6dcaf1fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
122f28.2afc: 00007ff6dcaf2000-00007ff6dcaf2fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
123f28.2afc: 00007ff6dcaf3000-00007ff6dcb38fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
124f28.2afc: 00007ff6dcb39000-00007ff6dcb39fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
125f28.2afc: 00007ff6dcb3a000-00007ff6dcb3afff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
126f28.2afc: 00007ff6dcb3b000-00007ff6dcb3ffff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
127f28.2afc: 00007ff6dcb40000-00007ff6dcb40fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
128f28.2afc: 00007ff6dcb41000-00007ff6dcb41fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
129f28.2afc: 00007ff6dcb42000-00007ff6dcb45fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
130f28.2afc: 00007ff6dcb46000-00007ff6dcb8dfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
131f28.2afc: 00007ff6dcb8e000-00007ffb4507ffff 0x0001/0x0000 0x0000000
132f28.2afc: *00007ffb45080000-00007ffb45080fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
133f28.2afc: 00007ffb45081000-00007ffb45192fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
134f28.2afc: 00007ffb45193000-00007ffb451d8fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
135f28.2afc: 00007ffb451d9000-00007ffb451e0fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
136f28.2afc: 00007ffb451e1000-00007ffb451eefff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
137f28.2afc: 00007ffb451ef000-00007ffb451effff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
138f28.2afc: 00007ffb451f0000-00007ffb451f2fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
139f28.2afc: 00007ffb451f3000-00007ffb4525ffff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
140f28.2afc: 00007ffb45260000-00007ffffffdffff 0x0001/0x0000 0x0000000
141f28.2afc: *00007ffffffe0000-00007ffffffeffff 0x0001/0x0002 0x0020000
142f28.2afc: VirtualBox.exe: timestamp 0x59e6e5d5 (rc=VINF_SUCCESS)
143f28.2afc: '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
144f28.2afc: '\Device\HarddiskVolume3\Windows\System32\ntdll.dll' has no imports
145f28.2afc: supR3HardNtChildPurify: Done after 298 ms and 0 fixes (loop #0).
14617a4.1c08: Log file opened: 5.2.0r118431 g_hStartupLog=0000000000000004 g_uNtVerCombined=0xa03fab00
147f28.2afc: supR3HardNtEnableThreadCreation:
14817a4.1c08: supR3HardenedVmProcessInit: uNtDllAddr=00007ffb45080000 g_uNtVerCombined=0xa03fab00
14917a4.1c08: ntdll.dll: timestamp 0x493793ea (rc=VINF_SUCCESS)
15017a4.1c08: New simple heap: #1 0000000000a00000 LB 0x400000 (for 1966080 allocation)
15117a4.1c08: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox'
15217a4.1c08: System32: \Device\HarddiskVolume3\Windows\System32
15317a4.1c08: WinSxS: \Device\HarddiskVolume3\Windows\WinSxS
15417a4.1c08: KnownDllPath: C:\WINDOWS\System32
15517a4.1c08: supR3HardenedVmProcessInit: Opening vboxdrv stub...
15617a4.1c08: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
15717a4.1c08: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
15817a4.1c08: Registered Dll notification callback with NTDLL.
15917a4.1c08: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\kernel32.dll)
16017a4.1c08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\kernel32.dll
16117a4.1c08: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\KERNEL32.DLL (Input=KERNEL32.DLL, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000004001:<flags> [calling]
16217a4.1c08: supR3HardenedDllNotificationCallback: load 00007ffb41480000 LB 0x00266000 C:\WINDOWS\System32\KERNELBASE.dll [fFlags=0x0]
16317a4.1c08: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\KernelBase.dll)
16417a4.1c08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\KernelBase.dll
16517a4.1c08: supR3HardenedDllNotificationCallback: load 00007ffb43cb0000 LB 0x000ae000 C:\WINDOWS\System32\KERNEL32.DLL [fFlags=0x0]
16617a4.1c08: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
16717a4.1c08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb43cb0000 'C:\WINDOWS\System32\KERNEL32.DLL'
16817a4.1c08: supR3HardenedDllNotificationCallback: load 00007ff6dca80000 LB 0x0010e000 C:\Program Files\Oracle\VirtualBox\VirtualBox.exe [fFlags=0x0]
16917a4.1c08: '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
17017a4.1c08: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe)
17117a4.1c08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
17217a4.1c08: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffb450f91b0 pvNtTerminateThread=00007ffb45120890
173f28.2afc: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 73 ms.
17417a4.1c08: \SystemRoot\System32\ntdll.dll:
17517a4.1c08: CreationTime: 2017-09-29T13:41:43.343111100Z
17617a4.1c08: LastWriteTime: 2017-09-29T13:41:43.358737200Z
17717a4.1c08: ChangeTime: 2017-11-02T16:40:11.585266100Z
17817a4.1c08: FileAttributes: 0x20
17917a4.1c08: Size: 0x1dd100
18017a4.1c08: NT Headers: 0xe0
18117a4.1c08: Timestamp: 0x493793ea
18217a4.1c08: Machine: 0x8664 - amd64
18317a4.1c08: Timestamp: 0x493793ea
18417a4.1c08: Image Version: 10.0
18517a4.1c08: SizeOfImage: 0x1e0000 (1966080)
18617a4.1c08: Resource Dir: 0x174000 LB 0x6a1d8
18717a4.1c08: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
18817a4.1c08: [Raw version resource data: 0x1740f0 LB 0x380, codepage 0x0 (reserved 0x0)]
18917a4.1c08: ProductName: Microsoft® Windows® Operating System
19017a4.1c08: ProductVersion: 10.0.16299.15
19117a4.1c08: FileVersion: 10.0.16299.15 (WinBuild.160101.0800)
19217a4.1c08: FileDescription: NT Layer DLL
19317a4.1c08: \SystemRoot\System32\kernel32.dll:
19417a4.1c08: CreationTime: 2017-09-29T13:42:04.954227600Z
19517a4.1c08: LastWriteTime: 2017-09-29T13:42:04.954227600Z
19617a4.1c08: ChangeTime: 2017-11-02T17:01:52.148856600Z
19717a4.1c08: FileAttributes: 0x20
19817a4.1c08: Size: 0xab868
19917a4.1c08: NT Headers: 0xe8
20017a4.1c08: Timestamp: 0xc2cf900
20117a4.1c08: Machine: 0x8664 - amd64
20217a4.1c08: Timestamp: 0xc2cf900
20317a4.1c08: Image Version: 10.0
20417a4.1c08: SizeOfImage: 0xae000 (712704)
20517a4.1c08: Resource Dir: 0xac000 LB 0x520
20617a4.1c08: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
20717a4.1c08: [Raw version resource data: 0xac0b0 LB 0x3a4, codepage 0x0 (reserved 0x0)]
20817a4.1c08: ProductName: Microsoft® Windows® Operating System
20917a4.1c08: ProductVersion: 10.0.16299.15
21017a4.1c08: FileVersion: 10.0.16299.15 (WinBuild.160101.0800)
21117a4.1c08: FileDescription: Windows NT BASE API Client DLL
21217a4.1c08: \SystemRoot\System32\KernelBase.dll:
21317a4.1c08: CreationTime: 2017-09-29T13:41:43.124345500Z
21417a4.1c08: LastWriteTime: 2017-09-29T13:41:43.124345500Z
21517a4.1c08: ChangeTime: 2017-11-02T17:01:53.176154200Z
21617a4.1c08: FileAttributes: 0x20
21717a4.1c08: Size: 0x266000
21817a4.1c08: NT Headers: 0xf0
21917a4.1c08: Timestamp: 0x4736733c
22017a4.1c08: Machine: 0x8664 - amd64
22117a4.1c08: Timestamp: 0x4736733c
22217a4.1c08: Image Version: 10.0
22317a4.1c08: SizeOfImage: 0x266000 (2514944)
22417a4.1c08: Resource Dir: 0x245000 LB 0x548
22517a4.1c08: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
22617a4.1c08: [Raw version resource data: 0x2450b0 LB 0x3bc, codepage 0x0 (reserved 0x0)]
22717a4.1c08: ProductName: Microsoft® Windows® Operating System
22817a4.1c08: ProductVersion: 10.0.16299.15
22917a4.1c08: FileVersion: 10.0.16299.15 (WinBuild.160101.0800)
23017a4.1c08: FileDescription: Windows NT BASE API Client DLL
23117a4.1c08: \SystemRoot\System32\apisetschema.dll:
23217a4.1c08: CreationTime: 2017-09-29T13:42:07.095026600Z
23317a4.1c08: LastWriteTime: 2017-09-29T13:42:07.095026600Z
23417a4.1c08: ChangeTime: 2017-11-02T16:40:08.742708400Z
23517a4.1c08: FileAttributes: 0x20
23617a4.1c08: Size: 0x1b398
23717a4.1c08: NT Headers: 0xc8
23817a4.1c08: Timestamp: 0xf30abf31
23917a4.1c08: Machine: 0x8664 - amd64
24017a4.1c08: Timestamp: 0xf30abf31
24117a4.1c08: Image Version: 10.0
24217a4.1c08: SizeOfImage: 0x1c000 (114688)
24317a4.1c08: Resource Dir: 0x1b000 LB 0x408
24417a4.1c08: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
24517a4.1c08: [Raw version resource data: 0x1b060 LB 0x3a8, codepage 0x0 (reserved 0x0)]
24617a4.1c08: ProductName: Microsoft® Windows® Operating System
24717a4.1c08: ProductVersion: 10.0.16299.15
24817a4.1c08: FileVersion: 10.0.16299.15 (WinBuild.160101.0800)
24917a4.1c08: FileDescription: ApiSet Schema DLL
25017a4.1c08: NtOpenDirectoryObject failed on \Driver: 0xc0000022
25117a4.1c08: supR3HardenedWinFindAdversaries: 0x0
25217a4.1c08: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox'
25317a4.1c08: Calling main()
25417a4.1c08: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
25517a4.1c08: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox'
25617a4.1c08: '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
25717a4.1c08: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe)
25817a4.1c08: SUPR3HardenedMain: Respawn #2
25917a4.1c08: supR3HardNtEnableThreadCreation:
26017a4.1c08: '\Device\HarddiskVolume3\Windows\System32\ntdll.dll' has no imports
26117a4.1c08: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\ntdll.dll)
26217a4.1c08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\ntdll.dll
26317a4.1c08: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\ntdll.dll (Input=ntdll.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
26417a4.1c08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb45080000 'C:\WINDOWS\System32\ntdll.dll'
26517a4.1c08: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffb450f91b0 pvNtTerminateThread=00007ffb45120890
26617a4.1c08: supR3HardenedWinDoReSpawn(2): New child 19fc.2d74 [kernel32].
26717a4.1c08: supR3HardenedWinReSpawn: NtSetInformationThread/ThreadHideFromDebugger failed: 0xc0000022 (harmless)
26817a4.1c08: supR3HardNtChildGatherData: PebBaseAddress=0000000001048000 cbPeb=0x388
26917a4.1c08: supR3HardNtPuChFindNtdll: uNtDllParentAddr=00007ffb45080000 uNtDllChildAddr=00007ffb45080000
27017a4.1c08: supR3HardenedWinSetupChildInit: uLdrInitThunk=00007ffb450f91b0
27117a4.1c08: supR3HardenedWinSetupChildInit: Start child.
27217a4.1c08: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 1 ms.
27317a4.1c08: supR3HardNtChildPurify: Startup delay kludge #1/0: 262 ms, 31 sleeps
27417a4.1c08: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
27517a4.1c08: *0000000000000000-0000000000eaffff 0x0001/0x0000 0x0000000
27617a4.1c08: *0000000000eb0000-0000000000ecffff 0x0004/0x0004 0x0020000
27717a4.1c08: *0000000000ed0000-0000000000ee8fff 0x0002/0x0002 0x0040000
27817a4.1c08: 0000000000ee9000-0000000000eeffff 0x0001/0x0000 0x0000000
27917a4.1c08: *0000000000ef0000-0000000000feafff 0x0000/0x0004 0x0020000
28017a4.1c08: 0000000000feb000-0000000000fedfff 0x0104/0x0004 0x0020000
28117a4.1c08: 0000000000fee000-0000000000feffff 0x0004/0x0004 0x0020000
28217a4.1c08: *0000000000ff0000-0000000000ff3fff 0x0002/0x0002 0x0040000
28317a4.1c08: 0000000000ff4000-0000000000ffffff 0x0001/0x0000 0x0000000
28417a4.1c08: *0000000001000000-0000000001047fff 0x0000/0x0004 0x0020000
28517a4.1c08: 0000000001048000-000000000104afff 0x0004/0x0004 0x0020000
28617a4.1c08: 000000000104b000-00000000011fffff 0x0000/0x0004 0x0020000
28717a4.1c08: *0000000001200000-0000000001200fff 0x0004/0x0004 0x0020000
28817a4.1c08: 0000000001201000-000000007ffdffff 0x0001/0x0000 0x0000000
28917a4.1c08: *000000007ffe0000-000000007ffe0fff 0x0002/0x0002 0x0020000
29017a4.1c08: *000000007ffe1000-000000007ffeffff 0x0000/0x0002 0x0020000
29117a4.1c08: 000000007fff0000-00007ff6dc3bffff 0x0001/0x0000 0x0000000
29217a4.1c08: *00007ff6dc3c0000-00007ff6dc3e2fff 0x0002/0x0002 0x0040000
29317a4.1c08: 00007ff6dc3e3000-00007ff6dca7ffff 0x0001/0x0000 0x0000000
29417a4.1c08: *00007ff6dca80000-00007ff6dca80fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
29517a4.1c08: 00007ff6dca81000-00007ff6dcaf1fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
29617a4.1c08: 00007ff6dcaf2000-00007ff6dcaf2fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
29717a4.1c08: 00007ff6dcaf3000-00007ff6dcb38fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
29817a4.1c08: 00007ff6dcb39000-00007ff6dcb39fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
29917a4.1c08: 00007ff6dcb3a000-00007ff6dcb3afff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
30017a4.1c08: 00007ff6dcb3b000-00007ff6dcb3ffff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
30117a4.1c08: 00007ff6dcb40000-00007ff6dcb40fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
30217a4.1c08: 00007ff6dcb41000-00007ff6dcb41fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
30317a4.1c08: 00007ff6dcb42000-00007ff6dcb45fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
30417a4.1c08: 00007ff6dcb46000-00007ff6dcb8dfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
30517a4.1c08: 00007ff6dcb8e000-00007ffb4507ffff 0x0001/0x0000 0x0000000
30617a4.1c08: *00007ffb45080000-00007ffb45080fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
30717a4.1c08: 00007ffb45081000-00007ffb45192fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
30817a4.1c08: 00007ffb45193000-00007ffb451d8fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
30917a4.1c08: 00007ffb451d9000-00007ffb451e0fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
31017a4.1c08: 00007ffb451e1000-00007ffb451eefff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
31117a4.1c08: 00007ffb451ef000-00007ffb451effff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
31217a4.1c08: 00007ffb451f0000-00007ffb451f2fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
31317a4.1c08: 00007ffb451f3000-00007ffb4525ffff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
31417a4.1c08: 00007ffb45260000-00007ffffffdffff 0x0001/0x0000 0x0000000
31517a4.1c08: *00007ffffffe0000-00007ffffffeffff 0x0001/0x0002 0x0020000
31617a4.1c08: VirtualBox.exe: timestamp 0x59e6e5d5 (rc=VINF_SUCCESS)
31717a4.1c08: '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
31817a4.1c08: '\Device\HarddiskVolume3\Windows\System32\ntdll.dll' has no imports
31917a4.1c08: supR3HardNtChildPurify: Done after 301 ms and 0 fixes (loop #0).
32017a4.1c08: supR3HardenedEarlyCompact: Removed heap 1 (0x00000000a00000 LB 0x400000)
32117a4.1c08: supR3HardNtEnableThreadCreation:
32219fc.2d74: Log file opened: 5.2.0r118431 g_hStartupLog=0000000000000004 g_uNtVerCombined=0xa03fab00
32319fc.2d74: supR3HardenedVmProcessInit: uNtDllAddr=00007ffb45080000 g_uNtVerCombined=0xa03fab00
32419fc.2d74: ntdll.dll: timestamp 0x493793ea (rc=VINF_SUCCESS)
32519fc.2d74: New simple heap: #1 0000000001310000 LB 0x400000 (for 1966080 allocation)
32619fc.2d74: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox'
32719fc.2d74: System32: \Device\HarddiskVolume3\Windows\System32
32819fc.2d74: WinSxS: \Device\HarddiskVolume3\Windows\WinSxS
32919fc.2d74: KnownDllPath: C:\WINDOWS\System32
33019fc.2d74: supR3HardenedVmProcessInit: Opening vboxdrv...
33119fc.2d74: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
33219fc.2d74: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
33319fc.2d74: Registered Dll notification callback with NTDLL.
33419fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\kernel32.dll)
33519fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\kernel32.dll
33619fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\KERNEL32.DLL (Input=KERNEL32.DLL, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000004001:<flags> [calling]
33719fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb41480000 LB 0x00266000 C:\WINDOWS\System32\KERNELBASE.dll [fFlags=0x0]
33819fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\KernelBase.dll)
33919fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\KernelBase.dll
34019fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb43cb0000 LB 0x000ae000 C:\WINDOWS\System32\KERNEL32.DLL [fFlags=0x0]
34119fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
34219fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb43cb0000 'C:\WINDOWS\System32\KERNEL32.DLL'
34319fc.2d74: supR3HardenedDllNotificationCallback: load 00007ff6dca80000 LB 0x0010e000 C:\Program Files\Oracle\VirtualBox\VirtualBox.exe [fFlags=0x0]
34419fc.2d74: '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
34519fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe)
34619fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
34719fc.2d74: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffb450f91b0 pvNtTerminateThread=00007ffb45120890
34817a4.1c08: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 76 ms.
34919fc.2d74: \SystemRoot\System32\ntdll.dll:
35019fc.2d74: CreationTime: 2017-09-29T13:41:43.343111100Z
35119fc.2d74: LastWriteTime: 2017-09-29T13:41:43.358737200Z
35219fc.2d74: ChangeTime: 2017-11-02T16:40:11.585266100Z
35319fc.2d74: FileAttributes: 0x20
35419fc.2d74: Size: 0x1dd100
35519fc.2d74: NT Headers: 0xe0
35619fc.2d74: Timestamp: 0x493793ea
35719fc.2d74: Machine: 0x8664 - amd64
35819fc.2d74: Timestamp: 0x493793ea
35919fc.2d74: Image Version: 10.0
36019fc.2d74: SizeOfImage: 0x1e0000 (1966080)
36119fc.2d74: Resource Dir: 0x174000 LB 0x6a1d8
36219fc.2d74: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
36319fc.2d74: [Raw version resource data: 0x1740f0 LB 0x380, codepage 0x0 (reserved 0x0)]
36419fc.2d74: ProductName: Microsoft® Windows® Operating System
36519fc.2d74: ProductVersion: 10.0.16299.15
36619fc.2d74: FileVersion: 10.0.16299.15 (WinBuild.160101.0800)
36719fc.2d74: FileDescription: NT Layer DLL
36819fc.2d74: \SystemRoot\System32\kernel32.dll:
36919fc.2d74: CreationTime: 2017-09-29T13:42:04.954227600Z
37019fc.2d74: LastWriteTime: 2017-09-29T13:42:04.954227600Z
37119fc.2d74: ChangeTime: 2017-11-02T17:01:52.148856600Z
37219fc.2d74: FileAttributes: 0x20
37319fc.2d74: Size: 0xab868
37419fc.2d74: NT Headers: 0xe8
37519fc.2d74: Timestamp: 0xc2cf900
37619fc.2d74: Machine: 0x8664 - amd64
37719fc.2d74: Timestamp: 0xc2cf900
37819fc.2d74: Image Version: 10.0
37919fc.2d74: SizeOfImage: 0xae000 (712704)
38019fc.2d74: Resource Dir: 0xac000 LB 0x520
38119fc.2d74: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
38219fc.2d74: [Raw version resource data: 0xac0b0 LB 0x3a4, codepage 0x0 (reserved 0x0)]
38319fc.2d74: ProductName: Microsoft® Windows® Operating System
38419fc.2d74: ProductVersion: 10.0.16299.15
38519fc.2d74: FileVersion: 10.0.16299.15 (WinBuild.160101.0800)
38619fc.2d74: FileDescription: Windows NT BASE API Client DLL
38719fc.2d74: \SystemRoot\System32\KernelBase.dll:
38819fc.2d74: CreationTime: 2017-09-29T13:41:43.124345500Z
38919fc.2d74: LastWriteTime: 2017-09-29T13:41:43.124345500Z
39019fc.2d74: ChangeTime: 2017-11-02T17:01:53.176154200Z
39119fc.2d74: FileAttributes: 0x20
39219fc.2d74: Size: 0x266000
39319fc.2d74: NT Headers: 0xf0
39419fc.2d74: Timestamp: 0x4736733c
39519fc.2d74: Machine: 0x8664 - amd64
39619fc.2d74: Timestamp: 0x4736733c
39719fc.2d74: Image Version: 10.0
39819fc.2d74: SizeOfImage: 0x266000 (2514944)
39919fc.2d74: Resource Dir: 0x245000 LB 0x548
40019fc.2d74: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
40119fc.2d74: [Raw version resource data: 0x2450b0 LB 0x3bc, codepage 0x0 (reserved 0x0)]
40219fc.2d74: ProductName: Microsoft® Windows® Operating System
40319fc.2d74: ProductVersion: 10.0.16299.15
40419fc.2d74: FileVersion: 10.0.16299.15 (WinBuild.160101.0800)
40519fc.2d74: FileDescription: Windows NT BASE API Client DLL
40619fc.2d74: \SystemRoot\System32\apisetschema.dll:
40719fc.2d74: CreationTime: 2017-09-29T13:42:07.095026600Z
40819fc.2d74: LastWriteTime: 2017-09-29T13:42:07.095026600Z
40919fc.2d74: ChangeTime: 2017-11-02T16:40:08.742708400Z
41019fc.2d74: FileAttributes: 0x20
41119fc.2d74: Size: 0x1b398
41219fc.2d74: NT Headers: 0xc8
41319fc.2d74: Timestamp: 0xf30abf31
41419fc.2d74: Machine: 0x8664 - amd64
41519fc.2d74: Timestamp: 0xf30abf31
41619fc.2d74: Image Version: 10.0
41719fc.2d74: SizeOfImage: 0x1c000 (114688)
41819fc.2d74: Resource Dir: 0x1b000 LB 0x408
41919fc.2d74: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
42019fc.2d74: [Raw version resource data: 0x1b060 LB 0x3a8, codepage 0x0 (reserved 0x0)]
42119fc.2d74: ProductName: Microsoft® Windows® Operating System
42219fc.2d74: ProductVersion: 10.0.16299.15
42319fc.2d74: FileVersion: 10.0.16299.15 (WinBuild.160101.0800)
42419fc.2d74: FileDescription: ApiSet Schema DLL
42519fc.2d74: NtOpenDirectoryObject failed on \Driver: 0xc0000022
42619fc.2d74: supR3HardenedWinFindAdversaries: 0x0
42719fc.2d74: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox'
42819fc.2d74: Calling main()
42919fc.2d74: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
43019fc.2d74: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox'
43119fc.2d74: '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
43219fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe)
43319fc.2d74: SUPR3HardenedMain: Final process, opening VBoxDrv...
43419fc.2d74: supR3HardenedEarlyCompact: Removed heap 1 (0x00000001310000 LB 0x400000)
43519fc.2d74: supR3HardNtEnableThreadCreation:
43619fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSupLib.dll)
43719fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSupLib.dll
43819fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
43919fc.2d74: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
44019fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb3d0b0000 LB 0x00005000 C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL [fFlags=0x0]
44119fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
44219fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
44319fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
44419fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3d0b0000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
44519fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
44619fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
44719fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3d0b0000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
44819fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3d0b0000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
44919fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
45019fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msasn1.dll'.
45119fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'crypt32.dll'.
45219fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 'rpcrt4.dll'.
45319fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\wintrust.dll)
45419fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\wintrust.dll
45519fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
45619fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
45719fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll)
45819fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll
45919fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
46019fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume3\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
46119fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #33 'msasn1.dll'.
46219fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\crypt32.dll)
46319fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\crypt32.dll
46419fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
46519fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume3\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
46619fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\msasn1.dll)
46719fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\msasn1.dll
46819fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
46919fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
47019fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\msvcrt.dll)
47119fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\msvcrt.dll
47219fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
47319fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume3\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
47419fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
47519fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
47619fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb43d60000 LB 0x0009d000 C:\WINDOWS\System32\msvcrt.dll [fFlags=0x0]
47719fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
47819fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb413d0000 LB 0x00012000 C:\WINDOWS\System32\MSASN1.dll [fFlags=0x0]
47919fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
48019fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb416f0000 LB 0x000f6000 C:\WINDOWS\System32\ucrtbase.dll [fFlags=0x0]
48119fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\ucrtbase.dll)
48219fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\ucrtbase.dll
48319fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb41b30000 LB 0x001ce000 C:\WINDOWS\System32\CRYPT32.dll [fFlags=0x0]
48419fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
48519fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb42550000 LB 0x0011f000 C:\WINDOWS\System32\RPCRT4.dll [fFlags=0x0]
48619fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
48719fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb43e00000 LB 0x0005b000 C:\WINDOWS\System32\sechost.dll [fFlags=0x0]
48819fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'rpcrt4.dll'.
48919fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\sechost.dll)
49019fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\sechost.dll
49119fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb44530000 LB 0x000a1000 C:\WINDOWS\System32\advapi32.dll [fFlags=0x0]
49219fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
49319fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'sechost.dll'.
49419fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 'rpcrt4.dll'.
49519fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\advapi32.dll)
49619fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\advapi32.dll
49719fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb41ad0000 LB 0x00058000 C:\WINDOWS\System32\Wintrust.dll [fFlags=0x0]
49819fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
49919fc.2d74: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
50019fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
50119fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41480000 'api-ms-win-core-synch-l1-2-0'
50219fc.2d74: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
50319fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
50419fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41480000 'api-ms-win-core-fibers-l1-1-1'
50519fc.2d74: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
50619fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
50719fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41480000 'api-ms-win-core-fibers-l1-1-1'
50819fc.2d74: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
50919fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
51019fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41480000 'api-ms-win-core-synch-l1-2-0'
51119fc.2d74: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-l1-2-1) -> 0x0, fPresent=1
51219fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-l1-2-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
51319fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41480000 'api-ms-win-core-localization-l1-2-1'
51419fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41ad0000 'C:\WINDOWS\system32\Wintrust.dll'
51519fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\bcrypt.dll)
51619fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\bcrypt.dll
51719fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
51819fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
51919fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
52019fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'sechost.dll'...
52119fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'sechost.dll' -> '\Device\HarddiskVolume3\Windows\System32\sechost.dll' [rcNtRedir=0xc0150008]
52219fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\sechost.dll [lacks WinVerifyTrust]
52319fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
52419fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
52519fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
52619fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
52719fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
52819fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
52919fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\bcrypt.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
53019fc.2d74: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
53119fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb40f30000 LB 0x00025000 C:\WINDOWS\system32\bcrypt.dll [fFlags=0x0]
53219fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
53319fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40f30000 'C:\WINDOWS\system32\bcrypt.dll'
53419fc.2d74: bcrypt.dll loaded at 00007ffb40f30000, BCryptOpenAlgorithmProvider at 00007ffb40f32590, preloading providers:
53519fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\bcryptprimitives.dll)
53619fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\bcryptprimitives.dll
53719fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\bcryptprimitives.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
53819fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb417f0000 LB 0x00072000 C:\WINDOWS\System32\bcryptprimitives.dll [fFlags=0x0]
53919fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
54019fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb417f0000 'C:\WINDOWS\system32\bcryptprimitives.dll'
54119fc.2d74: BCryptOpenAlgorithmProvider(,'MD2',0,0) -> 0x0 (hAlgo=0000000003915190)
54219fc.2d74: BCryptOpenAlgorithmProvider(,'MD4',0,0) -> 0x0 (hAlgo=000000000391c670)
54319fc.2d74: BCryptOpenAlgorithmProvider(,'MD5',0,0) -> 0x0 (hAlgo=000000000391c7b0)
54419fc.2d74: BCryptOpenAlgorithmProvider(,'SHA1',0,0) -> 0x0 (hAlgo=000000000391f320)
54519fc.2d74: BCryptOpenAlgorithmProvider(,'SHA256',0,0) -> 0x0 (hAlgo=000000000391fe00)
54619fc.2d74: BCryptOpenAlgorithmProvider(,'SHA512',0,0) -> 0x0 (hAlgo=00000000039200d0)
54719fc.2d74: BCryptOpenAlgorithmProvider(,'RSA',0,0) -> 0x0 (hAlgo=00000000039203a0)
54819fc.2d74: BCryptOpenAlgorithmProvider(,'DSA',0,0) -> 0x0 (hAlgo=0000000003920670)
54919fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
55019fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
55119fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41ad0000 'C:\Windows\System32\WINTRUST.DLL'
55219fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
55319fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
55419fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41ad0000 'C:\Windows\System32\WINTRUST.DLL'
55519fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
55619fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
55719fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41ad0000 'C:\Windows\System32\WINTRUST.DLL'
55819fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
55919fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
56019fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41ad0000 'C:\Windows\System32\WINTRUST.DLL'
56119fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
56219fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
56319fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41ad0000 'C:\Windows\System32\WINTRUST.DLL'
56419fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
56519fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
56619fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41ad0000 'C:\Windows\System32\WINTRUST.DLL'
56719fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
56819fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
56919fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41ad0000 'C:\Windows\System32\WINTRUST.DLL'
57019fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\cryptsp.dll)
57119fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\cryptsp.dll
57219fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb40e30000 LB 0x00017000 C:\WINDOWS\SYSTEM32\CRYPTSP.dll [fFlags=0x0]
57319fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
57419fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'bcrypt.dll'.
57519fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\rsaenh.dll)
57619fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\rsaenh.dll
57719fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
57819fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume3\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
57919fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
58019fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
58119fc.2d74: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
58219fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb40870000 LB 0x00033000 C:\WINDOWS\system32\rsaenh.dll [fFlags=0x0]
58319fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
58419fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
58519fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'bcryptprimitives.dll'.
58619fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\cryptbase.dll)
58719fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\cryptbase.dll
58819fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb40e20000 LB 0x0000b000 C:\WINDOWS\SYSTEM32\CRYPTBASE.dll [fFlags=0x0]
58919fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\cryptbase.dll [lacks WinVerifyTrust]
59019fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
59119fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcryptprimitives.dll'...
59219fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcryptprimitives.dll' -> '\Device\HarddiskVolume3\Windows\System32\bcryptprimitives.dll' [rcNtRedir=0xc0150008]
59319fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
59419fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
59519fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb43cb0000 'C:\WINDOWS\System32\kernel32.dll'
59619fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
59719fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41ad0000 'C:\Windows\System32\WINTRUST.DLL'
59819fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
59919fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\CRYPT32.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
60019fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\CRYPT32.dll'
60119fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb43ae0000 LB 0x0001d000 C:\WINDOWS\System32\imagehlp.dll [fFlags=0x0]
60219fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\imagehlp.dll)
60319fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\imagehlp.dll
60419fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
60519fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
60619fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
60719fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
60819fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'rpcrt4.dll'.
60919fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\gpapi.dll)
61019fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\gpapi.dll
61119fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb401a0000 LB 0x00022000 C:\WINDOWS\SYSTEM32\gpapi.dll [fFlags=0x0]
61219fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gpapi.dll [lacks WinVerifyTrust]
61319fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb41460000 LB 0x0001b000 C:\WINDOWS\System32\profapi.dll [fFlags=0x0]
61419fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\profapi.dll)
61519fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\profapi.dll
61619fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
61719fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'crypt32.dll'.
61819fc.2d74: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\cryptnet.dll)
61919fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\cryptnet.dll
62019fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
62119fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume3\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
62219fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
62319fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
62419fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
62519fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
62619fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
62719fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
62819fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
62919fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
63019fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
63119fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
63219fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (Input=cryptnet.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
63319fc.2d74: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
63419fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb126e0000 LB 0x0002f000 C:\WINDOWS\System32\cryptnet.dll [fFlags=0x0]
63519fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
63619fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
63719fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
63819fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb126e0000 'C:\WINDOWS\System32\cryptnet.dll'
63919fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
64019fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
64119fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb126e0000 'C:\WINDOWS\System32\cryptnet.dll'
64219fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
64319fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
64419fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb126e0000 'C:\WINDOWS\System32\cryptnet.dll'
64519fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
64619fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
64719fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb126e0000 'C:\WINDOWS\System32\cryptnet.dll'
64819fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
64919fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
65019fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb126e0000 'C:\WINDOWS\System32\cryptnet.dll'
65119fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
65219fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
65319fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb126e0000 'C:\WINDOWS\System32\cryptnet.dll'
65419fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
65519fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb126e0000 'C:\WINDOWS\System32\cryptnet.dll'
65619fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
65719fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb126e0000 'C:\WINDOWS\System32\cryptnet.dll'
65819fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
65919fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb126e0000 'C:\WINDOWS\System32\cryptnet.dll'
66019fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
66119fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb126e0000 'C:\WINDOWS\System32\cryptnet.dll'
66219fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
66319fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb126e0000 'C:\WINDOWS\System32\cryptnet.dll'
66419fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb126e0000 'C:\WINDOWS\System32\cryptnet.dll'
66519fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
66619fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb126e0000 'C:\Windows\System32\cryptnet.dll'
66719fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
66819fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
66919fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
67019fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
67119fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
67219fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
67319fc.2d74: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000000 pwszName=\SystemRoot\System32\ntdll.dll
67419fc.2d74: supR3HardNtViCallWinVerifyTrustCatFile: New context 000000000398aff0
67519fc.2d74: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000398aff0
67619fc.2d74: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2E2E4DE0C5BD65756637B6F71B7BAE24CF704BFD
67719fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
67819fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\rpcrt4.dll (Input=rpcrt4.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
67919fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb42550000 'C:\WINDOWS\System32\rpcrt4.dll'
68019fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
68119fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41ad0000 'C:\Windows\System32\WINTRUST.DLL'
68219fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
68319fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41ad0000 'C:\Windows\System32\WINTRUST.DLL'
68419fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
68519fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41ad0000 'C:\Windows\System32\WINTRUST.DLL'
68619fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
68719fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41ad0000 'C:\Windows\System32\WINTRUST.DLL'
68819fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
68919fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41ad0000 'C:\Windows\System32\WINTRUST.DLL'
69019fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
69119fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41ad0000 'C:\Windows\System32\WINTRUST.DLL'
69219fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
69319fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
69419fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41ad0000 'C:\Windows\System32\WINTRUST.DLL'
69519fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
69619fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
69719fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
69819fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
69919fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
70019fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
70119fc.2d74: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0015~31bf3856ad364e35~amd64~~10.0.16299.15.cat'; file='\SystemRoot\System32\ntdll.dll'
70219fc.2d74: g_pfnWinVerifyTrust=00007ffb41ad6bc0
70319fc.2d74: supR3HardenedScreenImage/preload: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll [redoing WinVerifyTrust]
70419fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
70519fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
70619fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
70719fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
70819fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
70919fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
71019fc.2d74: supR3HardenedScreenImage/preload: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\crypt32.dll'
71119fc.2d74: supR3HardenedScreenImage/preload: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wintrust.dll [redoing WinVerifyTrust]
71219fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
71319fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
71419fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
71519fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll
71619fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
71719fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
71819fc.2d74: supR3HardenedScreenImage/preload: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\wintrust.dll'
71919fc.2d74: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000388 pwszName=\Device\HarddiskVolume3\Windows\System32\cryptnet.dll
72019fc.2d74: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000398aff0
72119fc.2d74: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000398aff0
72219fc.2d74: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=5A0BC1B38B9F5EE15493A1BB6ABB29D2FFBB4119
72319fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
72419fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
72519fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
72619fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
72719fc.2d74: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0015~31bf3856ad364e35~amd64~~10.0.16299.15.cat'; file='\Device\HarddiskVolume3\Windows\System32\cryptnet.dll'
72819fc.2d74: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
72919fc.2d74: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\cryptnet.dll'
73019fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
73119fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
73219fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
73319fc.2d74: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\profapi.dll'
73419fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
73519fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
73619fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
73719fc.2d74: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\gpapi.dll'
73819fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
73919fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
74019fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
74119fc.2d74: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\imagehlp.dll'
74219fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
74319fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
74419fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
74519fc.2d74: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\cryptbase.dll'
74619fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
74719fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
74819fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
74919fc.2d74: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\rsaenh.dll'
75019fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
75119fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
75219fc.2d74: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\cryptsp.dll'
75319fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
75419fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll
75519fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
75619fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
75719fc.2d74: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\bcryptprimitives.dll'
75819fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll
75919fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
76019fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
76119fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
76219fc.2d74: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\bcrypt.dll'
76319fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
76419fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
76519fc.2d74: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\advapi32.dll'
76619fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
76719fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
76819fc.2d74: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\sechost.dll'
76919fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
77019fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
77119fc.2d74: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\ucrtbase.dll'
77219fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
77319fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
77419fc.2d74: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll'
77519fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
77619fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
77719fc.2d74: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\msasn1.dll'
77819fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
77919fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
78019fc.2d74: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll'
78119fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
78219fc.2d74: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSupLib.dll'
78319fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
78419fc.2d74: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe'
78519fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
78619fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
78719fc.2d74: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\KernelBase.dll'
78819fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
78919fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
79019fc.2d74: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\kernel32.dll'
79119fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\system32\crypt32.dll'
79219fc.2d74: supR3HardenedWinIsDesiredRootCA: Adding 0x5ad46780fa5df300 DC=com, DC=microsoft, CN=Microsoft Root Certificate Authority
79319fc.2d74: supR3HardenedWinIsDesiredRootCA: Adding 0xea5386456178582b C=ZA, ST=Western Cape, L=Durbanville, O=Thawte, OU=Thawte Certification, CN=Thawte Timestamping CA
79419fc.2d74: supR3HardenedWinIsDesiredRootCA: Adding 0x3be670c1bd02a900 OU=Copyright (c) 1997 Microsoft Corp., OU=Microsoft Corporation, CN=Microsoft Root Authority
79519fc.2d74: supR3HardenedWinIsDesiredRootCA: Adding 0xe991ee72b03db500 C=US, O=Symantec Corporation, CN=Symantec Enterprise Mobile Root for Microsoft
79619fc.2d74: supR3HardenedWinIsDesiredRootCA: Adding 0x4d3835aa4180b200 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2011
79719fc.2d74: supR3HardenedWinIsDesiredRootCA: Adding 0xc85c1e46c0fcc300 OU=generated by AVG Antivirus for SSL/TLS scanning, O=AVG Web/Mail Shield, CN=AVG Web/Mail Shield Root
79819fc.2d74: supR3HardenedWinIsDesiredRootCA: Adding 0x646e3fe3ba08df00 C=US, O=MSFT, CN=Microsoft Authenticode(tm) Root Authority
79919fc.2d74: supR3HardenedWinIsDesiredRootCA: Adding 0xece4e4289e08b900 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010
80019fc.2d74: supR3HardenedWinIsDesiredRootCA: Adding 0x43a9cc371ff5385a O=Microsoft Trust Network, OU=Microsoft Corporation, OU=Microsoft Time Stamping Service Root, OU=Copyright (c) 1997 Microsoft Corp.
80119fc.2d74: supR3HardenedWinIsDesiredRootCA: Adding 0x2e2d2c7c68f0202e O=VeriSign Trust Network, OU=VeriSign, Inc., OU=VeriSign Time Stamping Service Root, OU=NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.
80219fc.2d74: supR3HardenedWinIsDesiredRootCA: Adding 0xd8dbfb2c27bfb200 C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2008 thawte, Inc. - For authorized use only, CN=thawte Primary Root CA - G3
80319fc.2d74: supR3HardenedWinIsDesiredRootCA: Adding 0x61a3a33f81aace00 C=US, ST=UT, L=Salt Lake City, O=The USERTRUST Network, OU=http://www.usertrust.com, CN=UTN-USERFirst-Object
80419fc.2d74: supR3HardenedWinIsDesiredRootCA: Adding 0x57ba5395b561bf00 C=BM, O=QuoVadis Limited, OU=Root Certification Authority, CN=QuoVadis Root Certification Authority
80519fc.2d74: supR3HardenedWinIsDesiredRootCA: Adding 0xf4fd306318ccda00 C=US, O=GeoTrust Inc., CN=GeoTrust Global CA
80619fc.2d74: supR3HardenedWinIsDesiredRootCA: Adding 0x83085097e9afdf00 O=Digital Signature Trust Co., CN=DST Root CA X3
80719fc.2d74: supR3HardenedWinIsDesiredRootCA: Adding 0x780679907625cc00 OU=GlobalSign Root CA - R3, O=GlobalSign, CN=GlobalSign
80819fc.2d74: supR3HardenedWinIsDesiredRootCA: Adding 0x3d98ab22bb04a300 C=IE, O=Baltimore, OU=CyberTrust, CN=Baltimore CyberTrust Root
80919fc.2d74: supR3HardenedWinIsDesiredRootCA: Adding 0xa0ee62086758b15d C=US, O=Equifax, OU=Equifax Secure Certificate Authority
81019fc.2d74: supR3HardenedWinIsDesiredRootCA: Adding 0xeae16ef49d40be00 C=GB, ST=Greater Manchester, L=Salford, O=Comodo CA Limited, CN=AAA Certificate Services
81119fc.2d74: supR3HardenedWinIsDesiredRootCA: Adding 0xd944bca189a00 C=BM, O=QuoVadis Limited, CN=QuoVadis Root CA 2
81219fc.2d74: supR3HardenedWinIsDesiredRootCA: Adding 0xc6fa4243b695b600 C=US, O=Entrust, Inc., OU=www.entrust.net/CPS is incorporated by reference, OU=(c) 2006 Entrust, Inc., CN=Entrust Root Certification Authority
81319fc.2d74: supR3HardenedWinIsDesiredRootCA: Adding 0xa3ce8d99e60eda00 C=BE, O=GlobalSign nv-sa, OU=Root CA, CN=GlobalSign Root CA
81419fc.2d74: supR3HardenedWinIsDesiredRootCA: Adding 0x560ad29254e89100 C=GB, ST=Greater Manchester, L=Salford, O=COMODO CA Limited, CN=COMODO RSA Certification Authority
81519fc.2d74: supR3HardenedWinIsDesiredRootCA: Adding 0xa671e9fec832b700 C=US, O=Starfield Technologies, Inc., OU=Starfield Class 2 Certification Authority
81619fc.2d74: supR3HardenedWinIsDesiredRootCA: Adding 0xa8de7211e13be200 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root CA
81719fc.2d74: supR3HardenedWinIsDesiredRootCA: Adding 0x7ae89c50f0b6a00f C=US, O=GTE Corporation, OU=GTE CyberTrust Solutions, Inc., CN=GTE CyberTrust Global Root
81819fc.2d74: supR3HardenedWinIsDesiredRootCA: Adding 0xd45980fbf0a0ac00 C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2006 thawte, Inc. - For authorized use only, CN=thawte Primary Root CA
81919fc.2d74: supR3HardenedWinIsDesiredRootCA: Adding 0xf5cd95e581a4ab00 C=US, O=SecureTrust Corporation, CN=SecureTrust CA
82019fc.2d74: supR3HardenedWinIsDesiredRootCA: Adding 0x6f2ebe0e24cfa600 OU=GlobalSign Root CA - R2, O=GlobalSign, CN=GlobalSign
82119fc.2d74: supR3HardenedWinIsDesiredRootCA: Adding 0x14018a1bf29e595c C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority
82219fc.2d74: supR3HardenedWinIsDesiredRootCA: Adding 0x9e5bc2d78b6a3636 C=ZA, ST=Western Cape, L=Cape Town, O=Thawte Consulting cc, OU=Certification Services Division, CN=Thawte Premium Server CA, [email protected]
82319fc.2d74: supR3HardenedWinIsDesiredRootCA: Adding 0xd4fbe673e5ccc600 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA
82419fc.2d74: supR3HardenedWinIsDesiredRootCA: Adding 0x1b8578514b74ac00 C=US, O=WFA Hotspot 2.0, CN=Hotspot 2.0 Trust Root CA - 03
82519fc.2d74: supR3HardenedWinIsDesiredRootCA: Adding 0xb28612a94b4dad00 O=Entrust.net, OU=www.entrust.net/CPS_2048 incorp. by ref. (limits liab.), OU=(c) 1999 Entrust.net Limited, CN=Entrust.net Certification Authority (2048)
82619fc.2d74: supR3HardenedWinIsDesiredRootCA: Adding 0x357a29080824af00 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2006 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G5
82719fc.2d74: supR3HardenedWinIsDesiredRootCA: Adding 0x59faf1086271bf00 C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com, Inc., CN=Go Daddy Root Certificate Authority - G2
82819fc.2d74: supR3HardenedWinIsDesiredRootCA: Adding 0x3401b15e3761c700 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2008 VeriSign, Inc. - For authorized use only, CN=VeriSign Universal Root Certification Authority
82919fc.2d74: supR3HardenedWinIsDesiredRootCA: Adding 0x7cd4ff7b15b8be00 C=US, O=GeoTrust Inc., CN=GeoTrust Primary Certification Authority
83019fc.2d74: supR3HardenedWinIsDesiredRootCA: Adding 0x491857ead79dde00 C=US, O=The Go Daddy Group, Inc., OU=Go Daddy Class 2 Certification Authority
83119fc.2d74: supR3HardenedWinIsDesiredRootCA: Adding 0xc2ba72a37dfbe300 C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Trusted Network CA
83219fc.2d74: supR3HardenedWinIsDesiredRootCA: Adding 0x8043e4ce150ead00 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID Root CA
83319fc.2d74: supR3HardenedWinIsDesiredRootCA: Adding 0x331d58625ee2dc00 C=US, O=GeoTrust Inc., OU=(c) 2008 GeoTrust Inc. - For authorized use only, CN=GeoTrust Primary Certification Authority - G3
83419fc.2d74: supR3HardenedWinIsDesiredRootCA: Adding 0xf2e6331af7b700 C=SE, O=AddTrust AB, OU=AddTrust External TTP Network, CN=AddTrust External CA Root
83519fc.2d74: supR3HardenedWinRetrieveTrustedRootCAs: cAdded=43
83619fc.2d74: SUPR3HardenedMain: Load Runtime...
83719fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
83819fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
83919fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
84019fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ws2_32.dll'.
84119fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'rpcrt4.dll'.
84219fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll) WinVerifyTrust
84319fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll
84419fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
84519fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
84619fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll
84719fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
84819fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
84919fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
85019fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
85119fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'rpcrt4.dll'.
85219fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\ws2_32.dll) WinVerifyTrust
85319fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\ws2_32.dll
85419fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
85519fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
85619fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
85719fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
85819fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll
85919fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
86019fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
86119fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll) WinVerifyTrust
86219fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll
86319fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
86419fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
86519fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
86619fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
86719fc.2d74: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
86819fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll)
86919fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll
87019fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
87119fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll) WinVerifyTrust
87219fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000a01:<flags> [calling]
87319fc.2d74: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll
87419fc.2d74: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll [avoiding WinVerifyTrust]
87519fc.2d74: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll
87619fc.2d74: supR3HardenedDllNotificationCallback: load 000000006f2c0000 LB 0x000d2000 C:\Program Files\Oracle\VirtualBox\MSVCR100.dll [fFlags=0x0]
87719fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll [avoiding WinVerifyTrust]
87819fc.2d74: supR3HardenedDllNotificationCallback: load 000000006f220000 LB 0x00098000 C:\Program Files\Oracle\VirtualBox\MSVCP100.dll [fFlags=0x0]
87919fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll
88019fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb43b00000 LB 0x0006c000 C:\WINDOWS\System32\WS2_32.dll [fFlags=0x0]
88119fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ws2_32.dll
88219fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb04330000 LB 0x00595000 C:\Program Files\Oracle\VirtualBox\VBoxRT.dll [fFlags=0x0]
88319fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll
88419fc.2d74: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
88519fc.2d74: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
88619fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll
88719fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
88819fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb04330000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
88919fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll
89019fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
89119fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb04330000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
89219fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll
89319fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
89419fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb04330000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
89519fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll
89619fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
89719fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb04330000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
89819fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll
89919fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
90019fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb04330000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
90119fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll
90219fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
90319fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb04330000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
90419fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb04330000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
90519fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb04330000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
90619fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb04330000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
90719fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb04330000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
90819fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb04330000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
90919fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb04330000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
91019fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb04330000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
91119fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll
91219fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
91319fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb04330000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
91419fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb04330000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
91519fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb04330000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
91619fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb04330000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
91719fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb04330000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
91819fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb04330000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
91919fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb04330000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
92019fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb04330000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
92119fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb04330000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
92219fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb04330000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
92319fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb04330000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
92419fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb04330000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
92519fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb04330000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
92619fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb04330000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
92719fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb04330000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
92819fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb04330000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
92919fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll
93019fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
93119fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb04330000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
93219fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb04330000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
93319fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb04330000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
93419fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb04330000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
93519fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41ad0000 'C:\WINDOWS\system32\Wintrust.dll'
93619fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
93719fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
93819fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll
93919fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
94019fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
94119fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
94219fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\system32\crypt32.dll'
94319fc.2d74: SUPR3HardenedMain: Load TrustedMain...
94419fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
94519fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'opengl32.dll'.
94619fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
94719fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcp100.dll'.
94819fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcr100.dll'.
94919fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qt5corevbox.dll'.
95019fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'qt5guivbox.dll'.
95119fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'qt5widgetsvbox.dll'.
95219fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'qt5printsupportvbox.dll'.
95319fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'qt5openglvbox.dll'.
95419fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'user32.dll'.
95519fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'advapi32.dll'.
95619fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'shell32.dll'.
95719fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'ole32.dll'.
95819fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'oleaut32.dll'.
95919fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #15 'winmm.dll'.
96019fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.dll) WinVerifyTrust
96119fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.dll
96219fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
96319fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume3\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
96419fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
96519fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
96619fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'winmmbase.dll'.
96719fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msvcrt.dll'.
96819fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\winmm.dll) WinVerifyTrust
96919fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\winmm.dll
97019fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
97119fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume3\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
97219fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
97319fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
97419fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll
97519fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmmbase.dll'...
97619fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmmbase.dll' -> '\Device\HarddiskVolume3\Windows\System32\winmmbase.dll' [rcNtRedir=0xc0150008]
97719fc.2d74: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\winmmbase.dll'.
97819fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
97919fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\winmmbase.dll)
98019fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\winmmbase.dll
98119fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
98219fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
98319fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll
98419fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
98519fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll
98619fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
98719fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
98819fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
98919fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'combase.dll'.
99019fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'rpcrt4.dll'.
99119fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\oleaut32.dll) WinVerifyTrust
99219fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\oleaut32.dll
99319fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
99419fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
99519fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
99619fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
99719fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll
99819fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
99919fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
100019fc.2d74: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\combase.dll'.
100119fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rpcrt4.dll'.
100219fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #45 'bcryptprimitives.dll'.
100319fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\combase.dll)
100419fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\combase.dll
100519fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
100619fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
100719fc.2d74: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll'.
100819fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll)
100919fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\msvcp_win.dll
101019fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcryptprimitives.dll'...
101119fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcryptprimitives.dll' -> '\Device\HarddiskVolume3\Windows\System32\bcryptprimitives.dll' [rcNtRedir=0xc0150008]
101219fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\bcryptprimitives.dll
101319fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
101419fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
101519fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
101619fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
101719fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #22 'rpcrt4.dll'.
101819fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #46 'gdi32.dll'.
101919fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #47 'user32.dll'.
102019fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #48 'combase.dll'.
102119fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\ole32.dll) WinVerifyTrust
102219fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\ole32.dll
102319fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
102419fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume3\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
102519fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
102619fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
102719fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\combase.dll [lacks WinVerifyTrust]
102819fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
102919fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
103019fc.2d74: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\user32.dll'.
103119fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'win32u.dll'.
103219fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #34 'gdi32.dll'.
103319fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\user32.dll)
103419fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\user32.dll
103519fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
103619fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
103719fc.2d74: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32.dll'.
103819fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\gdi32.dll)
103919fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\gdi32.dll
104019fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
104119fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
104219fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
104319fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
104419fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
104519fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
104619fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
104719fc.2d74: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\win32u.dll'.
104819fc.2d74: '\Device\HarddiskVolume3\Windows\System32\win32u.dll' has no imports
104919fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\win32u.dll)
105019fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\win32u.dll
105119fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
105219fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
105319fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
105419fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #73 'user32.dll'.
105519fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #75 'gdi32.dll'.
105619fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\shell32.dll) WinVerifyTrust
105719fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\shell32.dll
105819fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
105919fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
106019fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\advapi32.dll
106119fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
106219fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
106319fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\user32.dll [redoing WinVerifyTrust]
106419fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
106519fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
106619fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
106719fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
106819fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
106919fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\user32.dll [lacks WinVerifyTrust]
107019fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
107119fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
107219fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll
107319fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
107419fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
107519fc.2d74: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\user32.dll'
107619fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5openglvbox.dll'...
107719fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5openglvbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5openglvbox.dll' [rcNtRedir=0xc0150008]
107819fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
107919fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'qt5widgetsvbox.dll'.
108019fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'qt5guivbox.dll'.
108119fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5corevbox.dll'.
108219fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcr100.dll'.
108319fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll) WinVerifyTrust
108419fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll
108519fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5printsupportvbox.dll'...
108619fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5printsupportvbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5printsupportvbox.dll' [rcNtRedir=0xc0150008]
108719fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
108819fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
108919fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
109019fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
109119fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
109219fc.2d74: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll'.
109319fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
109419fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'shell32.dll'.
109519fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ole32.dll'.
109619fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
109719fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ws2_32.dll'.
109819fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'mpr.dll'.
109919fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'msvcp100.dll'.
110019fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'msvcr100.dll'.
110119fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll)
110219fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
110319fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
110419fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
110519fc.2d74: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll'.
110619fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ole32.dll'.
110719fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'opengl32.dll'.
110819fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
110919fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
111019fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qt5corevbox.dll'.
111119fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcp100.dll'.
111219fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcr100.dll'.
111319fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll)
111419fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
111519fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
111619fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
111719fc.2d74: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll'.
111819fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
111919fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
112019fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5guivbox.dll'.
112119fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qt5corevbox.dll'.
112219fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'shell32.dll'.
112319fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcp100.dll'.
112419fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcr100.dll'.
112519fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll)
112619fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll
112719fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
112819fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
112919fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
113019fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
113119fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
113219fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll
113319fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
113419fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume3\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
113519fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shell32.dll
113619fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
113719fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
113819fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [lacks WinVerifyTrust]
113919fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
114019fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
114119fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll [lacks WinVerifyTrust]
114219fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
114319fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
114419fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\user32.dll
114519fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
114619fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
114719fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
114819fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
114919fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
115019fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
115119fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
115219fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
115319fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll
115419fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
115519fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
115619fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [lacks WinVerifyTrust]
115719fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
115819fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
115919fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\user32.dll
116019fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
116119fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
116219fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
116319fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
116419fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume3\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
116519fc.2d74: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume3\Windows\System32\opengl32.dll'.
116619fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
116719fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
116819fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
116919fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
117019fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'glu32.dll'.
117119fc.2d74: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\opengl32.dll)
117219fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\opengl32.dll
117319fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
117419fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
117519fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ole32.dll
117619fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
117719fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
117819fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
117919fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
118019fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
118119fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll
118219fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mpr.dll'...
118319fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'mpr.dll' -> '\Device\HarddiskVolume3\Windows\System32\mpr.dll' [rcNtRedir=0xc0150008]
118419fc.2d74: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\mpr.dll'.
118519fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\mpr.dll)
118619fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\mpr.dll
118719fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
118819fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
118919fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ws2_32.dll
119019fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
119119fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
119219fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\advapi32.dll
119319fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
119419fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
119519fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ole32.dll
119619fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
119719fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume3\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
119819fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shell32.dll
119919fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
120019fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
120119fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\user32.dll
120219fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'glu32.dll'...
120319fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'glu32.dll' -> '\Device\HarddiskVolume3\Windows\System32\glu32.dll' [rcNtRedir=0xc0150008]
120419fc.2d74: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume3\Windows\System32\glu32.dll'.
120519fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
120619fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
120719fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'opengl32.dll'.
120819fc.2d74: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\glu32.dll)
120919fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\glu32.dll
121019fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
121119fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
121219fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
121319fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
121419fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
121519fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\user32.dll
121619fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
121719fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
121819fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\advapi32.dll
121919fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
122019fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
122119fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll
122219fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
122319fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume3\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
122419fc.2d74: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\opengl32.dll [lacks WinVerifyTrust]
122519fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
122619fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
122719fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\user32.dll
122819fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
122919fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
123019fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
123119fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
123219fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
123319fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5widgetsvbox.dll'.
123419fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qt5guivbox.dll'.
123519fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qt5corevbox.dll'.
123619fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'winspool.drv'.
123719fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'comdlg32.dll'.
123819fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'msvcr100.dll'.
123919fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5PrintSupportVBox.dll) WinVerifyTrust
124019fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5PrintSupportVBox.dll
124119fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
124219fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
124319fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll [redoing WinVerifyTrust]
124419fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
124519fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
124619fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
124719fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comdlg32.dll'...
124819fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'comdlg32.dll' -> '\Device\HarddiskVolume3\Windows\System32\comdlg32.dll' [rcNtRedir=0xc0150008]
124919fc.2d74: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume3\Windows\System32\comdlg32.dll'.
125019fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
125119fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #36 'user32.dll'.
125219fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #37 'shlwapi.dll'.
125319fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #38 'gdi32.dll'.
125419fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #39 'comctl32.dll'.
125519fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #40 'shell32.dll'.
125619fc.2d74: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\comdlg32.dll)
125719fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\comdlg32.dll
125819fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winspool.drv'...
125919fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'winspool.drv' -> '\Device\HarddiskVolume3\Windows\System32\winspool.drv' [rcNtRedir=0xc0150008]
126019fc.2d74: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume3\Windows\System32\winspool.drv'.
126119fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
126219fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'iphlpapi.dll'.
126319fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #34 'bcrypt.dll'.
126419fc.2d74: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\winspool.drv)
126519fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\winspool.drv
126619fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
126719fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
126819fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [lacks WinVerifyTrust]
126919fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
127019fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
127119fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll [lacks WinVerifyTrust]
127219fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
127319fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
127419fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll [lacks WinVerifyTrust]
127519fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
127619fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
127719fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\user32.dll
127819fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
127919fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
128019fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
128119fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
128219fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume3\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
128319fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\bcrypt.dll
128419fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'iphlpapi.dll'...
128519fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'iphlpapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\iphlpapi.dll' [rcNtRedir=0xc0150008]
128619fc.2d74: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\IPHLPAPI.DLL'.
128719fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\IPHLPAPI.DLL)
128819fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\IPHLPAPI.DLL
128919fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
129019fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
129119fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
129219fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume3\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
129319fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shell32.dll
129419fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comctl32.dll'...
129519fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'comctl32.dll' -> '\Device\HarddiskVolume3\Windows\System32\comctl32.dll' [rcNtRedir=0x0]
129619fc.2d74: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\comctl32.dll'.
129719fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'advapi32.dll'.
129819fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
129919fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
130019fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\comctl32.dll)
130119fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\comctl32.dll
130219fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
130319fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
130419fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
130519fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
130619fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
130719fc.2d74: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\shlwapi.dll'.
130819fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
130919fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #45 'gdi32.dll'.
131019fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #46 'user32.dll'.
131119fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\shlwapi.dll)
131219fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\shlwapi.dll
131319fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
131419fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
131519fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
131619fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
131719fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
131819fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
131919fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
132019fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
132119fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
132219fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
132319fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
132419fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
132519fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
132619fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
132719fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
132819fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
132919fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
133019fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
133119fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\advapi32.dll
133219fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
133319fc.2d74: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll'
133419fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
133519fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
133619fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll [redoing WinVerifyTrust]
133719fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
133819fc.2d74: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll'
133919fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
134019fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
134119fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [redoing WinVerifyTrust]
134219fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
134319fc.2d74: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll'
134419fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
134519fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
134619fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll [redoing WinVerifyTrust]
134719fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
134819fc.2d74: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'
134919fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
135019fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
135119fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll
135219fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
135319fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
135419fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
135519fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume3\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
135619fc.2d74: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\opengl32.dll [redoing WinVerifyTrust]
135719fc.2d74: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000434 pwszName=\Device\HarddiskVolume3\Windows\System32\opengl32.dll
135819fc.2d74: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000398aff0
135919fc.2d74: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000398aff0
136019fc.2d74: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F39C902102F30859FF82648A950427FCB81FB124
136119fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
136219fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
136319fc.2d74: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package00111~31bf3856ad364e35~amd64~~10.0.16299.15.cat'; file='\Device\HarddiskVolume3\Windows\System32\opengl32.dll'
136419fc.2d74: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
136519fc.2d74: supR3HardenedScreenImage/Imports: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\opengl32.dll'
136619fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VirtualBox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000a01:<flags> [calling]
136719fc.2d74: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.dll
136819fc.2d74: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\opengl32.dll
136919fc.2d74: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
137019fc.2d74: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
137119fc.2d74: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll
137219fc.2d74: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5PrintSupportVBox.dll
137319fc.2d74: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll
137419fc.2d74: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winmm.dll
137519fc.2d74: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\glu32.dll [avoiding WinVerifyTrust]
137619fc.2d74: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\mpr.dll [avoiding WinVerifyTrust]
137719fc.2d74: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\winspool.drv [avoiding WinVerifyTrust]
137819fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'advapi32.dll'.
137919fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
138019fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
138119fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.16299.19_none_e48015d00334ec58\comctl32.dll)
138219fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.16299.19_none_e48015d00334ec58\comctl32.dll
138319fc.2d74: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winmmbase.dll [avoiding WinVerifyTrust]
138419fc.2d74: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\IPHLPAPI.DLL [avoiding WinVerifyTrust]
138519fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb41910000 LB 0x00020000 C:\WINDOWS\System32\win32u.dll [fFlags=0x0]
138619fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\win32u.dll [avoiding WinVerifyTrust]
138719fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb41870000 LB 0x0009b000 C:\WINDOWS\System32\msvcp_win.dll [fFlags=0x0]
138819fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcp_win.dll [avoiding WinVerifyTrust]
138919fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb41930000 LB 0x00194000 C:\WINDOWS\System32\gdi32full.dll [fFlags=0x0]
139019fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
139119fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #33 'gdi32.dll'.
139219fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #35 'user32.dll'.
139319fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #36 'win32u.dll'.
139419fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\gdi32full.dll)
139519fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\gdi32full.dll
139619fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb42670000 LB 0x00028000 C:\WINDOWS\System32\GDI32.dll [fFlags=0x0]
139719fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [avoiding WinVerifyTrust]
139819fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb44ba0000 LB 0x0018e000 C:\WINDOWS\System32\USER32.dll [fFlags=0x0]
139919fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb20b50000 LB 0x0002c000 C:\WINDOWS\SYSTEM32\GLU32.dll [fFlags=0x0]
140019fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\glu32.dll [avoiding WinVerifyTrust]
140119fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb203e0000 LB 0x0011e000 C:\WINDOWS\SYSTEM32\OPENGL32.dll [fFlags=0x0]
140219fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\opengl32.dll
140319fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb42500000 LB 0x0004a000 C:\WINDOWS\System32\cfgmgr32.dll [fFlags=0x0]
140419fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\cfgmgr32.dll)
140519fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\cfgmgr32.dll
140619fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb43e60000 LB 0x00308000 C:\WINDOWS\System32\combase.dll [fFlags=0x0]
140719fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\combase.dll [avoiding WinVerifyTrust]
140819fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb44a40000 LB 0x000a6000 C:\WINDOWS\System32\shcore.dll [fFlags=0x0]
140919fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
141019fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #37 'rpcrt4.dll'.
141119fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #44 'combase.dll'.
141219fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\SHCore.dll)
141319fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\SHCore.dll
141419fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb44ea0000 LB 0x00051000 C:\WINDOWS\System32\shlwapi.dll [fFlags=0x0]
141519fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shlwapi.dll [avoiding WinVerifyTrust]
141619fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb413f0000 LB 0x00011000 C:\WINDOWS\System32\kernel.appcore.dll [fFlags=0x0]
141719fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'msvcrt.dll'.
141819fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'rpcrt4.dll'.
141919fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\kernel.appcore.dll)
142019fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\kernel.appcore.dll
142119fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb41410000 LB 0x0004c000 C:\WINDOWS\System32\powrprof.dll [fFlags=0x0]
142219fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'rpcrt4.dll'.
142319fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\powrprof.dll)
142419fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\powrprof.dll
142519fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb41db0000 LB 0x00747000 C:\WINDOWS\System32\windows.storage.dll [fFlags=0x0]
142619fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
142719fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'rpcrt4.dll'.
142819fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #55 'combase.dll'.
142919fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #75 'profapi.dll'.
143019fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\windows.storage.dll)
143119fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\windows.storage.dll
143219fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb426a0000 LB 0x01437000 C:\WINDOWS\System32\SHELL32.dll [fFlags=0x0]
143319fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shell32.dll
143419fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb44f00000 LB 0x00149000 C:\WINDOWS\System32\ole32.dll [fFlags=0x0]
143519fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ole32.dll
143619fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb32110000 LB 0x0001b000 C:\WINDOWS\SYSTEM32\MPR.dll [fFlags=0x0]
143719fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\mpr.dll [avoiding WinVerifyTrust]
143819fc.2d74: supR3HardenedDllNotificationCallback: load 000000006ecb0000 LB 0x00565000 C:\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [fFlags=0x0]
143919fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
144019fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb03360000 LB 0x005f7000 C:\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll [fFlags=0x0]
144119fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
144219fc.2d74: supR3HardenedDllNotificationCallback: load 000000006e740000 LB 0x00561000 C:\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll [fFlags=0x0]
144319fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll
144419fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb409f0000 LB 0x00039000 C:\WINDOWS\SYSTEM32\IPHLPAPI.DLL [fFlags=0x0]
144519fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\IPHLPAPI.DLL [avoiding WinVerifyTrust]
144619fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb39720000 LB 0x00086000 C:\WINDOWS\SYSTEM32\WINSPOOL.DRV [fFlags=0x0]
144719fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\winspool.drv [avoiding WinVerifyTrust]
144819fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb397c0000 LB 0x000a6000 C:\WINDOWS\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.16299.19_none_e48015d00334ec58\COMCTL32.dll [fFlags=0x0]
144919fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.16299.19_none_e48015d00334ec58\comctl32.dll [avoiding WinVerifyTrust]
145019fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb44d30000 LB 0x0010a000 C:\WINDOWS\System32\COMDLG32.dll [fFlags=0x0]
145119fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\comdlg32.dll [avoiding WinVerifyTrust]
145219fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb1d4c0000 LB 0x00051000 C:\Program Files\Oracle\VirtualBox\Qt5PrintSupportVBox.dll [fFlags=0x0]
145319fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5PrintSupportVBox.dll
145419fc.2d74: supR3HardenedDllNotificationCallback: load 000000006e6e0000 LB 0x00054000 C:\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll [fFlags=0x0]
145519fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll
145619fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb43bd0000 LB 0x000c5000 C:\WINDOWS\System32\OLEAUT32.dll [fFlags=0x0]
145719fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\oleaut32.dll
145819fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb3f610000 LB 0x0002a000 C:\WINDOWS\SYSTEM32\WINMMBASE.dll [fFlags=0x0]
145919fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winmmbase.dll [avoiding WinVerifyTrust]
146019fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb3f640000 LB 0x00023000 C:\WINDOWS\SYSTEM32\WINMM.dll [fFlags=0x0]
146119fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winmm.dll
146219fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb03960000 LB 0x009cf000 C:\Program Files\Oracle\VirtualBox\VirtualBox.dll [fFlags=0x0]
146319fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.dll
146419fc.2d74: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\windows.storage.dll'.
146519fc.2d74: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\windows.storage.dll' [rescheduled]
146619fc.2d74: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\powrprof.dll'.
146719fc.2d74: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\powrprof.dll' [rescheduled]
146819fc.2d74: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\kernel.appcore.dll'.
146919fc.2d74: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\kernel.appcore.dll' [rescheduled]
147019fc.2d74: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\SHCore.dll'.
147119fc.2d74: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\SHCore.dll' [rescheduled]
147219fc.2d74: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\cfgmgr32.dll'.
147319fc.2d74: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\cfgmgr32.dll' [rescheduled]
147419fc.2d74: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll'.
147519fc.2d74: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll' [rescheduled]
147619fc.2d74: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.16299.19_none_e48015d00334ec58\comctl32.dll'.
147719fc.2d74: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.16299.19_none_e48015d00334ec58\comctl32.dll' [rescheduled]
147819fc.2d74: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\shlwapi.dll'.
147919fc.2d74: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\shlwapi.dll' [rescheduled]
148019fc.2d74: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\comctl32.dll'.
148119fc.2d74: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\comctl32.dll' [rescheduled]
148219fc.2d74: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\IPHLPAPI.DLL'.
148319fc.2d74: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\IPHLPAPI.DLL' [rescheduled]
148419fc.2d74: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume3\Windows\System32\winspool.drv'.
148519fc.2d74: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\winspool.drv' [rescheduled]
148619fc.2d74: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume3\Windows\System32\comdlg32.dll'.
148719fc.2d74: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\comdlg32.dll' [rescheduled]
148819fc.2d74: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume3\Windows\System32\glu32.dll'.
148919fc.2d74: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\glu32.dll' [rescheduled]
149019fc.2d74: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\mpr.dll'.
149119fc.2d74: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\mpr.dll' [rescheduled]
149219fc.2d74: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\win32u.dll'.
149319fc.2d74: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rescheduled]
149419fc.2d74: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32.dll'.
149519fc.2d74: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rescheduled]
149619fc.2d74: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll'.
149719fc.2d74: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rescheduled]
149819fc.2d74: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\combase.dll'.
149919fc.2d74: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rescheduled]
150019fc.2d74: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\winmmbase.dll'.
150119fc.2d74: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\winmmbase.dll' [rescheduled]
150219fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\kernel32.dll
150319fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'profapi.dll'...
150419fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'profapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\profapi.dll' [rcNtRedir=0xc0150008]
150519fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\profapi.dll
150619fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
150719fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
150819fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\combase.dll [redoing WinVerifyTrust]
150919fc.2d74: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\combase.dll'.
151019fc.2d74: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume3\Windows\System32\combase.dll
151119fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
151219fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
151319fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
151419fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
151519fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
151619fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
151719fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
151819fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
151919fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
152019fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
152119fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
152219fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
152319fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\combase.dll [redoing WinVerifyTrust]
152419fc.2d74: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\combase.dll'.
152519fc.2d74: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume3\Windows\System32\combase.dll
152619fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
152719fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
152819fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
152919fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
153019fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
153119fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
153219fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\win32u.dll [redoing WinVerifyTrust]
153319fc.2d74: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\win32u.dll'.
153419fc.2d74: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume3\Windows\System32\win32u.dll
153519fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
153619fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
153719fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
153819fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
153919fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [redoing WinVerifyTrust]
154019fc.2d74: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32.dll'.
154119fc.2d74: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume3\Windows\System32\gdi32.dll
154219fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
154319fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
154419fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcp_win.dll [redoing WinVerifyTrust]
154519fc.2d74: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll'.
154619fc.2d74: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume3\Windows\System32\msvcp_win.dll
154719fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
154819fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
154919fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
155019fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
155119fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [redoing WinVerifyTrust]
155219fc.2d74: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32.dll'.
155319fc.2d74: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume3\Windows\System32\gdi32.dll
155419fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
155519fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
155619fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\advapi32.dll
155719fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\kernel32.dll (Input=kernel32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
155819fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb43cb0000 'C:\WINDOWS\System32\kernel32.dll'
155919fc.2d74: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-string-l1-1-0) -> 0x0, fPresent=1
156019fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-string-l1-1-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
156119fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41480000 'api-ms-win-core-string-l1-1-0'
156219fc.2d74: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-datetime-l1-1-1) -> 0x0, fPresent=1
156319fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-datetime-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
156419fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41480000 'api-ms-win-core-datetime-l1-1-1'
156519fc.2d74: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-obsolete-l1-2-0) -> 0x0, fPresent=1
156619fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-obsolete-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
156719fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41480000 'api-ms-win-core-localization-obsolete-l1-2-0'
156819fc.2d74: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\imm32.dll'.
156919fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'user32.dll'.
157019fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'win32u.dll'.
157119fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\imm32.dll)
157219fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\imm32.dll
157319fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
157419fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
157519fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\win32u.dll [redoing WinVerifyTrust]
157619fc.2d74: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\win32u.dll'.
157719fc.2d74: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume3\Windows\System32\win32u.dll
157819fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
157919fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
158019fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\IMM32.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
158119fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb44360000 LB 0x0002d000 C:\WINDOWS\System32\IMM32.DLL [fFlags=0x0]
158219fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\imm32.dll [avoiding WinVerifyTrust]
158319fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb44360000 'C:\WINDOWS\system32\IMM32.DLL'
158419fc.2d74: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\imm32.dll'.
158519fc.2d74: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\imm32.dll' [rescheduled]
158619fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\imm32.dll [redoing WinVerifyTrust]
158719fc.2d74: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\imm32.dll'.
158819fc.2d74: supR3HardenedScreenImage/LdrLoadDll: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume3\Windows\System32\imm32.dll
158919fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\imm32.dll (Input=imm32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
159019fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb44360000 'C:\WINDOWS\System32\imm32.dll'
159119fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\advapi32.dll
159219fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\ADVAPI32.DLL (Input=ADVAPI32.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
159319fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb44530000 'C:\WINDOWS\System32\ADVAPI32.DLL'
159419fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb03960000 'C:\Program Files\Oracle\VirtualBox\VirtualBox.dll'
159519fc.2d74: SUPR3HardenedMain: Calling TrustedMain (00007ffb039614f0)...
159619fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
159719fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
159819fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'ole32.dll'.
159919fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
160019fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'imm32.dll'.
160119fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'winmm.dll'.
160219fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
160319fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'shell32.dll'.
160419fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'advapi32.dll'.
160519fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'qt5guivbox.dll'.
160619fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'qt5corevbox.dll'.
160719fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'msvcr100.dll'.
160819fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\platforms\qwindows.dll) WinVerifyTrust
160919fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\platforms\qwindows.dll
161019fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
161119fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
161219fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
161319fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
161419fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
161519fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
161619fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
161719fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
161819fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
161919fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
162019fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\advapi32.dll
162119fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
162219fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume3\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
162319fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shell32.dll
162419fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
162519fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume3\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
162619fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\oleaut32.dll
162719fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
162819fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume3\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
162919fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winmm.dll
163019fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
163119fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume3\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
163219fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\imm32.dll [redoing WinVerifyTrust]
163319fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
163419fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
163519fc.2d74: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\imm32.dll'
163619fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
163719fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
163819fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\user32.dll
163919fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
164019fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
164119fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ole32.dll
164219fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
164319fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
164419fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [redoing WinVerifyTrust]
164519fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
164619fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
164719fc.2d74: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\gdi32.dll'
164819fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\platforms\qwindows.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
164919fc.2d74: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\platforms\qwindows.dll
165019fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb156f0000 LB 0x0012e000 C:\Program Files\Oracle\VirtualBox\platforms\qwindows.dll [fFlags=0x0]
165119fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\platforms\qwindows.dll
165219fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb156f0000 'C:\Program Files\Oracle\VirtualBox\platforms\qwindows.dll'
165319fc.2d74: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000640 pwszName=\Device\HarddiskVolume3\Windows\System32\uxtheme.dll
165419fc.2d74: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000398aff0
165519fc.2d74: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000398aff0
165619fc.2d74: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=0AB199956403E78CE61C981F6BA97CA632BE55AC
165719fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
165819fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
165919fc.2d74: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package00114~31bf3856ad364e35~amd64~~10.0.16299.15.cat'; file='\Device\HarddiskVolume3\Windows\System32\uxtheme.dll'
166019fc.2d74: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
166119fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
166219fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #33 'gdi32.dll'.
166319fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #34 'user32.dll'.
166419fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\uxtheme.dll) WinVerifyTrust
166519fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\uxtheme.dll
166619fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
166719fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
166819fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
166919fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
167019fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
167119fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
167219fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll
167319fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
167419fc.2d74: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\uxtheme.dll
167519fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb3fb90000 LB 0x00095000 C:\WINDOWS\system32\uxtheme.dll [fFlags=0x0]
167619fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\uxtheme.dll
167719fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3fb90000 'C:\WINDOWS\system32\uxtheme.dll'
167819fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb44ba0000 'C:\WINDOWS\system32\user32.dll'
167919fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shell32.dll
168019fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
168119fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb426a0000 'C:\WINDOWS\system32\shell32.dll'
168219fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\SHCore.dll [redoing WinVerifyTrust]
168319fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
168419fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
168519fc.2d74: supR3HardenedScreenImage/LdrLoadDll: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\SHCore.dll'
168619fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\SHCore.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
168719fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb44a40000 'C:\WINDOWS\system32\SHCore.dll'
168819fc.2d74: supR3HardenedMonitor_LdrLoadDll: error opening 'C:\WINDOWS\system32\wintab32.dll': 0 (NtPath=\??\C:\WINDOWS\system32\wintab32.dll; Input=C:\WINDOWS\system32\wintab32.dll; rcNtGetDll=0x0
168919fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000034 'C:\WINDOWS\system32\wintab32.dll'
169019fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
169119fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #22 'win32u.dll'.
169219fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'user32.dll'.
169319fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #24 'gdi32.dll'.
169419fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\dwmapi.dll)
169519fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\dwmapi.dll
169619fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb3fc60000 LB 0x0002a000 C:\WINDOWS\system32\dwmapi.dll [fFlags=0x0]
169719fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dwmapi.dll [avoiding WinVerifyTrust]
169819fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
169919fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
170019fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
170119fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
170219fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
170319fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
170419fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\win32u.dll [lacks WinVerifyTrust]
170519fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
170619fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
170719fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
170819fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
170919fc.2d74: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\dwmapi.dll'
171019fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winmm.dll
171119fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\winmm.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
171219fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3f640000 'C:\WINDOWS\system32\winmm.dll'
171319fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winmm.dll
171419fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\winmm.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
171519fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3f640000 'C:\WINDOWS\system32\winmm.dll'
171619fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shell32.dll
171719fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
171819fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb426a0000 'C:\WINDOWS\system32\shell32.dll'
171919fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\uxtheme.dll
172019fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
172119fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3fb90000 'C:\WINDOWS\system32\uxtheme.dll'
172219fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\advapi32.dll
172319fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\advapi32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
172419fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb44530000 'C:\WINDOWS\system32\advapi32.dll'
172519fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
172619fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
172719fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'rpcrt4.dll'.
172819fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 'profapi.dll'.
172919fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\userenv.dll) WinVerifyTrust
173019fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\userenv.dll
173119fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'profapi.dll'...
173219fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'profapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\profapi.dll' [rcNtRedir=0xc0150008]
173319fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\profapi.dll
173419fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
173519fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
173619fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\userenv.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
173719fc.2d74: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\userenv.dll
173819fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb412d0000 LB 0x00029000 C:\WINDOWS\system32\userenv.dll [fFlags=0x0]
173919fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\userenv.dll
174019fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb412d0000 'C:\WINDOWS\system32\userenv.dll'
174119fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\kernel32.dll
174219fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\kernel32.dll (Input=kernel32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
174319fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb43cb0000 'C:\WINDOWS\System32\kernel32.dll'
174419fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb44af0000 LB 0x0009e000 C:\WINDOWS\System32\clbcatq.dll [fFlags=0x0]
174519fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
174619fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #28 'rpcrt4.dll'.
174719fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\clbcatq.dll)
174819fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\clbcatq.dll
174919fc.2908: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
175019fc.2908: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
175119fc.2908: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll
175219fc.2908: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
175319fc.2908: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
175419fc.2908: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
175519fc.2908: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
175619fc.2908: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\clbcatq.dll'
175719fc.2908: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
175819fc.2908: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
175919fc.2908: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
176019fc.2908: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
176119fc.2908: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
176219fc.2908: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ole32.dll'.
176319fc.2908: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'oleaut32.dll'.
176419fc.2908: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxC.dll) WinVerifyTrust
176519fc.2908: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxC.dll
176619fc.2908: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
176719fc.2908: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume3\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
176819fc.2908: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\oleaut32.dll
176919fc.2908: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
177019fc.2908: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
177119fc.2908: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ole32.dll
177219fc.2908: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
177319fc.2908: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
177419fc.2908: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
177519fc.2908: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
177619fc.2908: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
177719fc.2908: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
177819fc.2908: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll
177919fc.2908: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
178019fc.2908: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
178119fc.2908: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxC.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
178219fc.2908: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxC.dll
178319fc.2908: supR3HardenedDllNotificationCallback: load 00007ffb02e60000 LB 0x004ff000 C:\Program Files\Oracle\VirtualBox\VBoxC.dll [fFlags=0x0]
178419fc.2908: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxC.dll
178519fc.2908: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb02e60000 'C:\Program Files\Oracle\VirtualBox\VBoxC.dll'
178619fc.2908: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
178719fc.2908: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
178819fc.2908: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
178919fc.2908: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
179019fc.2908: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'shlwapi.dll'.
179119fc.2908: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ole32.dll'.
179219fc.2908: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'oleaut32.dll'.
179319fc.2908: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
179419fc.2908: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll) WinVerifyTrust
179519fc.2908: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll
179619fc.2908: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
179719fc.2908: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
179819fc.2908: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
179919fc.2908: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume3\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
180019fc.2908: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\oleaut32.dll
180119fc.2908: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
180219fc.2908: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
180319fc.2908: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ole32.dll
180419fc.2908: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
180519fc.2908: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
180619fc.2908: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shlwapi.dll [redoing WinVerifyTrust]
180719fc.2908: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
180819fc.2908: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
180919fc.2908: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\shlwapi.dll'
181019fc.2908: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
181119fc.2908: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
181219fc.2908: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
181319fc.2908: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
181419fc.2908: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
181519fc.2908: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
181619fc.2908: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
181719fc.2908: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll
181819fc.2908: supR3HardenedDllNotificationCallback: load 00007ffb15630000 LB 0x000ba000 C:\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll [fFlags=0x0]
181919fc.2908: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll
182019fc.2908: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb15630000 'C:\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll'
182119fc.2908: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\oleaut32.dll
182219fc.2908: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\oleaut32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
182319fc.2908: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb43bd0000 'C:\Windows\System32\oleaut32.dll'
182419fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll
182519fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\gdi32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
182619fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb42670000 'C:\WINDOWS\system32\gdi32.dll'
182719fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shell32.dll
182819fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
182919fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb426a0000 'C:\WINDOWS\system32\shell32.dll'
183019fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb44170000 LB 0x00167000 C:\WINDOWS\System32\MSCTF.dll [fFlags=0x0]
183119fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
183219fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #19 'oleaut32.dll'.
183319fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #36 'user32.dll'.
183419fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #37 'gdi32.dll'.
183519fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #38 'imm32.dll'.
183619fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\msctf.dll)
183719fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\msctf.dll
183819fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
183919fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume3\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
184019fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\imm32.dll
184119fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
184219fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
184319fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
184419fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
184519fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
184619fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume3\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
184719fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\oleaut32.dll
184819fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
184919fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
185019fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
185119fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
185219fc.2d74: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\msctf.dll'
185319fc.2d74: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000009c4 pwszName=\Device\HarddiskVolume3\Windows\System32\DataExchange.dll
185419fc.2d74: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000398aff0
185519fc.2d74: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000398aff0
185619fc.2d74: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=87FA668FC207CB724FFDD342C6B5B8D273E3498D
185719fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
185819fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
185919fc.2d74: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0010~31bf3856ad364e35~amd64~~10.0.16299.15.cat'; file='\Device\HarddiskVolume3\Windows\System32\DataExchange.dll'
186019fc.2d74: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
186119fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
186219fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'shcore.dll'.
186319fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #28 'combase.dll'.
186419fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #31 'd3d11.dll'.
186519fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #32 'dcomp.dll'.
186619fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\DataExchange.dll) WinVerifyTrust
186719fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\DataExchange.dll
186819fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dcomp.dll'...
186919fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'dcomp.dll' -> '\Device\HarddiskVolume3\Windows\System32\dcomp.dll' [rcNtRedir=0xc0150008]
187019fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
187119fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
187219fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'win32u.dll'.
187319fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
187419fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\dcomp.dll) WinVerifyTrust
187519fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\dcomp.dll
187619fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'd3d11.dll'...
187719fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'd3d11.dll' -> '\Device\HarddiskVolume3\Windows\System32\d3d11.dll' [rcNtRedir=0xc0150008]
187819fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
187919fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
188019fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
188119fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
188219fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\win32u.dll [lacks WinVerifyTrust]
188319fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
188419fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
188519fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
188619fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'dxgi.dll'.
188719fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #35 'win32u.dll'.
188819fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\d3d11.dll) WinVerifyTrust
188919fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\d3d11.dll
189019fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
189119fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
189219fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\combase.dll [redoing WinVerifyTrust]
189319fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
189419fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
189519fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\win32u.dll [lacks WinVerifyTrust]
189619fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dxgi.dll'...
189719fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'dxgi.dll' -> '\Device\HarddiskVolume3\Windows\System32\dxgi.dll' [rcNtRedir=0xc0150008]
189819fc.2d74: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\dxgi.dll'.
189919fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
190019fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'win32u.dll'.
190119fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\dxgi.dll)
190219fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\dxgi.dll
190319fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
190419fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
190519fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
190619fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
190719fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\win32u.dll [lacks WinVerifyTrust]
190819fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
190919fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
191019fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
191119fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
191219fc.2d74: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\combase.dll'
191319fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shcore.dll'...
191419fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'shcore.dll' -> '\Device\HarddiskVolume3\Windows\System32\shcore.dll' [rcNtRedir=0xc0150008]
191519fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\SHCore.dll
191619fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
191719fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
191819fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\dataexchange.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
191919fc.2d74: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\DataExchange.dll
192019fc.2d74: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\d3d11.dll
192119fc.2d74: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dcomp.dll
192219fc.2d74: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dxgi.dll [avoiding WinVerifyTrust]
192319fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb40240000 LB 0x000af000 C:\WINDOWS\system32\dxgi.dll [fFlags=0x0]
192419fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dxgi.dll [avoiding WinVerifyTrust]
192519fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb3e830000 LB 0x002e2000 C:\WINDOWS\system32\d3d11.dll [fFlags=0x0]
192619fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\d3d11.dll
192719fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb3f1c0000 LB 0x00142000 C:\WINDOWS\system32\dcomp.dll [fFlags=0x0]
192819fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dcomp.dll
192919fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb215f0000 LB 0x0004f000 C:\WINDOWS\system32\dataexchange.dll [fFlags=0x0]
193019fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\DataExchange.dll
193119fc.2d74: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\dxgi.dll'.
193219fc.2d74: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\dxgi.dll' [rescheduled]
193319fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb42670000 'C:\WINDOWS\System32\gdi32.dll'
193419fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb215f0000 'C:\WINDOWS\system32\dataexchange.dll'
193519fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
193619fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'rmclient.dll'.
193719fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #30 'rpcrt4.dll'.
193819fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #32 'bcrypt.dll'.
193919fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #45 'combase.dll'.
194019fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\twinapi.appcore.dll)
194119fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\twinapi.appcore.dll
194219fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
194319fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'rpcrt4.dll'.
194419fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\rmclient.dll)
194519fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\rmclient.dll
194619fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb3ff00000 LB 0x00020000 C:\WINDOWS\system32\RMCLIENT.dll [fFlags=0x0]
194719fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rmclient.dll [avoiding WinVerifyTrust]
194819fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb3fd50000 LB 0x0017b000 C:\WINDOWS\system32\twinapi.appcore.dll [fFlags=0x0]
194919fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\twinapi.appcore.dll [avoiding WinVerifyTrust]
195019fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
195119fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'coreuicomponents.dll'.
195219fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'coremessaging.dll'.
195319fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\TextInputFramework.dll)
195419fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\TextInputFramework.dll
195519fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
195619fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #35 'coremessaging.dll'.
195719fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #48 'shcore.dll'.
195819fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\CoreUIComponents.dll)
195919fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\CoreUIComponents.dll
196019fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
196119fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #24 'rpcrt4.dll'.
196219fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\CoreMessaging.dll)
196319fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\CoreMessaging.dll
196419fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\ntmarta.dll)
196519fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\ntmarta.dll
196619fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'combase.dll'.
196719fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #21 'rpcrt4.dll'.
196819fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #28 'bcryptprimitives.dll'.
196919fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\WinTypes.dll)
197019fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\WinTypes.dll
197119fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb40510000 LB 0x00031000 C:\WINDOWS\SYSTEM32\ntmarta.dll [fFlags=0x0]
197219fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ntmarta.dll [avoiding WinVerifyTrust]
197319fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb3f0e0000 LB 0x000dd000 C:\WINDOWS\System32\CoreMessaging.dll [fFlags=0x0]
197419fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\CoreMessaging.dll [avoiding WinVerifyTrust]
197519fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb3da20000 LB 0x00136000 C:\WINDOWS\SYSTEM32\wintypes.dll [fFlags=0x0]
197619fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\WinTypes.dll [avoiding WinVerifyTrust]
197719fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb3bee0000 LB 0x002ee000 C:\WINDOWS\System32\CoreUIComponents.dll [fFlags=0x0]
197819fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\CoreUIComponents.dll [avoiding WinVerifyTrust]
197919fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb2db50000 LB 0x00098000 C:\WINDOWS\System32\TextInputFramework.dll [fFlags=0x0]
198019fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\TextInputFramework.dll [avoiding WinVerifyTrust]
198119fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcryptprimitives.dll'...
198219fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcryptprimitives.dll' -> '\Device\HarddiskVolume3\Windows\System32\bcryptprimitives.dll' [rcNtRedir=0xc0150008]
198319fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\bcryptprimitives.dll
198419fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
198519fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
198619fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
198719fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
198819fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\combase.dll
198919fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
199019fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
199119fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
199219fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
199319fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shcore.dll'...
199419fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'shcore.dll' -> '\Device\HarddiskVolume3\Windows\System32\shcore.dll' [rcNtRedir=0xc0150008]
199519fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\SHCore.dll
199619fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'coremessaging.dll'...
199719fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'coremessaging.dll' -> '\Device\HarddiskVolume3\Windows\System32\coremessaging.dll' [rcNtRedir=0xc0150008]
199819fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\CoreMessaging.dll [lacks WinVerifyTrust]
199919fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
200019fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
200119fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'coremessaging.dll'...
200219fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'coremessaging.dll' -> '\Device\HarddiskVolume3\Windows\System32\coremessaging.dll' [rcNtRedir=0xc0150008]
200319fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\CoreMessaging.dll [lacks WinVerifyTrust]
200419fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'coreuicomponents.dll'...
200519fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'coreuicomponents.dll' -> '\Device\HarddiskVolume3\Windows\System32\coreuicomponents.dll' [rcNtRedir=0xc0150008]
200619fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\CoreUIComponents.dll [lacks WinVerifyTrust]
200719fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
200819fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
200919fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
201019fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
201119fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
201219fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
201319fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
201419fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
201519fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\combase.dll
201619fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
201719fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume3\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
201819fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\bcrypt.dll
201919fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
202019fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
202119fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rmclient.dll'...
202219fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'rmclient.dll' -> '\Device\HarddiskVolume3\Windows\System32\rmclient.dll' [rcNtRedir=0xc0150008]
202319fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rmclient.dll [lacks WinVerifyTrust]
202419fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
202519fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
202619fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
202719fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
202819fc.2d74: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\WinTypes.dll'
202919fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
203019fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
203119fc.2d74: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\ntmarta.dll'
203219fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll
203319fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
203419fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
203519fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
203619fc.2d74: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\CoreMessaging.dll'
203719fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
203819fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
203919fc.2d74: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\CoreUIComponents.dll'
204019fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
204119fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
204219fc.2d74: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\TextInputFramework.dll'
204319fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
204419fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
204519fc.2d74: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\rmclient.dll'
204619fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
204719fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
204819fc.2d74: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\twinapi.appcore.dll'
204919fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\oleaut32.dll
205019fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\OLEAUT32.DLL (Input=OLEAUT32.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
205119fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb43bd0000 'C:\WINDOWS\System32\OLEAUT32.DLL'
205219fc.2d74: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(ext-ms-win-rtcore-ntuser-window-ext-l1-1-0.dll) -> 0x0, fPresent=1
205319fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=ext-ms-win-rtcore-ntuser-window-ext-l1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
205419fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb44ba0000 'ext-ms-win-rtcore-ntuser-window-ext-l1-1-0.dll'
205519fc.2d74: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(ext-ms-win-rtcore-ntuser-integration-l1-1-0.dll) -> 0x0, fPresent=1
205619fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=ext-ms-win-rtcore-ntuser-integration-l1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
205719fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb44ba0000 'ext-ms-win-rtcore-ntuser-integration-l1-1-0.dll'
205819fc.2d74: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-com-l1-1-0.dll) -> 0x0, fPresent=1
205919fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-com-l1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
206019fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb43e60000 'api-ms-win-core-com-l1-1-0.dll'
206119fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msctf.dll
206219fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\MSCTF.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
206319fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb44170000 'C:\WINDOWS\System32\MSCTF.dll'
206419fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb426a0000 'C:\WINDOWS\system32\shell32.dll'
206519fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb426a0000 'C:\WINDOWS\system32\shell32.dll'
206619fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ole32.dll
206719fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\ole32.dll (Input=ole32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
206819fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb44f00000 'C:\WINDOWS\System32\ole32.dll'
206919fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\oleaut32.dll
207019fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\OLEAUT32.dll (Input=OLEAUT32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
207119fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb43bd0000 'C:\WINDOWS\System32\OLEAUT32.dll'
207219fc.2d74: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000ad8 pwszName=\Device\HarddiskVolume3\Windows\System32\wbem\wbemprox.dll
207319fc.2d74: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000398aff0
207419fc.2d74: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000398aff0
207519fc.2d74: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=AE2733DC030E44DCE443886E467FF179D2D68A91
207619fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
207719fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
207819fc.2d74: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package01~31bf3856ad364e35~amd64~~10.0.16299.15.cat'; file='\Device\HarddiskVolume3\Windows\System32\wbem\wbemprox.dll'
207919fc.2d74: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
208019fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
208119fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ws2_32.dll'.
208219fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'wbemcomn.dll'.
208319fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\wbem\wbemprox.dll) WinVerifyTrust
208419fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\wbem\wbemprox.dll
208519fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wbemcomn.dll'...
208619fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'wbemcomn.dll' -> '\Device\HarddiskVolume3\Windows\System32\wbemcomn.dll' [rcNtRedir=0xc0150008]
208719fc.2d74: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000ae4 pwszName=\Device\HarddiskVolume3\Windows\System32\wbemcomn.dll
208819fc.2d74: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000398aff0
208919fc.2d74: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000398aff0
209019fc.2d74: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=CA3F9D85214DB0270185C719B931C69440BA9C18
209119fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
209219fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
209319fc.2d74: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package01~31bf3856ad364e35~amd64~~10.0.16299.15.cat'; file='\Device\HarddiskVolume3\Windows\System32\wbemcomn.dll'
209419fc.2d74: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
209519fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
209619fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'bcrypt.dll'.
209719fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'ws2_32.dll'.
209819fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\wbemcomn.dll) WinVerifyTrust
209919fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\wbemcomn.dll
210019fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
210119fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
210219fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ws2_32.dll
210319fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
210419fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
210519fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
210619fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
210719fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ws2_32.dll
210819fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
210919fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume3\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
211019fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\bcrypt.dll
211119fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
211219fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
211319fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\wbem\wbemprox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
211419fc.2d74: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wbem\wbemprox.dll
211519fc.2d74: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wbemcomn.dll
211619fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb3af70000 LB 0x00081000 C:\WINDOWS\SYSTEM32\wbemcomn.dll [fFlags=0x0]
211719fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wbemcomn.dll
211819fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb3c1e0000 LB 0x0000f000 C:\WINDOWS\system32\wbem\wbemprox.dll [fFlags=0x0]
211919fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wbem\wbemprox.dll
212019fc.2d74: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(API-MS-Win-Core-LocalRegistry-L1-1-0.dll) -> 0x0, fPresent=1
212119fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Core-LocalRegistry-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
212219fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41480000 'API-MS-Win-Core-LocalRegistry-L1-1-0.dll'
212319fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3c1e0000 'C:\WINDOWS\system32\wbem\wbemprox.dll'
212419fc.2d74: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000af4 pwszName=\Device\HarddiskVolume3\Windows\System32\wbem\wbemsvc.dll
212519fc.2d74: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000398aff0
212619fc.2d74: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000398aff0
212719fc.2d74: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=4C70145BD7347C12AB1BF3946D40606389C4D331
212819fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
212919fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
213019fc.2d74: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package01~31bf3856ad364e35~amd64~~10.0.16299.15.cat'; file='\Device\HarddiskVolume3\Windows\System32\wbem\wbemsvc.dll'
213119fc.2d74: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
213219fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
213319fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'rpcrt4.dll'.
213419fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\wbem\wbemsvc.dll) WinVerifyTrust
213519fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\wbem\wbemsvc.dll
213619fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
213719fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
213819fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
213919fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
214019fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\wbem\wbemsvc.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
214119fc.2d74: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wbem\wbemsvc.dll
214219fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb383a0000 LB 0x00014000 C:\WINDOWS\system32\wbem\wbemsvc.dll [fFlags=0x0]
214319fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wbem\wbemsvc.dll
214419fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb383a0000 'C:\WINDOWS\system32\wbem\wbemsvc.dll'
214519fc.2d74: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-l1-2-0.dll) -> 0x0, fPresent=1
214619fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-l1-2-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
214719fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41480000 'api-ms-win-core-localization-l1-2-0.dll'
214819fc.2d74: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-obsolete-l1-1-0.dll) -> 0x0, fPresent=1
214919fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-obsolete-l1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
215019fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41480000 'api-ms-win-core-localization-obsolete-l1-1-0.dll'
215119fc.2d74: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000b40 pwszName=\Device\HarddiskVolume3\Windows\System32\wbem\fastprox.dll
215219fc.2d74: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000398aff0
215319fc.2d74: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000398aff0
215419fc.2d74: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=336CDD3C969CEFC6CE8D502298ED123FE8D2F483
215519fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
215619fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
215719fc.2d74: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package01~31bf3856ad364e35~amd64~~10.0.16299.15.cat'; file='\Device\HarddiskVolume3\Windows\System32\wbem\fastprox.dll'
215819fc.2d74: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
215919fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
216019fc.2d74: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #19 'wbemcomn.dll'.
216119fc.2d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\wbem\fastprox.dll) WinVerifyTrust
216219fc.2d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\wbem\fastprox.dll
216319fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wbemcomn.dll'...
216419fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'wbemcomn.dll' -> '\Device\HarddiskVolume3\Windows\System32\wbemcomn.dll' [rcNtRedir=0xc0150008]
216519fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wbemcomn.dll
216619fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
216719fc.2d74: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
216819fc.2d74: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll
216919fc.2d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\wbem\fastprox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
217019fc.2d74: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wbem\fastprox.dll
217119fc.2d74: supR3HardenedDllNotificationCallback: load 00007ffb383c0000 LB 0x000f0000 C:\WINDOWS\system32\wbem\fastprox.dll [fFlags=0x0]
217219fc.2d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wbem\fastprox.dll
217319fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb383c0000 'C:\WINDOWS\system32\wbem\fastprox.dll'
217419fc.2c2c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
217519fc.2c2c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
217619fc.2c2c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrem.dll'.
217719fc.2c2c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
217819fc.2c2c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxVMM.dll) WinVerifyTrust
217919fc.2c2c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxVMM.dll
218019fc.2c2c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
218119fc.2c2c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
218219fc.2c2c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrem.dll'...
218319fc.2c2c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrem.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxrem.dll' [rcNtRedir=0xc0150008]
218419fc.2c2c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
218519fc.2c2c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'vboxrt.dll'.
218619fc.2c2c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
218719fc.2c2c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcrt.dll'.
218819fc.2c2c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxREM.dll) WinVerifyTrust
218919fc.2c2c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxREM.dll
219019fc.2c2c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
219119fc.2c2c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
219219fc.2c2c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
219319fc.2c2c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
219419fc.2c2c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
219519fc.2c2c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
219619fc.2c2c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxVMM.dll
219719fc.2c2c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
219819fc.2c2c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
219919fc.2c2c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
220019fc.2c2c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxVMM.dll
220119fc.2c2c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxREM.dll
220219fc.2c2c: supR3HardenedDllNotificationCallback: load 000000006e5d0000 LB 0x0010b000 C:\Program Files\Oracle\VirtualBox\VBoxREM.dll [fFlags=0x0]
220319fc.2c2c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxREM.dll
220419fc.2c2c: supR3HardenedDllNotificationCallback: load 00007ffafc040000 LB 0x002c7000 C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL [fFlags=0x0]
220519fc.2c2c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxVMM.dll
220619fc.2c2c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafc040000 'C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL'
220719fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
220819fc.167c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000c08 pwszName=\Device\HarddiskVolume3\Windows\System32\NetSetupShim.dll
220919fc.167c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000398aff0
221019fc.167c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000398aff0
221119fc.167c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F30E80B88384D221750DC79ADCE84BDFB8A5A73A
221219fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
221319fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
221419fc.167c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package00111~31bf3856ad364e35~amd64~~10.0.16299.15.cat'; file='\Device\HarddiskVolume3\Windows\System32\NetSetupShim.dll'
221519fc.167c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
221619fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
221719fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #30 'rpcrt4.dll'.
221819fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #31 'oleaut32.dll'.
221919fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #33 'ws2_32.dll'.
222019fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #34 'netsetupapi.dll'.
222119fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #35 'setupapi.dll'.
222219fc.167c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\NetSetupShim.dll) WinVerifyTrust
222319fc.167c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\NetSetupShim.dll
222419fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
222519fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
222619fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
222719fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
222819fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
222919fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #29 'rpcrt4.dll'.
223019fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #37 'cfgmgr32.dll'.
223119fc.167c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\setupapi.dll) WinVerifyTrust
223219fc.167c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\setupapi.dll
223319fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'netsetupapi.dll'...
223419fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'netsetupapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\netsetupapi.dll' [rcNtRedir=0xc0150008]
223519fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
223619fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume3\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
223719fc.167c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\cfgmgr32.dll [lacks WinVerifyTrust]
223819fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
223919fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
224019fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
224119fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
224219fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
224319fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
224419fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
224519fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'rpcrt4.dll'.
224619fc.167c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\NetSetupApi.dll) WinVerifyTrust
224719fc.167c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\NetSetupApi.dll
224819fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
224919fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
225019fc.167c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ws2_32.dll
225119fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
225219fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume3\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
225319fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
225419fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
225519fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
225619fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
225719fc.167c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcp_win.dll [redoing WinVerifyTrust]
225819fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
225919fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
226019fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
226119fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
226219fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
226319fc.167c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll
226419fc.167c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
226519fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
226619fc.167c: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll'
226719fc.167c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\NetSetupShim.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
226819fc.167c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\NetSetupShim.dll
226919fc.167c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\NetSetupApi.dll
227019fc.167c: supR3HardenedDllNotificationCallback: load 00007ffb35db0000 LB 0x00026000 C:\Windows\System32\NetSetupApi.dll [fFlags=0x0]
227119fc.167c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\NetSetupApi.dll
227219fc.167c: supR3HardenedDllNotificationCallback: load 00007ffb445e0000 LB 0x0044e000 C:\WINDOWS\System32\setupapi.dll [fFlags=0x0]
227319fc.167c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\setupapi.dll
227419fc.167c: supR3HardenedDllNotificationCallback: load 00007ffb35ec0000 LB 0x0007d000 C:\Windows\System32\NetSetupShim.dll [fFlags=0x0]
227519fc.167c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\NetSetupShim.dll
227619fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb35ec0000 'C:\Windows\System32\NetSetupShim.dll'
227719fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
227819fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
227919fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
228019fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #24 'rpcrt4.dll'.
228119fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'nsi.dll'.
228219fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'winnsi.dll'.
228319fc.167c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\NetSetupEngine.dll) WinVerifyTrust
228419fc.167c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\NetSetupEngine.dll
228519fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winnsi.dll'...
228619fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'winnsi.dll' -> '\Device\HarddiskVolume3\Windows\System32\winnsi.dll' [rcNtRedir=0xc0150008]
228719fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
228819fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
228919fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rpcrt4.dll'.
229019fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'nsi.dll'.
229119fc.167c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\winnsi.dll) WinVerifyTrust
229219fc.167c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\winnsi.dll
229319fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
229419fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume3\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
229519fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
229619fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume3\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
229719fc.167c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\nsi.dll'.
229819fc.167c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\nsi.dll)
229919fc.167c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\nsi.dll
230019fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
230119fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
230219fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
230319fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
230419fc.167c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\nsi.dll) WinVerifyTrust
230519fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
230619fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
230719fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
230819fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
230919fc.167c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\NetSetupEngine.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
231019fc.167c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\NetSetupEngine.dll
231119fc.167c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winnsi.dll
231219fc.167c: supR3HardenedDllNotificationCallback: load 00007ffb44a30000 LB 0x00008000 C:\WINDOWS\System32\NSI.dll [fFlags=0x0]
231319fc.167c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\nsi.dll [avoiding WinVerifyTrust]
231419fc.167c: supR3HardenedDllNotificationCallback: load 00007ffb3c330000 LB 0x0000b000 C:\WINDOWS\SYSTEM32\WINNSI.DLL [fFlags=0x0]
231519fc.167c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winnsi.dll
231619fc.167c: supR3HardenedDllNotificationCallback: load 00007ffb15820000 LB 0x000c1000 C:\Windows\System32\NetSetupEngine.dll [fFlags=0x0]
231719fc.167c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\NetSetupEngine.dll
231819fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb15820000 'C:\Windows\System32\NetSetupEngine.dll'
231919fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
232019fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
232119fc.167c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\nsi.dll'
232219fc.20b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
232319fc.20b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
232419fc.20b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
232519fc.20b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
232619fc.20b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
232719fc.20b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll) WinVerifyTrust
232819fc.20b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll
232919fc.20b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
233019fc.20b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
233119fc.20b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
233219fc.20b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
233319fc.20b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
233419fc.20b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
233519fc.20b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxVMM.dll
233619fc.20b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
233719fc.20b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
233819fc.20b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
233919fc.20b4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll
234019fc.20b4: supR3HardenedDllNotificationCallback: load 00007ffb3ce90000 LB 0x0000b000 C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL [fFlags=0x0]
234119fc.20b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll
234219fc.20b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3ce90000 'C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL'
234319fc.20b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb44ba0000 'C:\WINDOWS\system32\User32.dll'
234419fc.a04: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
234519fc.a04: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
234619fc.a04: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
234719fc.a04: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
234819fc.a04: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll) WinVerifyTrust
234919fc.a04: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll
235019fc.a04: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
235119fc.a04: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
235219fc.a04: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
235319fc.a04: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
235419fc.a04: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll
235519fc.a04: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
235619fc.a04: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
235719fc.a04: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
235819fc.a04: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll
235919fc.a04: supR3HardenedDllNotificationCallback: load 00007ffb35880000 LB 0x0000d000 C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL [fFlags=0x0]
236019fc.a04: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll
236119fc.a04: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb35880000 'C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL'
236219fc.2194: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
236319fc.2194: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
236419fc.2194: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
236519fc.2194: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
236619fc.2194: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll) WinVerifyTrust
236719fc.2194: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll
236819fc.2194: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
236919fc.2194: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
237019fc.2194: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
237119fc.2194: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
237219fc.2194: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
237319fc.2194: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
237419fc.2194: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
237519fc.2194: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll
237619fc.2194: supR3HardenedDllNotificationCallback: load 00007ffb350a0000 LB 0x0000c000 C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL [fFlags=0x0]
237719fc.2194: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll
237819fc.2194: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb350a0000 'C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL'
237919fc.2ba0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
238019fc.2ba0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
238119fc.2ba0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
238219fc.2ba0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
238319fc.2ba0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll) WinVerifyTrust
238419fc.2ba0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll
238519fc.2ba0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
238619fc.2ba0: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
238719fc.2ba0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
238819fc.2ba0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
238919fc.2ba0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
239019fc.2ba0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
239119fc.2ba0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll
239219fc.2ba0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
239319fc.2ba0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll
239419fc.2ba0: supR3HardenedDllNotificationCallback: load 00007ffb34d10000 LB 0x0000b000 C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL [fFlags=0x0]
239519fc.2ba0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll
239619fc.2ba0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb34d10000 'C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL'
239719fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb426a0000 'C:\WINDOWS\system32\Shell32.dll'
239819fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
239919fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
240019fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
240119fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
240219fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
240319fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vboxddu.dll'.
240419fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'vboxdd2.dll'.
240519fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
240619fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'setupapi.dll'.
240719fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'ws2_32.dll'.
240819fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'ole32.dll'.
240919fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'iphlpapi.dll'.
241019fc.167c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxDD.dll) WinVerifyTrust
241119fc.167c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxDD.dll
241219fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'iphlpapi.dll'...
241319fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'iphlpapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\iphlpapi.dll' [rcNtRedir=0xc0150008]
241419fc.167c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\IPHLPAPI.DLL [redoing WinVerifyTrust]
241519fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
241619fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
241719fc.167c: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\IPHLPAPI.DLL'
241819fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
241919fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
242019fc.167c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ole32.dll
242119fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
242219fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
242319fc.167c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ws2_32.dll
242419fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
242519fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
242619fc.167c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\setupapi.dll
242719fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
242819fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
242919fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxdd2.dll'...
243019fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxdd2.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxdd2.dll' [rcNtRedir=0xc0150008]
243119fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
243219fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
243319fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
243419fc.167c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxDD2.dll) WinVerifyTrust
243519fc.167c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxDD2.dll
243619fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxddu.dll'...
243719fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxddu.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxddu.dll' [rcNtRedir=0xc0150008]
243819fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
243919fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
244019fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
244119fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
244219fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
244319fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
244419fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
244519fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
244619fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'setupapi.dll'.
244719fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'advapi32.dll'.
244819fc.167c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxDDU.dll) WinVerifyTrust
244919fc.167c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxDDU.dll
245019fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
245119fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
245219fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
245319fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
245419fc.167c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxVMM.dll
245519fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
245619fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
245719fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
245819fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
245919fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
246019fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
246119fc.167c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\setupapi.dll
246219fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
246319fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
246419fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
246519fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
246619fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
246719fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
246819fc.167c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxDD.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
246919fc.167c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxDD.dll
247019fc.167c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxDDU.dll
247119fc.167c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxDD2.dll
247219fc.167c: supR3HardenedDllNotificationCallback: load 00007ffb155c0000 LB 0x00063000 C:\Program Files\Oracle\VirtualBox\VBoxDDU.dll [fFlags=0x0]
247319fc.167c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxDDU.dll
247419fc.167c: supR3HardenedDllNotificationCallback: load 00007ffb06510000 LB 0x0005d000 C:\Program Files\Oracle\VirtualBox\VBoxDD2.dll [fFlags=0x0]
247519fc.167c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxDD2.dll
247619fc.167c: supR3HardenedDllNotificationCallback: load 00007ffafb680000 LB 0x009bf000 C:\Program Files\Oracle\VirtualBox\VBoxDD.DLL [fFlags=0x0]
247719fc.167c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxDD.dll
247819fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafb680000 'C:\Program Files\Oracle\VirtualBox\VBoxDD.DLL'
247919fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
248019fc.167c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxC.dll
248119fc.167c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxC.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
248219fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb02e60000 'C:\Program Files\Oracle\VirtualBox\VBoxC.DLL'
248319fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
248419fc.167c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxDD2.dll
248519fc.167c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxDD2.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
248619fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb06510000 'C:\Program Files\Oracle\VirtualBox\VBoxDD2.DLL'
248719fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
248819fc.7fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
248919fc.7fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
249019fc.7fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
249119fc.7fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
249219fc.7fc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll) WinVerifyTrust
249319fc.7fc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll
249419fc.7fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
249519fc.7fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
249619fc.7fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
249719fc.7fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
249819fc.7fc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxVMM.dll
249919fc.7fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
250019fc.7fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
250119fc.7fc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
250219fc.7fc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll
250319fc.7fc: supR3HardenedDllNotificationCallback: load 00007ffb33400000 LB 0x0000d000 C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL [fFlags=0x0]
250419fc.7fc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll
250519fc.7fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb33400000 'C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL'
250619fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
250719fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
250819fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
250919fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'rpcrt4.dll'.
251019fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #32 'devobj.dll'.
251119fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #33 'propsys.dll'.
251219fc.167c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\MMDevAPI.dll) WinVerifyTrust
251319fc.167c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\MMDevAPI.dll
251419fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'propsys.dll'...
251519fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'propsys.dll' -> '\Device\HarddiskVolume3\Windows\System32\propsys.dll' [rcNtRedir=0xc0150008]
251619fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
251719fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
251819fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
251919fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #15 'oleaut32.dll'.
252019fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #31 'rpcrt4.dll'.
252119fc.167c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\propsys.dll) WinVerifyTrust
252219fc.167c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\propsys.dll
252319fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'devobj.dll'...
252419fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'devobj.dll' -> '\Device\HarddiskVolume3\Windows\System32\devobj.dll' [rcNtRedir=0xc0150008]
252519fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
252619fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
252719fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
252819fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume3\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
252919fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
253019fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
253119fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
253219fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
253319fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'cfgmgr32.dll'.
253419fc.167c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\devobj.dll) WinVerifyTrust
253519fc.167c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\devobj.dll
253619fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
253719fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
253819fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
253919fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
254019fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
254119fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume3\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
254219fc.167c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\cfgmgr32.dll [redoing WinVerifyTrust]
254319fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
254419fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
254519fc.167c: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\cfgmgr32.dll'
254619fc.167c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\MMDevApi.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
254719fc.167c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\MMDevAPI.dll
254819fc.167c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\devobj.dll
254919fc.167c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\propsys.dll
255019fc.167c: supR3HardenedDllNotificationCallback: load 00007ffb411e0000 LB 0x00027000 C:\WINDOWS\System32\DEVOBJ.dll [fFlags=0x0]
255119fc.167c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\devobj.dll
255219fc.167c: supR3HardenedDllNotificationCallback: load 00007ffb3e1e0000 LB 0x001b1000 C:\WINDOWS\System32\PROPSYS.dll [fFlags=0x0]
255319fc.167c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\propsys.dll
255419fc.167c: supR3HardenedDllNotificationCallback: load 00007ffb3ae50000 LB 0x0006f000 C:\WINDOWS\System32\MMDevApi.dll [fFlags=0x0]
255519fc.167c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\MMDevAPI.dll
255619fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3ae50000 'C:\WINDOWS\System32\MMDevApi.dll'
255719fc.167c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000dac pwszName=\Device\HarddiskVolume3\Windows\System32\dsound.dll
255819fc.167c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000398aff0
255919fc.167c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000398aff0
256019fc.167c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=149E0A5A40CD1471B9EF3D3043A8C754805FEC76
256119fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
256219fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
256319fc.167c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package~31bf3856ad364e35~amd64~~10.0.16299.15.cat'; file='\Device\HarddiskVolume3\Windows\System32\dsound.dll'
256419fc.167c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
256519fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
256619fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #32 'winmm.dll'.
256719fc.167c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\dsound.dll) WinVerifyTrust
256819fc.167c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\dsound.dll
256919fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
257019fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume3\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
257119fc.167c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winmm.dll
257219fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
257319fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
257419fc.167c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
257519fc.167c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dsound.dll
257619fc.167c: supR3HardenedDllNotificationCallback: load 00007ffb192d0000 LB 0x0008f000 C:\WINDOWS\System32\dsound.dll [fFlags=0x0]
257719fc.167c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dsound.dll
257819fc.167c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dsound.dll
257919fc.167c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
258019fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb192d0000 'C:\WINDOWS\System32\dsound.dll'
258119fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb192d0000 'C:\WINDOWS\System32\dsound.dll'
258219fc.167c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dsound.dll
258319fc.167c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
258419fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb192d0000 'C:\WINDOWS\system32\dsound.dll'
258519fc.167c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\MMDevAPI.dll
258619fc.167c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\MMDEVAPI.DLL (Input=MMDEVAPI.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
258719fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3ae50000 'C:\WINDOWS\System32\MMDEVAPI.DLL'
258819fc.167c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winmm.dll
258919fc.167c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\winmm.dll (Input=winmm.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
259019fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3f640000 'C:\WINDOWS\System32\winmm.dll'
259119fc.167c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000f5c pwszName=\Device\HarddiskVolume3\Windows\System32\wdmaud.drv
259219fc.167c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000398aff0
259319fc.167c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000398aff0
259419fc.167c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=47392EB8EC6AC07C788B971D8BB592B6FD619920
259519fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
259619fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
259719fc.167c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package~31bf3856ad364e35~amd64~~10.0.16299.15.cat'; file='\Device\HarddiskVolume3\Windows\System32\wdmaud.drv'
259819fc.167c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
259919fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
260019fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'mmdevapi.dll'.
260119fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 'ksuser.dll'.
260219fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #28 'avrt.dll'.
260319fc.167c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\wdmaud.drv) WinVerifyTrust
260419fc.167c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\wdmaud.drv
260519fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'avrt.dll'...
260619fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'avrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\avrt.dll' [rcNtRedir=0xc0150008]
260719fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
260819fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
260919fc.167c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\avrt.dll) WinVerifyTrust
261019fc.167c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\avrt.dll
261119fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ksuser.dll'...
261219fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ksuser.dll' -> '\Device\HarddiskVolume3\Windows\System32\ksuser.dll' [rcNtRedir=0xc0150008]
261319fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
261419fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
261519fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
261619fc.167c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\ksuser.dll) WinVerifyTrust
261719fc.167c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\ksuser.dll
261819fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mmdevapi.dll'...
261919fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'mmdevapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\mmdevapi.dll' [rcNtRedir=0xc0150008]
262019fc.167c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\MMDevAPI.dll
262119fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
262219fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
262319fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
262419fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
262519fc.167c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
262619fc.167c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wdmaud.drv
262719fc.167c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ksuser.dll
262819fc.167c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\avrt.dll
262919fc.167c: supR3HardenedDllNotificationCallback: load 00007ffb3c1d0000 LB 0x00009000 C:\WINDOWS\SYSTEM32\ksuser.dll [fFlags=0x0]
263019fc.167c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ksuser.dll
263119fc.167c: supR3HardenedDllNotificationCallback: load 00007ffb3d1c0000 LB 0x0000a000 C:\WINDOWS\SYSTEM32\AVRT.dll [fFlags=0x0]
263219fc.167c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\avrt.dll
263319fc.167c: supR3HardenedDllNotificationCallback: load 00007ffb1f020000 LB 0x00042000 C:\WINDOWS\System32\wdmaud.drv [fFlags=0x0]
263419fc.167c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wdmaud.drv
263519fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb1f020000 'C:\WINDOWS\System32\wdmaud.drv'
263619fc.167c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wdmaud.drv
263719fc.167c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
263819fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb1f020000 'C:\WINDOWS\System32\wdmaud.drv'
263919fc.167c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wdmaud.drv
264019fc.167c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
264119fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb1f020000 'C:\WINDOWS\System32\wdmaud.drv'
264219fc.167c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wdmaud.drv
264319fc.167c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
264419fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb1f020000 'C:\WINDOWS\System32\wdmaud.drv'
264519fc.167c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wdmaud.drv
264619fc.167c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
264719fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb1f020000 'C:\WINDOWS\System32\wdmaud.drv'
264819fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
264919fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
265019fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
265119fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'rpcrt4.dll'.
265219fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'oleaut32.dll'.
265319fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #55 'mmdevapi.dll'.
265419fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #56 'avrt.dll'.
265519fc.167c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\AudioSes.dll) WinVerifyTrust
265619fc.167c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\AudioSes.dll
265719fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'avrt.dll'...
265819fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'avrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\avrt.dll' [rcNtRedir=0xc0150008]
265919fc.167c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\avrt.dll
266019fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mmdevapi.dll'...
266119fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'mmdevapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\mmdevapi.dll' [rcNtRedir=0xc0150008]
266219fc.167c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\MMDevAPI.dll
266319fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
266419fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume3\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
266519fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
266619fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
266719fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
266819fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
266919fc.167c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcp_win.dll
267019fc.167c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\AUDIOSES.DLL (Input=AUDIOSES.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
267119fc.167c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\AudioSes.dll
267219fc.167c: supR3HardenedDllNotificationCallback: load 00007ffb34360000 LB 0x00122000 C:\WINDOWS\System32\AUDIOSES.DLL [fFlags=0x0]
267319fc.167c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\AudioSes.dll
267419fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb34360000 'C:\WINDOWS\System32\AUDIOSES.DLL'
267519fc.167c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wdmaud.drv
267619fc.167c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
267719fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb1f020000 'C:\WINDOWS\System32\wdmaud.drv'
267819fc.167c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wdmaud.drv
267919fc.167c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
268019fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb1f020000 'C:\WINDOWS\System32\wdmaud.drv'
268119fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb1f020000 'C:\WINDOWS\System32\wdmaud.drv'
268219fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb1f020000 'C:\WINDOWS\System32\wdmaud.drv'
268319fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb1f020000 'C:\WINDOWS\System32\wdmaud.drv'
268419fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb1f020000 'C:\WINDOWS\System32\wdmaud.drv'
268519fc.167c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000fa4 pwszName=\Device\HarddiskVolume3\Windows\System32\msacm32.drv
268619fc.167c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000398aff0
268719fc.167c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000398aff0
268819fc.167c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=8069FA07F8A743E03BD7E2DA392DE4429701D8E6
268919fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
269019fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
269119fc.167c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package~31bf3856ad364e35~amd64~~10.0.16299.15.cat'; file='\Device\HarddiskVolume3\Windows\System32\msacm32.drv'
269219fc.167c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
269319fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
269419fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'mmdevapi.dll'.
269519fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'msacm32.dll'.
269619fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'winmmbase.dll'.
269719fc.167c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\msacm32.drv) WinVerifyTrust
269819fc.167c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\msacm32.drv
269919fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmmbase.dll'...
270019fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmmbase.dll' -> '\Device\HarddiskVolume3\Windows\System32\winmmbase.dll' [rcNtRedir=0xc0150008]
270119fc.167c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winmmbase.dll [redoing WinVerifyTrust]
270219fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
270319fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
270419fc.167c: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\winmmbase.dll'
270519fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msacm32.dll'...
270619fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msacm32.dll' -> '\Device\HarddiskVolume3\Windows\System32\msacm32.dll' [rcNtRedir=0xc0150008]
270719fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
270819fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
270919fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
271019fc.167c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\msacm32.dll) WinVerifyTrust
271119fc.167c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\msacm32.dll
271219fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mmdevapi.dll'...
271319fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'mmdevapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\mmdevapi.dll' [rcNtRedir=0xc0150008]
271419fc.167c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\MMDevAPI.dll
271519fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
271619fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
271719fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
271819fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
271919fc.167c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
272019fc.167c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msacm32.drv
272119fc.167c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msacm32.dll
272219fc.167c: supR3HardenedDllNotificationCallback: load 00007ffb1e9e0000 LB 0x0001c000 C:\WINDOWS\SYSTEM32\MSACM32.dll [fFlags=0x0]
272319fc.167c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msacm32.dll
272419fc.167c: supR3HardenedDllNotificationCallback: load 00007ffb32370000 LB 0x0000c000 C:\WINDOWS\System32\msacm32.drv [fFlags=0x0]
272519fc.167c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msacm32.drv
272619fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb32370000 'C:\WINDOWS\System32\msacm32.drv'
272719fc.167c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msacm32.drv
272819fc.167c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
272919fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb32370000 'C:\WINDOWS\System32\msacm32.drv'
273019fc.167c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msacm32.drv
273119fc.167c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
273219fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb32370000 'C:\WINDOWS\System32\msacm32.drv'
273319fc.167c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msacm32.drv
273419fc.167c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
273519fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb32370000 'C:\WINDOWS\System32\msacm32.drv'
273619fc.167c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msacm32.drv
273719fc.167c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
273819fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb32370000 'C:\WINDOWS\System32\msacm32.drv'
273919fc.167c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msacm32.drv
274019fc.167c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
274119fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb32370000 'C:\WINDOWS\System32\msacm32.drv'
274219fc.167c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msacm32.drv
274319fc.167c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
274419fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb32370000 'C:\WINDOWS\System32\msacm32.drv'
274519fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb32370000 'C:\WINDOWS\System32\msacm32.drv'
274619fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb32370000 'C:\WINDOWS\System32\msacm32.drv'
274719fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb32370000 'C:\WINDOWS\System32\msacm32.drv'
274819fc.167c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000fac pwszName=\Device\HarddiskVolume3\Windows\System32\midimap.dll
274919fc.167c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000398aff0
275019fc.167c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000398aff0
275119fc.167c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=725292B88FCE45C617EE0258A333B14CA2D7EF04
275219fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
275319fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
275419fc.167c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package~31bf3856ad364e35~amd64~~10.0.16299.15.cat'; file='\Device\HarddiskVolume3\Windows\System32\midimap.dll'
275519fc.167c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
275619fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
275719fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'winmm.dll'.
275819fc.167c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\midimap.dll) WinVerifyTrust
275919fc.167c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\midimap.dll
276019fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
276119fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume3\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
276219fc.167c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winmm.dll
276319fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
276419fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
276519fc.167c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
276619fc.167c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\midimap.dll
276719fc.167c: supR3HardenedDllNotificationCallback: load 00007ffb32360000 LB 0x0000a000 C:\WINDOWS\System32\midimap.dll [fFlags=0x0]
276819fc.167c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\midimap.dll
276919fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb32360000 'C:\WINDOWS\System32\midimap.dll'
277019fc.167c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\midimap.dll
277119fc.167c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
277219fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb32360000 'C:\WINDOWS\System32\midimap.dll'
277319fc.167c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\midimap.dll
277419fc.167c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
277519fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb32360000 'C:\WINDOWS\System32\midimap.dll'
277619fc.167c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\midimap.dll
277719fc.167c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
277819fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb32360000 'C:\WINDOWS\System32\midimap.dll'
277919fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3f640000 'C:\WINDOWS\System32\winmm.dll'
278019fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3f640000 'C:\WINDOWS\System32\winmm.dll'
278119fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3f640000 'C:\WINDOWS\System32\winmm.dll'
278219fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3f640000 'C:\WINDOWS\System32\winmm.dll'
278319fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3f640000 'C:\WINDOWS\System32\winmm.dll'
278419fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3f640000 'C:\WINDOWS\System32\winmm.dll'
278519fc.167c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dsound.dll
278619fc.167c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
278719fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb192d0000 'C:\WINDOWS\system32\dsound.dll'
278819fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3f640000 'C:\WINDOWS\System32\winmm.dll'
278919fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb426a0000 'C:\WINDOWS\system32\shell32.dll'
279019fc.2d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb426a0000 'C:\WINDOWS\system32\shell32.dll'
279119fc.167c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dsound.dll
279219fc.167c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
279319fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb192d0000 'C:\WINDOWS\system32\dsound.dll'
279419fc.167c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winmm.dll
279519fc.167c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\winmm.dll (Input=winmm.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
279619fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3f640000 'C:\WINDOWS\System32\winmm.dll'
279719fc.167c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dsound.dll
279819fc.167c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
279919fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb192d0000 'C:\WINDOWS\system32\dsound.dll'
280019fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3f640000 'C:\WINDOWS\System32\winmm.dll'
280119fc.167c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dsound.dll
280219fc.167c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
280319fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb192d0000 'C:\WINDOWS\system32\dsound.dll'
280419fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3f640000 'C:\WINDOWS\System32\winmm.dll'
280519fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3f640000 'C:\WINDOWS\System32\winmm.dll'
280619fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3f640000 'C:\WINDOWS\System32\winmm.dll'
280719fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb192d0000 'C:\WINDOWS\system32\dsound.dll'
280819fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3f640000 'C:\WINDOWS\System32\winmm.dll'
280919fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb192d0000 'C:\WINDOWS\system32\dsound.dll'
281019fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3f640000 'C:\WINDOWS\System32\winmm.dll'
281119fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb192d0000 'C:\WINDOWS\system32\dsound.dll'
281219fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3f640000 'C:\WINDOWS\System32\winmm.dll'
281319fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb192d0000 'C:\WINDOWS\system32\dsound.dll'
281419fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3f640000 'C:\WINDOWS\System32\winmm.dll'
281519fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb192d0000 'C:\WINDOWS\system32\dsound.dll'
281619fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3f640000 'C:\WINDOWS\System32\winmm.dll'
281719fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb192d0000 'C:\WINDOWS\system32\dsound.dll'
281819fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3f640000 'C:\WINDOWS\System32\winmm.dll'
281919fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb192d0000 'C:\WINDOWS\system32\dsound.dll'
282019fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3f640000 'C:\WINDOWS\System32\winmm.dll'
282119fc.167c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dsound.dll
282219fc.167c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
282319fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb192d0000 'C:\WINDOWS\system32\dsound.dll'
282419fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3f640000 'C:\WINDOWS\System32\winmm.dll'
282519fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb192d0000 'C:\WINDOWS\system32\dsound.dll'
282619fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3f640000 'C:\WINDOWS\System32\winmm.dll'
282719fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb192d0000 'C:\WINDOWS\system32\dsound.dll'
282819fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3f640000 'C:\WINDOWS\System32\winmm.dll'
282919fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb192d0000 'C:\WINDOWS\system32\dsound.dll'
283019fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3f640000 'C:\WINDOWS\System32\winmm.dll'
283119fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb192d0000 'C:\WINDOWS\system32\dsound.dll'
283219fc.167c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winmm.dll
283319fc.167c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\winmm.dll (Input=winmm.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
283419fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3f640000 'C:\WINDOWS\System32\winmm.dll'
283519fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb192d0000 'C:\WINDOWS\system32\dsound.dll'
283619fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3f640000 'C:\WINDOWS\System32\winmm.dll'
283719fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb192d0000 'C:\WINDOWS\system32\dsound.dll'
283819fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3f640000 'C:\WINDOWS\System32\winmm.dll'
283919fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb192d0000 'C:\WINDOWS\system32\dsound.dll'
284019fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3f640000 'C:\WINDOWS\System32\winmm.dll'
284119fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb192d0000 'C:\WINDOWS\system32\dsound.dll'
284219fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3f640000 'C:\WINDOWS\System32\winmm.dll'
284319fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb192d0000 'C:\WINDOWS\system32\dsound.dll'
284419fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3f640000 'C:\WINDOWS\System32\winmm.dll'
284519fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb192d0000 'C:\WINDOWS\system32\dsound.dll'
284619fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3f640000 'C:\WINDOWS\System32\winmm.dll'
284719fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb192d0000 'C:\WINDOWS\system32\dsound.dll'
284819fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3f640000 'C:\WINDOWS\System32\winmm.dll'
284919fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb192d0000 'C:\WINDOWS\system32\dsound.dll'
285019fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3f640000 'C:\WINDOWS\System32\winmm.dll'
285119fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb192d0000 'C:\WINDOWS\system32\dsound.dll'
285219fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3f640000 'C:\WINDOWS\System32\winmm.dll'
285319fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb192d0000 'C:\WINDOWS\system32\dsound.dll'
285419fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3f640000 'C:\WINDOWS\System32\winmm.dll'
285519fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb192d0000 'C:\WINDOWS\system32\dsound.dll'
285619fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3f640000 'C:\WINDOWS\System32\winmm.dll'
285719fc.167c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dsound.dll
285819fc.167c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
285919fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb192d0000 'C:\WINDOWS\system32\dsound.dll'
286019fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3f640000 'C:\WINDOWS\System32\winmm.dll'
286119fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb192d0000 'C:\WINDOWS\system32\dsound.dll'
286219fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3f640000 'C:\WINDOWS\System32\winmm.dll'
286319fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb192d0000 'C:\WINDOWS\system32\dsound.dll'
286419fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3f640000 'C:\WINDOWS\System32\winmm.dll'
286519fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb192d0000 'C:\WINDOWS\system32\dsound.dll'
286619fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3f640000 'C:\WINDOWS\System32\winmm.dll'
286719fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb192d0000 'C:\WINDOWS\system32\dsound.dll'
286819fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3f640000 'C:\WINDOWS\System32\winmm.dll'
286919fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb192d0000 'C:\WINDOWS\system32\dsound.dll'
287019fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3f640000 'C:\WINDOWS\System32\winmm.dll'
287119fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb192d0000 'C:\WINDOWS\system32\dsound.dll'
287219fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3f640000 'C:\WINDOWS\System32\winmm.dll'
287319fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
287419fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41ad0000 'C:\Windows\System32\WINTRUST.DLL'
287519fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\CRYPT32.dll'
287619fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
287719fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
287819fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'rpcrt4.dll'.
287919fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'combase.dll'.
288019fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #21 'shcore.dll'.
288119fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #22 'win32u.dll'.
288219fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'textinputframework.dll'.
288319fc.167c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #40 'user32.dll'.
288419fc.167c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\Windows.UI.dll) WinVerifyTrust
288519fc.167c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\Windows.UI.dll
288619fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
288719fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
288819fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'textinputframework.dll'...
288919fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'textinputframework.dll' -> '\Device\HarddiskVolume3\Windows\System32\textinputframework.dll' [rcNtRedir=0xc0150008]
289019fc.167c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\TextInputFramework.dll
289119fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
289219fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
289319fc.167c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\win32u.dll [redoing WinVerifyTrust]
289419fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb40870000 'C:\WINDOWS\system32\rsaenh.dll'
289519fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb41b30000 'C:\WINDOWS\System32\crypt32.dll'
289619fc.167c: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\win32u.dll'
289719fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shcore.dll'...
289819fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'shcore.dll' -> '\Device\HarddiskVolume3\Windows\System32\shcore.dll' [rcNtRedir=0xc0150008]
289919fc.167c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\SHCore.dll
290019fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
290119fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
290219fc.167c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\combase.dll
290319fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
290419fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
290519fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
290619fc.167c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
290719fc.167c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\Windows.UI.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
290819fc.167c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\Windows.UI.dll
290919fc.167c: supR3HardenedDllNotificationCallback: load 00007ffb27cc0000 LB 0x00107000 C:\Windows\System32\Windows.UI.dll [fFlags=0x0]
291019fc.167c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\Windows.UI.dll
291119fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb27cc0000 'C:\Windows\System32\Windows.UI.dll'
291219fc.1d14: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\avrt.dll
291319fc.1d14: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\avrt.dll (Input=avrt.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
291419fc.1d14: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3d1c0000 'C:\WINDOWS\System32\avrt.dll'
291519fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb192d0000 'C:\WINDOWS\system32\dsound.dll'
291619fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3f640000 'C:\WINDOWS\System32\winmm.dll'
291719fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb192d0000 'C:\WINDOWS\system32\dsound.dll'
291819fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3f640000 'C:\WINDOWS\System32\winmm.dll'
291919fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb192d0000 'C:\WINDOWS\system32\dsound.dll'
292019fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3f640000 'C:\WINDOWS\System32\winmm.dll'
292119fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb192d0000 'C:\WINDOWS\system32\dsound.dll'
292219fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3f640000 'C:\WINDOWS\System32\winmm.dll'
292319fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb192d0000 'C:\WINDOWS\system32\dsound.dll'
292419fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3f640000 'C:\WINDOWS\System32\winmm.dll'
292519fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb192d0000 'C:\WINDOWS\system32\dsound.dll'
292619fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3f640000 'C:\WINDOWS\System32\winmm.dll'
292719fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb192d0000 'C:\WINDOWS\system32\dsound.dll'
292819fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3f640000 'C:\WINDOWS\System32\winmm.dll'
292919fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb192d0000 'C:\WINDOWS\system32\dsound.dll'
293019fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3f640000 'C:\WINDOWS\System32\winmm.dll'
293119fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb192d0000 'C:\WINDOWS\system32\dsound.dll'
293219fc.167c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb3f640000 'C:\WINDOWS\System32\winmm.dll'
293319fc.7fc: supR3HardenedDllNotificationCallback: Unload 00007ffb33400000 LB 0x0000d000 C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL [flags=0x0]
293419fc.2ba0: supR3HardenedDllNotificationCallback: Unload 00007ffb34d10000 LB 0x0000b000 C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL [flags=0x0]
293519fc.2194: supR3HardenedDllNotificationCallback: Unload 00007ffb350a0000 LB 0x0000c000 C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL [flags=0x0]
293619fc.a04: supR3HardenedDllNotificationCallback: Unload 00007ffb35880000 LB 0x0000d000 C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL [flags=0x0]
293719fc.20b4: supR3HardenedDllNotificationCallback: Unload 00007ffb3ce90000 LB 0x0000b000 C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL [flags=0x0]
293819fc.167c: supR3HardenedDllNotificationCallback: Unload 00007ffafb680000 LB 0x009bf000 C:\Program Files\Oracle\VirtualBox\VBoxDD.DLL [flags=0x0]
293919fc.167c: supR3HardenedDllNotificationCallback: Unload 00007ffb155c0000 LB 0x00063000 C:\Program Files\Oracle\VirtualBox\VBoxDDU.dll [flags=0x0]
294019fc.167c: supR3HardenedDllNotificationCallback: Unload 00007ffb06510000 LB 0x0005d000 C:\Program Files\Oracle\VirtualBox\VBoxDD2.dll [flags=0x0]
294119fc.2d74: Terminating the normal way: rcExit=0
294217a4.1c08: supR3HardNtChildWaitFor[2]: Quitting: ExitCode=0x0 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 237292 ms, the end);
2943f28.2afc: supR3HardNtChildWaitFor[1]: Quitting: ExitCode=0x0 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 237704 ms, the end);

© 2025 Oracle Support Privacy / Do Not Sell My Info Terms of Use Trademark Policy Automated Access Etiquette