VirtualBox

Ticket #18387: ubuntu1804_VBoxHardening.log

File ubuntu1804_VBoxHardening.log, 326.4 KB (added by nathaniel515, 6 years ago)
Line 
14a9c.4d9c: Log file opened: 6.0.4r128413 g_hStartupLog=0000000000000070 g_uNtVerCombined=0xa0456300
24a9c.4d9c: \SystemRoot\System32\ntdll.dll:
34a9c.4d9c: CreationTime: 2018-12-30T02:31:21.439974200Z
44a9c.4d9c: LastWriteTime: 2018-12-30T02:31:21.455594900Z
54a9c.4d9c: ChangeTime: 2019-01-08T21:05:01.868444500Z
64a9c.4d9c: FileAttributes: 0x20
74a9c.4d9c: Size: 0x1e7010
84a9c.4d9c: NT Headers: 0xe0
94a9c.4d9c: Timestamp: 0xe8b54827
104a9c.4d9c: Machine: 0x8664 - amd64
114a9c.4d9c: Timestamp: 0xe8b54827
124a9c.4d9c: Image Version: 10.0
134a9c.4d9c: SizeOfImage: 0x1ed000 (2019328)
144a9c.4d9c: Resource Dir: 0x17d000 LB 0x6ea08
154a9c.4d9c: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
164a9c.4d9c: [Raw version resource data: 0x17d0f0 LB 0x380, codepage 0x0 (reserved 0x0)]
174a9c.4d9c: ProductName: Microsoft® Windows® Operating System
184a9c.4d9c: ProductVersion: 10.0.17763.194
194a9c.4d9c: FileVersion: 10.0.17763.194 (WinBuild.160101.0800)
204a9c.4d9c: FileDescription: NT Layer DLL
214a9c.4d9c: \SystemRoot\System32\kernel32.dll:
224a9c.4d9c: CreationTime: 2018-09-15T07:28:44.342269900Z
234a9c.4d9c: LastWriteTime: 2018-09-15T07:28:44.342269900Z
244a9c.4d9c: ChangeTime: 2018-12-30T02:37:12.140802400Z
254a9c.4d9c: FileAttributes: 0x20
264a9c.4d9c: Size: 0xb1380
274a9c.4d9c: NT Headers: 0xe8
284a9c.4d9c: Timestamp: 0x65614da1
294a9c.4d9c: Machine: 0x8664 - amd64
304a9c.4d9c: Timestamp: 0x65614da1
314a9c.4d9c: Image Version: 10.0
324a9c.4d9c: SizeOfImage: 0xb3000 (733184)
334a9c.4d9c: Resource Dir: 0xb1000 LB 0x520
344a9c.4d9c: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
354a9c.4d9c: [Raw version resource data: 0xb10b0 LB 0x3a4, codepage 0x0 (reserved 0x0)]
364a9c.4d9c: ProductName: Microsoft® Windows® Operating System
374a9c.4d9c: ProductVersion: 10.0.17763.1
384a9c.4d9c: FileVersion: 10.0.17763.1 (WinBuild.160101.0800)
394a9c.4d9c: FileDescription: Windows NT BASE API Client DLL
404a9c.4d9c: \SystemRoot\System32\KernelBase.dll:
414a9c.4d9c: CreationTime: 2018-12-30T02:31:21.205655900Z
424a9c.4d9c: LastWriteTime: 2018-12-30T02:31:21.236896100Z
434a9c.4d9c: ChangeTime: 2019-01-08T21:05:01.867446600Z
444a9c.4d9c: FileAttributes: 0x20
454a9c.4d9c: Size: 0x293cc8
464a9c.4d9c: NT Headers: 0xf8
474a9c.4d9c: Timestamp: 0x1659a33b
484a9c.4d9c: Machine: 0x8664 - amd64
494a9c.4d9c: Timestamp: 0x1659a33b
504a9c.4d9c: Image Version: 10.0
514a9c.4d9c: SizeOfImage: 0x293000 (2699264)
524a9c.4d9c: Resource Dir: 0x26f000 LB 0x548
534a9c.4d9c: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
544a9c.4d9c: [Raw version resource data: 0x26f0b0 LB 0x3bc, codepage 0x0 (reserved 0x0)]
554a9c.4d9c: ProductName: Microsoft® Windows® Operating System
564a9c.4d9c: ProductVersion: 10.0.17763.134
574a9c.4d9c: FileVersion: 10.0.17763.134 (WinBuild.160101.0800)
584a9c.4d9c: FileDescription: Windows NT BASE API Client DLL
594a9c.4d9c: \SystemRoot\System32\apisetschema.dll:
604a9c.4d9c: CreationTime: 2018-09-15T07:28:25.403122600Z
614a9c.4d9c: LastWriteTime: 2018-09-15T07:28:25.403122600Z
624a9c.4d9c: ChangeTime: 2018-12-30T02:29:00.950166300Z
634a9c.4d9c: FileAttributes: 0x20
644a9c.4d9c: Size: 0x1c738
654a9c.4d9c: NT Headers: 0xd0
664a9c.4d9c: Timestamp: 0x33775897
674a9c.4d9c: Machine: 0x8664 - amd64
684a9c.4d9c: Timestamp: 0x33775897
694a9c.4d9c: Image Version: 10.0
704a9c.4d9c: SizeOfImage: 0x1d000 (118784)
714a9c.4d9c: Resource Dir: 0x1c000 LB 0x408
724a9c.4d9c: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
734a9c.4d9c: [Raw version resource data: 0x1c060 LB 0x3a8, codepage 0x0 (reserved 0x0)]
744a9c.4d9c: ProductName: Microsoft® Windows® Operating System
754a9c.4d9c: ProductVersion: 10.0.17763.1
764a9c.4d9c: FileVersion: 10.0.17763.1 (WinBuild.160101.0800)
774a9c.4d9c: FileDescription: ApiSet Schema DLL
784a9c.4d9c: NtOpenDirectoryObject failed on \Driver: 0xc0000022
794a9c.4d9c: supR3HardenedWinFindAdversaries: 0x8000
804a9c.4d9c: \SystemRoot\System32\drivers\cyprotectdrv64.sys:
814a9c.4d9c: CreationTime: 2018-12-30T23:56:45.646933300Z
824a9c.4d9c: LastWriteTime: 2019-01-07T19:47:35.388882000Z
834a9c.4d9c: ChangeTime: 2019-01-30T22:49:57.834123800Z
844a9c.4d9c: FileAttributes: 0x20
854a9c.4d9c: Size: 0x332a8
864a9c.4d9c: NT Headers: 0xf8
874a9c.4d9c: Timestamp: 0x5c05c934
884a9c.4d9c: Machine: 0x8664 - amd64
894a9c.4d9c: Timestamp: 0x5c05c934
904a9c.4d9c: Image Version: 6.1
914a9c.4d9c: SizeOfImage: 0x134000 (1261568)
924a9c.4d9c: Resource Dir: 0x132000 LB 0x2f0
934a9c.4d9c: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
944a9c.4d9c: [Raw version resource data: 0x132060 LB 0x28c, codepage 0x0 (reserved 0x0)]
954a9c.4d9c: ProductName: CylancePROTECT
964a9c.4d9c: ProductVersion: 2.0.1510.8
974a9c.4d9c: FileVersion: 2.0.1510.8
984a9c.4d9c: FileDescription: Cylance Protect Driver
994a9c.4d9c: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox'
1004a9c.4d9c: Calling main()
1014a9c.4d9c: SUPR3HardenedMain: pszProgName=VirtualBoxVM fFlags=0x2
1024a9c.4d9c: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox'
1034a9c.4d9c: SUPR3HardenedMain: Respawn #1
1044a9c.4d9c: System32: \Device\HarddiskVolume4\Windows\System32
1054a9c.4d9c: WinSxS: \Device\HarddiskVolume4\Windows\WinSxS
1064a9c.4d9c: KnownDllPath: C:\WINDOWS\System32
1074a9c.4d9c: '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
1084a9c.4d9c: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe)
1094a9c.4d9c: supR3HardNtEnableThreadCreation:
1104a9c.4d9c: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffcbb1e5640 pvNtTerminateThread=00007ffcbb2100b0
1114a9c.4d9c: supR3HardenedWinDoReSpawn(1): New child 5170.55f8 [kernel32].
1124a9c.4d9c: supR3HardNtChildGatherData: PebBaseAddress=0000000000e47000 cbPeb=0x388
1134a9c.4d9c: supR3HardNtPuChFindNtdll: uNtDllParentAddr=00007ffcbb170000 uNtDllChildAddr=00007ffcbb170000
1144a9c.4d9c: supR3HardenedWinSetupChildInit: uLdrInitThunk=00007ffcbb1e5640
1154a9c.4d9c: supR3HardenedWinSetupChildInit: Start child.
1164a9c.4d9c: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
1174a9c.4d9c: supR3HardNtChildPurify: Startup delay kludge #1/0: 513 ms, 58 sleeps
1184a9c.4d9c: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
1194a9c.4d9c: *0000000000000000-0000000000c6ffff 0x0001/0x0000 0x0000000
1204a9c.4d9c: *0000000000c70000-0000000000c8ffff 0x0004/0x0004 0x0020000
1214a9c.4d9c: *0000000000c90000-0000000000ca9fff 0x0002/0x0002 0x0040000
1224a9c.4d9c: 0000000000caa000-0000000000caffff 0x0001/0x0000 0x0000000
1234a9c.4d9c: *0000000000cb0000-0000000000daafff 0x0000/0x0004 0x0020000
1244a9c.4d9c: 0000000000dab000-0000000000dadfff 0x0104/0x0004 0x0020000
1254a9c.4d9c: 0000000000dae000-0000000000daffff 0x0004/0x0004 0x0020000
1264a9c.4d9c: *0000000000db0000-0000000000db3fff 0x0002/0x0002 0x0040000
1274a9c.4d9c: 0000000000db4000-0000000000dbffff 0x0001/0x0000 0x0000000
1284a9c.4d9c: *0000000000dc0000-0000000000dc1fff 0x0004/0x0004 0x0020000
1294a9c.4d9c: 0000000000dc2000-0000000000dfffff 0x0001/0x0000 0x0000000
1304a9c.4d9c: *0000000000e00000-0000000000e46fff 0x0000/0x0004 0x0020000
1314a9c.4d9c: 0000000000e47000-0000000000e49fff 0x0004/0x0004 0x0020000
1324a9c.4d9c: 0000000000e4a000-0000000000ffffff 0x0000/0x0004 0x0020000
1334a9c.4d9c: 0000000001000000-000000007ffdffff 0x0001/0x0000 0x0000000
1344a9c.4d9c: *000000007ffe0000-000000007ffe0fff 0x0002/0x0002 0x0020000
1354a9c.4d9c: 000000007ffe1000-000000007ffe6fff 0x0001/0x0000 0x0000000
1364a9c.4d9c: *000000007ffe7000-000000007ffe7fff 0x0002/0x0002 0x0020000
1374a9c.4d9c: 000000007ffe8000-00007ff50bb7ffff 0x0001/0x0000 0x0000000
1384a9c.4d9c: *00007ff50bb80000-00007ff50bb80fff 0x0002/0x0002 0x0040000
1394a9c.4d9c: 00007ff50bb81000-00007ff50bb8ffff 0x0001/0x0000 0x0000000
1404a9c.4d9c: *00007ff50bb90000-00007ff50bbb2fff 0x0002/0x0002 0x0040000
1414a9c.4d9c: 00007ff50bbb3000-00007ff7d61fffff 0x0001/0x0000 0x0000000
1424a9c.4d9c: *00007ff7d6200000-00007ff7d6200fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
1434a9c.4d9c: 00007ff7d6201000-00007ff7d6273fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
1444a9c.4d9c: 00007ff7d6274000-00007ff7d6274fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
1454a9c.4d9c: 00007ff7d6275000-00007ff7d62bbfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
1464a9c.4d9c: 00007ff7d62bc000-00007ff7d62bcfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
1474a9c.4d9c: 00007ff7d62bd000-00007ff7d62bdfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
1484a9c.4d9c: 00007ff7d62be000-00007ff7d62c2fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
1494a9c.4d9c: 00007ff7d62c3000-00007ff7d62c3fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
1504a9c.4d9c: 00007ff7d62c4000-00007ff7d62c4fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
1514a9c.4d9c: 00007ff7d62c5000-00007ff7d62c8fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
1524a9c.4d9c: 00007ff7d62c9000-00007ff7d6311fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
1534a9c.4d9c: 00007ff7d6312000-00007ffcbb16ffff 0x0001/0x0000 0x0000000
1544a9c.4d9c: *00007ffcbb170000-00007ffcbb170fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
1554a9c.4d9c: 00007ffcbb171000-00007ffcbb287fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
1564a9c.4d9c: 00007ffcbb288000-00007ffcbb2cefff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
1574a9c.4d9c: 00007ffcbb2cf000-00007ffcbb2d9fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
1584a9c.4d9c: 00007ffcbb2da000-00007ffcbb2e7fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
1594a9c.4d9c: 00007ffcbb2e8000-00007ffcbb2e8fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
1604a9c.4d9c: 00007ffcbb2e9000-00007ffcbb2ebfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
1614a9c.4d9c: 00007ffcbb2ec000-00007ffcbb35cfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
1624a9c.4d9c: 00007ffcbb35d000-00007ffffffeffff 0x0001/0x0000 0x0000000
1634a9c.4d9c: VirtualBoxVM.exe: timestamp 0x5c4b51f3 (rc=VINF_SUCCESS)
1644a9c.4d9c: '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
1654a9c.4d9c: '\Device\HarddiskVolume4\Windows\System32\ntdll.dll' has no imports
1664a9c.4d9c: supR3HardNtChildPurify: Done after 561 ms and 0 fixes (loop #0).
1675170.55f8: Log file opened: 6.0.4r128413 g_hStartupLog=0000000000000004 g_uNtVerCombined=0xa0456300
1685170.55f8: supR3HardenedVmProcessInit: uNtDllAddr=00007ffcbb170000 g_uNtVerCombined=0xa0456300
1695170.55f8: ntdll.dll: timestamp 0xe8b54827 (rc=VINF_SUCCESS)
1705170.55f8: New simple heap: #1 0000000001100000 LB 0x400000 (for 2019328 allocation)
1714a9c.4d9c: supR3HardNtEnableThreadCreation:
1725170.55f8: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox'
1735170.55f8: System32: \Device\HarddiskVolume4\Windows\System32
1745170.55f8: WinSxS: \Device\HarddiskVolume4\Windows\WinSxS
1755170.55f8: KnownDllPath: C:\WINDOWS\System32
1765170.55f8: supR3HardenedVmProcessInit: Opening vboxdrv stub...
1775170.55f8: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
1785170.55f8: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
1795170.55f8: Registered Dll notification callback with NTDLL.
1805170.55f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\kernel32.dll)
1815170.55f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\kernel32.dll
1825170.55f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\KERNEL32.DLL (Input=KERNEL32.DLL, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000004001:<flags> [calling]
1835170.55f8: supR3HardenedDllNotificationCallback: load 00007ffcb80b0000 LB 0x00293000 C:\WINDOWS\System32\KERNELBASE.dll [fFlags=0x0]
1845170.55f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\KernelBase.dll)
1855170.55f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\KernelBase.dll
1865170.55f8: supR3HardenedDllNotificationCallback: load 00007ffcba7c0000 LB 0x000b3000 C:\WINDOWS\System32\KERNEL32.DLL [fFlags=0x0]
1875170.55f8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
1885170.55f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcba7c0000 'C:\WINDOWS\System32\KERNEL32.DLL'
1895170.55f8: supR3HardenedDllNotificationCallback: load 00007ff7d6200000 LB 0x00112000 C:\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe [fFlags=0x0]
1905170.55f8: '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
1915170.55f8: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe)
1925170.55f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
1935170.55f8: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffcbb1e5640 pvNtTerminateThread=00007ffcbb2100b0
1944a9c.4d9c: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 87 ms.
1955170.55f8: \SystemRoot\System32\ntdll.dll:
1965170.55f8: CreationTime: 2018-12-30T02:31:21.439974200Z
1975170.55f8: LastWriteTime: 2018-12-30T02:31:21.455594900Z
1985170.55f8: ChangeTime: 2019-01-08T21:05:01.868444500Z
1995170.55f8: FileAttributes: 0x20
2005170.55f8: Size: 0x1e7010
2015170.55f8: NT Headers: 0xe0
2025170.55f8: Timestamp: 0xe8b54827
2035170.55f8: Machine: 0x8664 - amd64
2045170.55f8: Timestamp: 0xe8b54827
2055170.55f8: Image Version: 10.0
2065170.55f8: SizeOfImage: 0x1ed000 (2019328)
2075170.55f8: Resource Dir: 0x17d000 LB 0x6ea08
2085170.55f8: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
2095170.55f8: [Raw version resource data: 0x17d0f0 LB 0x380, codepage 0x0 (reserved 0x0)]
2105170.55f8: ProductName: Microsoft® Windows® Operating System
2115170.55f8: ProductVersion: 10.0.17763.194
2125170.55f8: FileVersion: 10.0.17763.194 (WinBuild.160101.0800)
2135170.55f8: FileDescription: NT Layer DLL
2145170.55f8: \SystemRoot\System32\kernel32.dll:
2155170.55f8: CreationTime: 2018-09-15T07:28:44.342269900Z
2165170.55f8: LastWriteTime: 2018-09-15T07:28:44.342269900Z
2175170.55f8: ChangeTime: 2018-12-30T02:37:12.140802400Z
2185170.55f8: FileAttributes: 0x20
2195170.55f8: Size: 0xb1380
2205170.55f8: NT Headers: 0xe8
2215170.55f8: Timestamp: 0x65614da1
2225170.55f8: Machine: 0x8664 - amd64
2235170.55f8: Timestamp: 0x65614da1
2245170.55f8: Image Version: 10.0
2255170.55f8: SizeOfImage: 0xb3000 (733184)
2265170.55f8: Resource Dir: 0xb1000 LB 0x520
2275170.55f8: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
2285170.55f8: [Raw version resource data: 0xb10b0 LB 0x3a4, codepage 0x0 (reserved 0x0)]
2295170.55f8: ProductName: Microsoft® Windows® Operating System
2305170.55f8: ProductVersion: 10.0.17763.1
2315170.55f8: FileVersion: 10.0.17763.1 (WinBuild.160101.0800)
2325170.55f8: FileDescription: Windows NT BASE API Client DLL
2335170.55f8: \SystemRoot\System32\KernelBase.dll:
2345170.55f8: CreationTime: 2018-12-30T02:31:21.205655900Z
2355170.55f8: LastWriteTime: 2018-12-30T02:31:21.236896100Z
2365170.55f8: ChangeTime: 2019-01-08T21:05:01.867446600Z
2375170.55f8: FileAttributes: 0x20
2385170.55f8: Size: 0x293cc8
2395170.55f8: NT Headers: 0xf8
2405170.55f8: Timestamp: 0x1659a33b
2415170.55f8: Machine: 0x8664 - amd64
2425170.55f8: Timestamp: 0x1659a33b
2435170.55f8: Image Version: 10.0
2445170.55f8: SizeOfImage: 0x293000 (2699264)
2455170.55f8: Resource Dir: 0x26f000 LB 0x548
2465170.55f8: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
2475170.55f8: [Raw version resource data: 0x26f0b0 LB 0x3bc, codepage 0x0 (reserved 0x0)]
2485170.55f8: ProductName: Microsoft® Windows® Operating System
2495170.55f8: ProductVersion: 10.0.17763.134
2505170.55f8: FileVersion: 10.0.17763.134 (WinBuild.160101.0800)
2515170.55f8: FileDescription: Windows NT BASE API Client DLL
2525170.55f8: \SystemRoot\System32\apisetschema.dll:
2535170.55f8: CreationTime: 2018-09-15T07:28:25.403122600Z
2545170.55f8: LastWriteTime: 2018-09-15T07:28:25.403122600Z
2555170.55f8: ChangeTime: 2018-12-30T02:29:00.950166300Z
2565170.55f8: FileAttributes: 0x20
2575170.55f8: Size: 0x1c738
2585170.55f8: NT Headers: 0xd0
2595170.55f8: Timestamp: 0x33775897
2605170.55f8: Machine: 0x8664 - amd64
2615170.55f8: Timestamp: 0x33775897
2625170.55f8: Image Version: 10.0
2635170.55f8: SizeOfImage: 0x1d000 (118784)
2645170.55f8: Resource Dir: 0x1c000 LB 0x408
2655170.55f8: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
2665170.55f8: [Raw version resource data: 0x1c060 LB 0x3a8, codepage 0x0 (reserved 0x0)]
2675170.55f8: ProductName: Microsoft® Windows® Operating System
2685170.55f8: ProductVersion: 10.0.17763.1
2695170.55f8: FileVersion: 10.0.17763.1 (WinBuild.160101.0800)
2705170.55f8: FileDescription: ApiSet Schema DLL
2715170.55f8: NtOpenDirectoryObject failed on \Driver: 0xc0000022
2725170.55f8: supR3HardenedWinFindAdversaries: 0x8000
2735170.55f8: \SystemRoot\System32\drivers\cyprotectdrv64.sys:
2745170.55f8: CreationTime: 2018-12-30T23:56:45.646933300Z
2755170.55f8: LastWriteTime: 2019-01-07T19:47:35.388882000Z
2765170.55f8: ChangeTime: 2019-01-30T22:49:57.834123800Z
2775170.55f8: FileAttributes: 0x20
2785170.55f8: Size: 0x332a8
2795170.55f8: NT Headers: 0xf8
2805170.55f8: Timestamp: 0x5c05c934
2815170.55f8: Machine: 0x8664 - amd64
2825170.55f8: Timestamp: 0x5c05c934
2835170.55f8: Image Version: 6.1
2845170.55f8: SizeOfImage: 0x134000 (1261568)
2855170.55f8: Resource Dir: 0x132000 LB 0x2f0
2865170.55f8: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
2875170.55f8: [Raw version resource data: 0x132060 LB 0x28c, codepage 0x0 (reserved 0x0)]
2885170.55f8: ProductName: CylancePROTECT
2895170.55f8: ProductVersion: 2.0.1510.8
2905170.55f8: FileVersion: 2.0.1510.8
2915170.55f8: FileDescription: Cylance Protect Driver
2925170.55f8: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox'
2935170.55f8: Calling main()
2945170.55f8: SUPR3HardenedMain: pszProgName=VirtualBoxVM fFlags=0x2
2955170.55f8: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox'
2965170.55f8: '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
2975170.55f8: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe)
2985170.55f8: SUPR3HardenedMain: Respawn #2
2995170.55f8: supR3HardNtEnableThreadCreation:
3005170.55f8: supR3HardenedDllNotificationCallback: load 00007ffcb9140000 LB 0x00122000 C:\WINDOWS\System32\RPCRT4.dll [fFlags=0x0]
3015170.55f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll)
3025170.55f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll
3035170.55f8: supR3HardenedDllNotificationCallback: load 00007ffcbad70000 LB 0x0009e000 C:\WINDOWS\System32\sechost.dll [fFlags=0x0]
3045170.55f8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'rpcrt4.dll'.
3055170.55f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\sechost.dll)
3065170.55f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\sechost.dll
3075170.55f8: '\Device\HarddiskVolume4\Windows\System32\ntdll.dll' has no imports
3085170.55f8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\ntdll.dll)
3095170.55f8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\ntdll.dll
3105170.55f8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
3115170.55f8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
3125170.55f8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
3135170.55f8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\ntdll.dll (Input=ntdll.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
3145170.55f8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcbb170000 'C:\WINDOWS\System32\ntdll.dll'
3155170.55f8: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffcbb1e5640 pvNtTerminateThread=00007ffcbb2100b0
3165170.55f8: supR3HardenedWinDoReSpawn(2): New child 4760.2884 [kernel32].
3175170.55f8: supR3HardenedWinReSpawn: NtSetInformationThread/ThreadHideFromDebugger failed: 0xc0000022 (harmless)
3185170.55f8: supR3HardNtChildGatherData: PebBaseAddress=00000000002c6000 cbPeb=0x388
3195170.55f8: supR3HardNtPuChFindNtdll: uNtDllParentAddr=00007ffcbb170000 uNtDllChildAddr=00007ffcbb170000
3205170.55f8: supR3HardenedWinSetupChildInit: uLdrInitThunk=00007ffcbb1e5640
3215170.55f8: supR3HardenedWinSetupChildInit: Start child.
3225170.55f8: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
3235170.55f8: supR3HardNtChildPurify: Startup delay kludge #1/0: 520 ms, 60 sleeps
3245170.55f8: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
3255170.55f8: *0000000000000000-00000000000effff 0x0001/0x0000 0x0000000
3265170.55f8: *00000000000f0000-000000000010ffff 0x0004/0x0004 0x0020000
3275170.55f8: *0000000000110000-0000000000129fff 0x0002/0x0002 0x0040000
3285170.55f8: 000000000012a000-000000000012ffff 0x0001/0x0000 0x0000000
3295170.55f8: *0000000000130000-0000000000133fff 0x0002/0x0002 0x0040000
3305170.55f8: 0000000000134000-000000000013ffff 0x0001/0x0000 0x0000000
3315170.55f8: *0000000000140000-0000000000141fff 0x0004/0x0004 0x0020000
3325170.55f8: 0000000000142000-00000000001fffff 0x0001/0x0000 0x0000000
3335170.55f8: *0000000000200000-00000000002c5fff 0x0000/0x0004 0x0020000
3345170.55f8: 00000000002c6000-00000000002c8fff 0x0004/0x0004 0x0020000
3355170.55f8: 00000000002c9000-00000000003fffff 0x0000/0x0004 0x0020000
3365170.55f8: *0000000000400000-00000000004fafff 0x0000/0x0004 0x0020000
3375170.55f8: 00000000004fb000-00000000004fdfff 0x0104/0x0004 0x0020000
3385170.55f8: 00000000004fe000-00000000004fffff 0x0004/0x0004 0x0020000
3395170.55f8: 0000000000500000-000000007ffdffff 0x0001/0x0000 0x0000000
3405170.55f8: *000000007ffe0000-000000007ffe0fff 0x0002/0x0002 0x0020000
3415170.55f8: 000000007ffe1000-000000007ffe6fff 0x0001/0x0000 0x0000000
3425170.55f8: *000000007ffe7000-000000007ffe7fff 0x0002/0x0002 0x0020000
3435170.55f8: 000000007ffe8000-00007ff59847ffff 0x0001/0x0000 0x0000000
3445170.55f8: *00007ff598480000-00007ff598480fff 0x0002/0x0002 0x0040000
3455170.55f8: 00007ff598481000-00007ff59848ffff 0x0001/0x0000 0x0000000
3465170.55f8: *00007ff598490000-00007ff5984b2fff 0x0002/0x0002 0x0040000
3475170.55f8: 00007ff5984b3000-00007ff7d61fffff 0x0001/0x0000 0x0000000
3485170.55f8: *00007ff7d6200000-00007ff7d6200fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
3495170.55f8: 00007ff7d6201000-00007ff7d6273fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
3505170.55f8: 00007ff7d6274000-00007ff7d6274fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
3515170.55f8: 00007ff7d6275000-00007ff7d62bbfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
3525170.55f8: 00007ff7d62bc000-00007ff7d62bcfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
3535170.55f8: 00007ff7d62bd000-00007ff7d62bdfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
3545170.55f8: 00007ff7d62be000-00007ff7d62c2fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
3555170.55f8: 00007ff7d62c3000-00007ff7d62c3fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
3565170.55f8: 00007ff7d62c4000-00007ff7d62c4fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
3575170.55f8: 00007ff7d62c5000-00007ff7d62c8fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
3585170.55f8: 00007ff7d62c9000-00007ff7d6311fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
3595170.55f8: 00007ff7d6312000-00007ffcbb16ffff 0x0001/0x0000 0x0000000
3605170.55f8: *00007ffcbb170000-00007ffcbb170fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
3615170.55f8: 00007ffcbb171000-00007ffcbb287fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
3625170.55f8: 00007ffcbb288000-00007ffcbb2cefff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
3635170.55f8: 00007ffcbb2cf000-00007ffcbb2d9fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
3645170.55f8: 00007ffcbb2da000-00007ffcbb2e7fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
3655170.55f8: 00007ffcbb2e8000-00007ffcbb2e8fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
3665170.55f8: 00007ffcbb2e9000-00007ffcbb2ebfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
3675170.55f8: 00007ffcbb2ec000-00007ffcbb35cfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
3685170.55f8: 00007ffcbb35d000-00007ffffffeffff 0x0001/0x0000 0x0000000
3695170.55f8: VirtualBoxVM.exe: timestamp 0x5c4b51f3 (rc=VINF_SUCCESS)
3705170.55f8: '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
3715170.55f8: '\Device\HarddiskVolume4\Windows\System32\ntdll.dll' has no imports
3725170.55f8: supR3HardNtChildPurify: Done after 585 ms and 0 fixes (loop #0).
3734760.2884: Log file opened: 6.0.4r128413 g_hStartupLog=0000000000000004 g_uNtVerCombined=0xa0456300
3744760.2884: supR3HardenedVmProcessInit: uNtDllAddr=00007ffcbb170000 g_uNtVerCombined=0xa0456300
3754760.2884: ntdll.dll: timestamp 0xe8b54827 (rc=VINF_SUCCESS)
3764760.2884: New simple heap: #1 0000000000600000 LB 0x400000 (for 2019328 allocation)
3775170.55f8: supR3HardenedEarlyCompact: Removed heap 1 (0x00000001100000 LB 0x400000)
3785170.55f8: supR3HardNtEnableThreadCreation:
3794760.2884: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox'
3804760.2884: System32: \Device\HarddiskVolume4\Windows\System32
3814760.2884: WinSxS: \Device\HarddiskVolume4\Windows\WinSxS
3824760.2884: KnownDllPath: C:\WINDOWS\System32
3834760.2884: supR3HardenedVmProcessInit: Opening vboxdrv...
3844760.2884: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
3854760.2884: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
3864760.2884: Registered Dll notification callback with NTDLL.
3874760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\kernel32.dll)
3884760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\kernel32.dll
3894760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\KERNEL32.DLL (Input=KERNEL32.DLL, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000004001:<flags> [calling]
3904760.2884: supR3HardenedDllNotificationCallback: load 00007ffcb80b0000 LB 0x00293000 C:\WINDOWS\System32\KERNELBASE.dll [fFlags=0x0]
3914760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\KernelBase.dll)
3924760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\KernelBase.dll
3934760.2884: supR3HardenedDllNotificationCallback: load 00007ffcba7c0000 LB 0x000b3000 C:\WINDOWS\System32\KERNEL32.DLL [fFlags=0x0]
3944760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
3954760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcba7c0000 'C:\WINDOWS\System32\KERNEL32.DLL'
3964760.2884: supR3HardenedDllNotificationCallback: load 00007ff7d6200000 LB 0x00112000 C:\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe [fFlags=0x0]
3974760.2884: '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
3984760.2884: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe)
3994760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
4004760.2884: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffcbb1e5640 pvNtTerminateThread=00007ffcbb2100b0
4015170.55f8: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 103 ms.
4024760.2884: \SystemRoot\System32\ntdll.dll:
4034760.2884: CreationTime: 2018-12-30T02:31:21.439974200Z
4044760.2884: LastWriteTime: 2018-12-30T02:31:21.455594900Z
4054760.2884: ChangeTime: 2019-01-08T21:05:01.868444500Z
4064760.2884: FileAttributes: 0x20
4074760.2884: Size: 0x1e7010
4084760.2884: NT Headers: 0xe0
4094760.2884: Timestamp: 0xe8b54827
4104760.2884: Machine: 0x8664 - amd64
4114760.2884: Timestamp: 0xe8b54827
4124760.2884: Image Version: 10.0
4134760.2884: SizeOfImage: 0x1ed000 (2019328)
4144760.2884: Resource Dir: 0x17d000 LB 0x6ea08
4154760.2884: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
4164760.2884: [Raw version resource data: 0x17d0f0 LB 0x380, codepage 0x0 (reserved 0x0)]
4174760.2884: ProductName: Microsoft® Windows® Operating System
4184760.2884: ProductVersion: 10.0.17763.194
4194760.2884: FileVersion: 10.0.17763.194 (WinBuild.160101.0800)
4204760.2884: FileDescription: NT Layer DLL
4214760.2884: \SystemRoot\System32\kernel32.dll:
4224760.2884: CreationTime: 2018-09-15T07:28:44.342269900Z
4234760.2884: LastWriteTime: 2018-09-15T07:28:44.342269900Z
4244760.2884: ChangeTime: 2018-12-30T02:37:12.140802400Z
4254760.2884: FileAttributes: 0x20
4264760.2884: Size: 0xb1380
4274760.2884: NT Headers: 0xe8
4284760.2884: Timestamp: 0x65614da1
4294760.2884: Machine: 0x8664 - amd64
4304760.2884: Timestamp: 0x65614da1
4314760.2884: Image Version: 10.0
4324760.2884: SizeOfImage: 0xb3000 (733184)
4334760.2884: Resource Dir: 0xb1000 LB 0x520
4344760.2884: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
4354760.2884: [Raw version resource data: 0xb10b0 LB 0x3a4, codepage 0x0 (reserved 0x0)]
4364760.2884: ProductName: Microsoft® Windows® Operating System
4374760.2884: ProductVersion: 10.0.17763.1
4384760.2884: FileVersion: 10.0.17763.1 (WinBuild.160101.0800)
4394760.2884: FileDescription: Windows NT BASE API Client DLL
4404760.2884: \SystemRoot\System32\KernelBase.dll:
4414760.2884: CreationTime: 2018-12-30T02:31:21.205655900Z
4424760.2884: LastWriteTime: 2018-12-30T02:31:21.236896100Z
4434760.2884: ChangeTime: 2019-01-08T21:05:01.867446600Z
4444760.2884: FileAttributes: 0x20
4454760.2884: Size: 0x293cc8
4464760.2884: NT Headers: 0xf8
4474760.2884: Timestamp: 0x1659a33b
4484760.2884: Machine: 0x8664 - amd64
4494760.2884: Timestamp: 0x1659a33b
4504760.2884: Image Version: 10.0
4514760.2884: SizeOfImage: 0x293000 (2699264)
4524760.2884: Resource Dir: 0x26f000 LB 0x548
4534760.2884: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
4544760.2884: [Raw version resource data: 0x26f0b0 LB 0x3bc, codepage 0x0 (reserved 0x0)]
4554760.2884: ProductName: Microsoft® Windows® Operating System
4564760.2884: ProductVersion: 10.0.17763.134
4574760.2884: FileVersion: 10.0.17763.134 (WinBuild.160101.0800)
4584760.2884: FileDescription: Windows NT BASE API Client DLL
4594760.2884: \SystemRoot\System32\apisetschema.dll:
4604760.2884: CreationTime: 2018-09-15T07:28:25.403122600Z
4614760.2884: LastWriteTime: 2018-09-15T07:28:25.403122600Z
4624760.2884: ChangeTime: 2018-12-30T02:29:00.950166300Z
4634760.2884: FileAttributes: 0x20
4644760.2884: Size: 0x1c738
4654760.2884: NT Headers: 0xd0
4664760.2884: Timestamp: 0x33775897
4674760.2884: Machine: 0x8664 - amd64
4684760.2884: Timestamp: 0x33775897
4694760.2884: Image Version: 10.0
4704760.2884: SizeOfImage: 0x1d000 (118784)
4714760.2884: Resource Dir: 0x1c000 LB 0x408
4724760.2884: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
4734760.2884: [Raw version resource data: 0x1c060 LB 0x3a8, codepage 0x0 (reserved 0x0)]
4744760.2884: ProductName: Microsoft® Windows® Operating System
4754760.2884: ProductVersion: 10.0.17763.1
4764760.2884: FileVersion: 10.0.17763.1 (WinBuild.160101.0800)
4774760.2884: FileDescription: ApiSet Schema DLL
4784760.2884: NtOpenDirectoryObject failed on \Driver: 0xc0000022
4794760.2884: supR3HardenedWinFindAdversaries: 0x8000
4804760.2884: \SystemRoot\System32\drivers\cyprotectdrv64.sys:
4814760.2884: CreationTime: 2018-12-30T23:56:45.646933300Z
4824760.2884: LastWriteTime: 2019-01-07T19:47:35.388882000Z
4834760.2884: ChangeTime: 2019-01-30T22:49:57.834123800Z
4844760.2884: FileAttributes: 0x20
4854760.2884: Size: 0x332a8
4864760.2884: NT Headers: 0xf8
4874760.2884: Timestamp: 0x5c05c934
4884760.2884: Machine: 0x8664 - amd64
4894760.2884: Timestamp: 0x5c05c934
4904760.2884: Image Version: 6.1
4914760.2884: SizeOfImage: 0x134000 (1261568)
4924760.2884: Resource Dir: 0x132000 LB 0x2f0
4934760.2884: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
4944760.2884: [Raw version resource data: 0x132060 LB 0x28c, codepage 0x0 (reserved 0x0)]
4954760.2884: ProductName: CylancePROTECT
4964760.2884: ProductVersion: 2.0.1510.8
4974760.2884: FileVersion: 2.0.1510.8
4984760.2884: FileDescription: Cylance Protect Driver
4994760.2884: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox'
5004760.2884: Calling main()
5014760.2884: SUPR3HardenedMain: pszProgName=VirtualBoxVM fFlags=0x2
5024760.2884: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox'
5034760.2884: '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
5044760.2884: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe)
5054760.2884: SUPR3HardenedMain: Final process, opening VBoxDrv...
5064760.2884: supR3HardenedEarlyCompact: Removed heap 1 (0x00000000600000 LB 0x400000)
5074760.2884: supR3HardNtEnableThreadCreation:
5084760.2884: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSupLib.dll)
5094760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSupLib.dll
5104760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
5114760.2884: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
5124760.2884: supR3HardenedDllNotificationCallback: load 00007ffcb4790000 LB 0x00005000 C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL [fFlags=0x0]
5134760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
5144760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
5154760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
5164760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb4790000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
5174760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
5184760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
5194760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb4790000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
5204760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb4790000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
5214760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
5224760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msasn1.dll'.
5234760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'crypt32.dll'.
5244760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 'rpcrt4.dll'.
5254760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\wintrust.dll)
5264760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\wintrust.dll
5274760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
5284760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
5294760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll)
5304760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll
5314760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
5324760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume4\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
5334760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #34 'msasn1.dll'.
5344760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\crypt32.dll)
5354760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\crypt32.dll
5364760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
5374760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume4\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
5384760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\msasn1.dll)
5394760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\msasn1.dll
5404760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
5414760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
5424760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\msvcrt.dll)
5434760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\msvcrt.dll
5444760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
5454760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume4\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
5464760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
5474760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
5484760.2884: supR3HardenedDllNotificationCallback: load 00007ffcb8aa0000 LB 0x0009e000 C:\WINDOWS\System32\msvcrt.dll [fFlags=0x0]
5494760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
5504760.2884: supR3HardenedDllNotificationCallback: load 00007ffcb71d0000 LB 0x00012000 C:\WINDOWS\System32\MSASN1.dll [fFlags=0x0]
5514760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
5524760.2884: supR3HardenedDllNotificationCallback: load 00007ffcb7d80000 LB 0x000fc000 C:\WINDOWS\System32\ucrtbase.dll [fFlags=0x0]
5534760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\ucrtbase.dll)
5544760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\ucrtbase.dll
5554760.2884: supR3HardenedDllNotificationCallback: load 00007ffcb7e80000 LB 0x001db000 C:\WINDOWS\System32\CRYPT32.dll [fFlags=0x0]
5564760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
5574760.2884: supR3HardenedDllNotificationCallback: load 00007ffcb9140000 LB 0x00122000 C:\WINDOWS\System32\RPCRT4.dll [fFlags=0x0]
5584760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
5594760.2884: supR3HardenedDllNotificationCallback: load 00007ffcb7a10000 LB 0x00058000 C:\WINDOWS\System32\Wintrust.dll [fFlags=0x0]
5604760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
5614760.2884: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
5624760.2884: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
5634760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb80b0000 'api-ms-win-core-synch-l1-2-0'
5644760.2884: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
5654760.2884: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
5664760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb80b0000 'api-ms-win-core-fibers-l1-1-1'
5674760.2884: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
5684760.2884: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
5694760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb80b0000 'api-ms-win-core-fibers-l1-1-1'
5704760.2884: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
5714760.2884: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
5724760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb80b0000 'api-ms-win-core-synch-l1-2-0'
5734760.2884: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-l1-2-1) -> 0x0, fPresent=1
5744760.2884: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-l1-2-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
5754760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb80b0000 'api-ms-win-core-localization-l1-2-1'
5764760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7a10000 'C:\WINDOWS\system32\Wintrust.dll'
5774760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\bcrypt.dll)
5784760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\bcrypt.dll
5794760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\bcrypt.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
5804760.2884: supR3HardenedDllNotificationCallback: load 00007ffcb8370000 LB 0x00026000 C:\WINDOWS\System32\bcrypt.dll [fFlags=0x0]
5814760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
5824760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb8370000 'C:\WINDOWS\system32\bcrypt.dll'
5834760.2884: bcrypt.dll loaded at 00007ffcb8370000, BCryptOpenAlgorithmProvider at 00007ffcb8374d60, preloading providers:
5844760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\bcryptprimitives.dll)
5854760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\bcryptprimitives.dll
5864760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\bcryptprimitives.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
5874760.2884: supR3HardenedDllNotificationCallback: load 00007ffcb7240000 LB 0x0007e000 C:\WINDOWS\System32\bcryptprimitives.dll [fFlags=0x0]
5884760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
5894760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7240000 'C:\WINDOWS\system32\bcryptprimitives.dll'
5904760.2884: BCryptOpenAlgorithmProvider(,'MD2',0,0) -> 0x0 (hAlgo=0000000000a0edc0)
5914760.2884: BCryptOpenAlgorithmProvider(,'MD4',0,0) -> 0x0 (hAlgo=0000000000a0fb20)
5924760.2884: BCryptOpenAlgorithmProvider(,'MD5',0,0) -> 0x0 (hAlgo=0000000000a0fe20)
5934760.2884: BCryptOpenAlgorithmProvider(,'SHA1',0,0) -> 0x0 (hAlgo=0000000000a10120)
5944760.2884: BCryptOpenAlgorithmProvider(,'SHA256',0,0) -> 0x0 (hAlgo=0000000000a10420)
5954760.2884: BCryptOpenAlgorithmProvider(,'SHA512',0,0) -> 0x0 (hAlgo=0000000000a10720)
5964760.2884: BCryptOpenAlgorithmProvider(,'RSA',0,0) -> 0x0 (hAlgo=0000000000a10a20)
5974760.2884: BCryptOpenAlgorithmProvider(,'DSA',0,0) -> 0x0 (hAlgo=0000000000a10d20)
5984760.2884: supR3HardenedDllNotificationCallback: load 00007ffcb7d60000 LB 0x00017000 C:\WINDOWS\System32\CRYPTSP.dll [fFlags=0x0]
5994760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\cryptsp.dll)
6004760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\cryptsp.dll
6014760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'bcrypt.dll'.
6024760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\rsaenh.dll)
6034760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\rsaenh.dll
6044760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
6054760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume4\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
6064760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
6074760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
6084760.2884: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
6094760.2884: supR3HardenedDllNotificationCallback: load 00007ffcb6520000 LB 0x00033000 C:\WINDOWS\system32\rsaenh.dll [fFlags=0x0]
6104760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
6114760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
6124760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'bcryptprimitives.dll'.
6134760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\cryptbase.dll)
6144760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\cryptbase.dll
6154760.2884: supR3HardenedDllNotificationCallback: load 00007ffcb6ad0000 LB 0x0000c000 C:\WINDOWS\SYSTEM32\CRYPTBASE.dll [fFlags=0x0]
6164760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\cryptbase.dll [lacks WinVerifyTrust]
6174760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
6184760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcryptprimitives.dll'...
6194760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcryptprimitives.dll' -> '\Device\HarddiskVolume4\Windows\System32\bcryptprimitives.dll' [rcNtRedir=0xc0150008]
6204760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
6214760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
6224760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcba7c0000 'C:\WINDOWS\System32\kernel32.dll'
6234760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
6244760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\WINTRUST.DLL (Input=WINTRUST.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
6254760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7a10000 'C:\WINDOWS\System32\WINTRUST.DLL'
6264760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
6274760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\CRYPT32.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
6284760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\CRYPT32.dll'
6294760.2884: supR3HardenedDllNotificationCallback: load 00007ffcb87f0000 LB 0x0001d000 C:\WINDOWS\System32\imagehlp.dll [fFlags=0x0]
6304760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\imagehlp.dll)
6314760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\imagehlp.dll
6324760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
6334760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
6344760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
6354760.2884: supR3HardenedDllNotificationCallback: load 00007ffcbad70000 LB 0x0009e000 C:\WINDOWS\System32\sechost.dll [fFlags=0x0]
6364760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'rpcrt4.dll'.
6374760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\sechost.dll)
6384760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\sechost.dll
6394760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
6404760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'rpcrt4.dll'.
6414760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\gpapi.dll)
6424760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\gpapi.dll
6434760.2884: supR3HardenedDllNotificationCallback: load 00007ffcb5e20000 LB 0x00022000 C:\WINDOWS\SYSTEM32\gpapi.dll [fFlags=0x0]
6444760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gpapi.dll [lacks WinVerifyTrust]
6454760.2884: supR3HardenedDllNotificationCallback: load 00007ffcb7210000 LB 0x00024000 C:\WINDOWS\System32\profapi.dll [fFlags=0x0]
6464760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\profapi.dll)
6474760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\profapi.dll
6484760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
6494760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'crypt32.dll'.
6504760.2884: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\System32\cryptnet.dll)
6514760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\cryptnet.dll
6524760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
6534760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume4\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
6544760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
6554760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
6564760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
6574760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
6584760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
6594760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
6604760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
6614760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
6624760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
6634760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
6644760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
6654760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
6664760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
6674760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (Input=cryptnet.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
6684760.2884: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6694760.2884: supR3HardenedDllNotificationCallback: load 00007ffc9cfa0000 LB 0x0002f000 C:\WINDOWS\System32\cryptnet.dll [fFlags=0x0]
6704760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6714760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6724760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
6734760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc9cfa0000 'C:\WINDOWS\System32\cryptnet.dll'
6744760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6754760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
6764760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc9cfa0000 'C:\WINDOWS\System32\cryptnet.dll'
6774760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6784760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
6794760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc9cfa0000 'C:\WINDOWS\System32\cryptnet.dll'
6804760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6814760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
6824760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc9cfa0000 'C:\WINDOWS\System32\cryptnet.dll'
6834760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6844760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
6854760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc9cfa0000 'C:\WINDOWS\System32\cryptnet.dll'
6864760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6874760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
6884760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc9cfa0000 'C:\WINDOWS\System32\cryptnet.dll'
6894760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6904760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc9cfa0000 'C:\WINDOWS\System32\cryptnet.dll'
6914760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6924760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc9cfa0000 'C:\WINDOWS\System32\cryptnet.dll'
6934760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6944760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc9cfa0000 'C:\WINDOWS\System32\cryptnet.dll'
6954760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6964760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc9cfa0000 'C:\WINDOWS\System32\cryptnet.dll'
6974760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6984760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc9cfa0000 'C:\WINDOWS\System32\cryptnet.dll'
6994760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc9cfa0000 'C:\WINDOWS\System32\cryptnet.dll'
7004760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
7014760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc9cfa0000 'C:\Windows\System32\cryptnet.dll'
7024760.2884: supR3HardenedDllNotificationCallback: load 00007ffcb8520000 LB 0x000a3000 C:\WINDOWS\System32\advapi32.dll [fFlags=0x0]
7034760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
7044760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'sechost.dll'.
7054760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 'rpcrt4.dll'.
7064760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\advapi32.dll)
7074760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\advapi32.dll
7084760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
7094760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
7104760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
7114760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
7124760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'sechost.dll'...
7134760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'sechost.dll' -> '\Device\HarddiskVolume4\Windows\System32\sechost.dll' [rcNtRedir=0xc0150008]
7144760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\sechost.dll [lacks WinVerifyTrust]
7154760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
7164760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
7174760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
7184760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
7194760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
7204760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
7214760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
7224760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
7234760.2884: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000000 pwszName=\SystemRoot\System32\ntdll.dll
7244760.2884: supR3HardNtViCallWinVerifyTrustCatFile: New context 0000000000a97690
7254760.2884: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000a97690
7264760.2884: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=E118BAE0A2CBC497F05FE519F5B8FB6FCD99D346
7274760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
7284760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\rpcrt4.dll (Input=rpcrt4.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
7294760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb9140000 'C:\WINDOWS\System32\rpcrt4.dll'
7304760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
7314760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
7324760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
7334760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
7344760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
7354760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
7364760.2884: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_352_for_KB4483235~31bf3856ad364e35~amd64~~10.0.1.1.cat'; file='\SystemRoot\System32\ntdll.dll'
7374760.2884: g_pfnWinVerifyTrust=00007ffcb7a16370
7384760.2884: supR3HardenedScreenImage/preload: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll [redoing WinVerifyTrust]
7394760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
7404760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
7414760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
7424760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
7434760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
7444760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
7454760.2884: supR3HardenedScreenImage/preload: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\crypt32.dll'
7464760.2884: supR3HardenedScreenImage/preload: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [redoing WinVerifyTrust]
7474760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
7484760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
7494760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
7504760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll
7514760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
7524760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
7534760.2884: supR3HardenedScreenImage/preload: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\wintrust.dll'
7544760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
7554760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
7564760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
7574760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
7584760.2884: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\advapi32.dll'
7594760.2884: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000398 pwszName=\Device\HarddiskVolume4\Windows\System32\cryptnet.dll
7604760.2884: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000a97690
7614760.2884: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000a97690
7624760.2884: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=A71FAF93E7F6555CF5752D6A603A870E378E49E6
7634760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
7644760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
7654760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
7664760.2884: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0316~31bf3856ad364e35~amd64~~10.0.17763.1.cat'; file='\Device\HarddiskVolume4\Windows\System32\cryptnet.dll'
7674760.2884: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
7684760.2884: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\cryptnet.dll'
7694760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
7704760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
7714760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
7724760.2884: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\profapi.dll'
7734760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
7744760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
7754760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
7764760.2884: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\gpapi.dll'
7774760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
7784760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
7794760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
7804760.2884: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\sechost.dll'
7814760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
7824760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
7834760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
7844760.2884: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\imagehlp.dll'
7854760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
7864760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
7874760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
7884760.2884: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\cryptbase.dll'
7894760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
7904760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
7914760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll
7924760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
7934760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
7944760.2884: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\rsaenh.dll'
7954760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll
7964760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
7974760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
7984760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
7994760.2884: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\cryptsp.dll'
8004760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
8014760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
8024760.2884: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\bcryptprimitives.dll'
8034760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
8044760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
8054760.2884: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\bcrypt.dll'
8064760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
8074760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
8084760.2884: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\ucrtbase.dll'
8094760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
8104760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
8114760.2884: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll'
8124760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
8134760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
8144760.2884: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\msasn1.dll'
8154760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
8164760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
8174760.2884: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll'
8184760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
8194760.2884: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 24202) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSupLib.dll'
8204760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
8214760.2884: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 24202) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe'
8224760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
8234760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
8244760.2884: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\KernelBase.dll'
8254760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
8264760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
8274760.2884: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\kernel32.dll'
8284760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\system32\crypt32.dll'
8294760.2884: supR3HardenedWinIsDesiredRootCA: Adding 0x5ad46780fa5df300 DC=com, DC=microsoft, CN=Microsoft Root Certificate Authority
8304760.2884: supR3HardenedWinIsDesiredRootCA: Adding 0xea5386456178582b C=ZA, ST=Western Cape, L=Durbanville, O=Thawte, OU=Thawte Certification, CN=Thawte Timestamping CA
8314760.2884: supR3HardenedWinIsDesiredRootCA: Adding 0x3be670c1bd02a900 OU=Copyright (c) 1997 Microsoft Corp., OU=Microsoft Corporation, CN=Microsoft Root Authority
8324760.2884: supR3HardenedWinIsDesiredRootCA: Adding 0xe991ee72b03db500 C=US, O=Symantec Corporation, CN=Symantec Enterprise Mobile Root for Microsoft
8334760.2884: supR3HardenedWinIsDesiredRootCA: Adding 0x4d3835aa4180b200 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2011
8344760.2884: supR3HardenedWinIsDesiredRootCA: Adding 0x646e3fe3ba08df00 C=US, O=MSFT, CN=Microsoft Authenticode(tm) Root Authority
8354760.2884: supR3HardenedWinIsDesiredRootCA: Adding 0xeaf38b956934d200 CN=DESKTOP-TS00JCV
8364760.2884: supR3HardenedWinIsDesiredRootCA: Adding 0xece4e4289e08b900 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010
8374760.2884: supR3HardenedWinIsDesiredRootCA: Adding 0xf3bb4d7e894b420 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft ECC TS Root Certificate Authority 2018
8384760.2884: supR3HardenedWinIsDesiredRootCA: Adding 0x43a9cc371ff5385a O=Microsoft Trust Network, OU=Microsoft Corporation, OU=Microsoft Time Stamping Service Root, OU=Copyright (c) 1997 Microsoft Corp.
8394760.2884: supR3HardenedWinIsDesiredRootCA: Adding 0x2e2d2c7c68f0202e O=VeriSign Trust Network, OU=VeriSign, Inc., OU=VeriSign Time Stamping Service Root, OU=NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.
8404760.2884: supR3HardenedWinIsDesiredRootCA: Adding 0xcec3d46562b9be8e C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft ECC Product Root Certificate Authority 2018
8414760.2884: supR3HardenedWinIsDesiredRootCA: Adding 0xd8dbfb2c27bfb200 C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2008 thawte, Inc. - For authorized use only, CN=thawte Primary Root CA - G3
8424760.2884: supR3HardenedWinIsDesiredRootCA: Adding 0x61a3a33f81aace00 C=US, ST=UT, L=Salt Lake City, O=The USERTRUST Network, OU=http://www.usertrust.com, CN=UTN-USERFirst-Object
8434760.2884: supR3HardenedWinIsDesiredRootCA: Adding 0x6b7bdc34cd37bb00 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root G2
8444760.2884: supR3HardenedWinIsDesiredRootCA: Adding 0x57ba5395b561bf00 C=BM, O=QuoVadis Limited, OU=Root Certification Authority, CN=QuoVadis Root Certification Authority
8454760.2884: supR3HardenedWinIsDesiredRootCA: Adding 0xf4fd306318ccda00 C=US, O=GeoTrust Inc., CN=GeoTrust Global CA
8464760.2884: supR3HardenedWinIsDesiredRootCA: Adding 0x83085097e9afdf00 O=Digital Signature Trust Co., CN=DST Root CA X3
8474760.2884: supR3HardenedWinIsDesiredRootCA: Adding 0x780679907625cc00 OU=GlobalSign Root CA - R3, O=GlobalSign, CN=GlobalSign
8484760.2884: supR3HardenedWinIsDesiredRootCA: Adding 0x3d98ab22bb04a300 C=IE, O=Baltimore, OU=CyberTrust, CN=Baltimore CyberTrust Root
8494760.2884: supR3HardenedWinIsDesiredRootCA: Adding 0x9403a4b8727eb000 C=TW, O=TAIWAN-CA, OU=Root CA, CN=TWCA Root Certification Authority
8504760.2884: supR3HardenedWinIsDesiredRootCA: Adding 0xd944bca189a00 C=BM, O=QuoVadis Limited, CN=QuoVadis Root CA 2
8514760.2884: supR3HardenedWinIsDesiredRootCA: Adding 0x8ff6fc03c1edbd00 C=US, ST=Arizona, L=Scottsdale, O=Starfield Technologies, Inc., CN=Starfield Root Certificate Authority - G2
8524760.2884: supR3HardenedWinIsDesiredRootCA: Adding 0xc6fa4243b695b600 C=US, O=Entrust, Inc., OU=www.entrust.net/CPS is incorporated by reference, OU=(c) 2006 Entrust, Inc., CN=Entrust Root Certification Authority
8534760.2884: supR3HardenedWinIsDesiredRootCA: Adding 0xa3ce8d99e60eda00 C=BE, O=GlobalSign nv-sa, OU=Root CA, CN=GlobalSign Root CA
8544760.2884: supR3HardenedWinIsDesiredRootCA: Adding 0x560ad29254e89100 C=GB, ST=Greater Manchester, L=Salford, O=COMODO CA Limited, CN=COMODO RSA Certification Authority
8554760.2884: supR3HardenedWinIsDesiredRootCA: Adding 0xa671e9fec832b700 C=US, O=Starfield Technologies, Inc., OU=Starfield Class 2 Certification Authority
8564760.2884: supR3HardenedWinIsDesiredRootCA: Adding 0xa8de7211e13be200 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root CA
8574760.2884: supR3HardenedWinIsDesiredRootCA: Adding 0xd45980fbf0a0ac00 C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2006 thawte, Inc. - For authorized use only, CN=thawte Primary Root CA
8584760.2884: supR3HardenedWinIsDesiredRootCA: Adding 0xef62113787ebace5 C=US, O=GeoTrust Inc., OU=(c) 2007 GeoTrust Inc. - For authorized use only, CN=GeoTrust Primary Certification Authority - G2
8594760.2884: supR3HardenedWinIsDesiredRootCA: Adding 0xc9edb72b684ba00 C=US, O=Entrust, Inc., OU=See www.entrust.net/legal-terms, OU=(c) 2009 Entrust, Inc. - for authorized use only, CN=Entrust Root Certification Authority - G2
8604760.2884: supR3HardenedWinIsDesiredRootCA: Adding 0xf5cd95e581a4ab00 C=US, O=SecureTrust Corporation, CN=SecureTrust CA
8614760.2884: supR3HardenedWinIsDesiredRootCA: Adding 0x6f2ebe0e24cfa600 OU=GlobalSign Root CA - R2, O=GlobalSign, CN=GlobalSign
8624760.2884: supR3HardenedWinIsDesiredRootCA: Adding 0x14018a1bf29e595c C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority
8634760.2884: supR3HardenedWinIsDesiredRootCA: Adding 0x7c4fd32ec1b1ce00 C=PL, O=Unizeto Sp. z o.o., CN=Certum CA
8644760.2884: supR3HardenedWinIsDesiredRootCA: Adding 0xd4fbe673e5ccc600 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA
8654760.2884: supR3HardenedWinIsDesiredRootCA: Adding 0xef477acf4ab2d300 C=DE, O=D-Trust GmbH, CN=D-TRUST Root Class 3 CA 2 2009
8664760.2884: supR3HardenedWinIsDesiredRootCA: Adding 0x1b8578514b74ac00 C=US, O=WFA Hotspot 2.0, CN=Hotspot 2.0 Trust Root CA - 03
8674760.2884: supR3HardenedWinIsDesiredRootCA: Adding 0xb28612a94b4dad00 O=Entrust.net, OU=www.entrust.net/CPS_2048 incorp. by ref. (limits liab.), OU=(c) 1999 Entrust.net Limited, CN=Entrust.net Certification Authority (2048)
8684760.2884: supR3HardenedWinIsDesiredRootCA: Adding 0x357a29080824af00 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2006 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G5
8694760.2884: supR3HardenedWinIsDesiredRootCA: Adding 0x59faf1086271bf00 C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com, Inc., CN=Go Daddy Root Certificate Authority - G2
8704760.2884: supR3HardenedWinIsDesiredRootCA: Adding 0x466cbc09db88c100 C=IL, O=StartCom Ltd., OU=Secure Digital Certificate Signing, CN=StartCom Certification Authority
8714760.2884: supR3HardenedWinIsDesiredRootCA: Adding 0x3401b15e3761c700 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2008 VeriSign, Inc. - For authorized use only, CN=VeriSign Universal Root Certification Authority
8724760.2884: supR3HardenedWinIsDesiredRootCA: Adding 0x491857ead79dde00 C=US, O=The Go Daddy Group, Inc., OU=Go Daddy Class 2 Certification Authority
8734760.2884: supR3HardenedWinIsDesiredRootCA: Adding 0x1f78fc529cbacb00 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 1999 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G3
8744760.2884: supR3HardenedWinIsDesiredRootCA: Adding 0xc2ba72a37dfbe300 C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Trusted Network CA
8754760.2884: supR3HardenedWinIsDesiredRootCA: Adding 0x8043e4ce150ead00 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID Root CA
8764760.2884: supR3HardenedWinIsDesiredRootCA: Adding 0xf2e6331af7b700 C=SE, O=AddTrust AB, OU=AddTrust External TTP Network, CN=AddTrust External CA Root
8774760.2884: supR3HardenedWinRetrieveTrustedRootCAs: cAdded=48
8784760.2884: SUPR3HardenedMain: Load Runtime...
8794760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
8804760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
8814760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
8824760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rpcrt4.dll'.
8834760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ws2_32.dll'.
8844760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll) WinVerifyTrust
8854760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
8864760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
8874760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
8884760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
8894760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
8904760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'rpcrt4.dll'.
8914760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\ws2_32.dll) WinVerifyTrust
8924760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\ws2_32.dll
8934760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
8944760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
8954760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll
8964760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
8974760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
8984760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
8994760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
9004760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll
9014760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
9024760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
9034760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll) WinVerifyTrust
9044760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll
9054760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
9064760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
9074760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
9084760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
9094760.2884: Detected WinVerifyTrust recursion: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll'.
9104760.2884: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll)
9114760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll
9124760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
9134760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll) WinVerifyTrust
9144760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000a01:<flags> [calling]
9154760.2884: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
9164760.2884: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll [avoiding WinVerifyTrust]
9174760.2884: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll
9184760.2884: supR3HardenedDllNotificationCallback: load 000000006cd40000 LB 0x000d2000 C:\Program Files\Oracle\VirtualBox\MSVCR100.dll [fFlags=0x0]
9194760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll [avoiding WinVerifyTrust]
9204760.2884: supR3HardenedDllNotificationCallback: load 000000006c730000 LB 0x00098000 C:\Program Files\Oracle\VirtualBox\MSVCP100.dll [fFlags=0x0]
9214760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll
9224760.2884: supR3HardenedDllNotificationCallback: load 00007ffcb8a30000 LB 0x0006d000 C:\WINDOWS\System32\WS2_32.dll [fFlags=0x0]
9234760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ws2_32.dll
9244760.2884: supR3HardenedDllNotificationCallback: load 00007ffc79710000 LB 0x0052d000 C:\Program Files\Oracle\VirtualBox\VBoxRT.dll [fFlags=0x0]
9254760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
9264760.2884: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll'.
9274760.2884: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
9284760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
9294760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9304760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9314760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
9324760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9334760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9344760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
9354760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9364760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9374760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
9384760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9394760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9404760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
9414760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9424760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9434760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
9444760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9454760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9464760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9474760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9484760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9494760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9504760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9514760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9524760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9534760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
9544760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9554760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9564760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9574760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9584760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9594760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9604760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9614760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9624760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9634760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9644760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9654760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9664760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9674760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9684760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9694760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9704760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9714760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
9724760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9734760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9744760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9754760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9764760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9774760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll
9784760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
9794760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7a10000 'C:\WINDOWS\system32\Wintrust.dll'
9804760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
9814760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
9824760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll
9834760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9844760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
9854760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
9864760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\system32\crypt32.dll'
9874760.2884: SUPR3HardenedMain: Load TrustedMain...
9884760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
9894760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'opengl32.dll'.
9904760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxglobal.dll'.
9914760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
9924760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcp100.dll'.
9934760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msvcr100.dll'.
9944760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'qt5corevbox.dll'.
9954760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'qt5guivbox.dll'.
9964760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'qt5widgetsvbox.dll'.
9974760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'qt5openglvbox.dll'.
9984760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'user32.dll'.
9994760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'ole32.dll'.
10004760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'oleaut32.dll'.
10014760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'winmm.dll'.
10024760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll) WinVerifyTrust
10034760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll
10044760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
10054760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume4\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
10064760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
10074760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
10084760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'winmmbase.dll'.
10094760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msvcrt.dll'.
10104760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\winmm.dll) WinVerifyTrust
10114760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\winmm.dll
10124760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
10134760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume4\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
10144760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
10154760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
10164760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll
10174760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmmbase.dll'...
10184760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmmbase.dll' -> '\Device\HarddiskVolume4\Windows\System32\winmmbase.dll' [rcNtRedir=0xc0150008]
10194760.2884: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\winmmbase.dll'.
10204760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
10214760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\winmmbase.dll)
10224760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\winmmbase.dll
10234760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
10244760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
10254760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll
10264760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
10274760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll
10284760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
10294760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
10304760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
10314760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'combase.dll'.
10324760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'rpcrt4.dll'.
10334760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\oleaut32.dll) WinVerifyTrust
10344760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\oleaut32.dll
10354760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
10364760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
10374760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
10384760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
10394760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll
10404760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
10414760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume4\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
10424760.2884: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\combase.dll'.
10434760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rpcrt4.dll'.
10444760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #46 'bcryptprimitives.dll'.
10454760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\combase.dll)
10464760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\combase.dll
10474760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
10484760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
10494760.2884: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\msvcp_win.dll'.
10504760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\msvcp_win.dll)
10514760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\msvcp_win.dll
10524760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcryptprimitives.dll'...
10534760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcryptprimitives.dll' -> '\Device\HarddiskVolume4\Windows\System32\bcryptprimitives.dll' [rcNtRedir=0xc0150008]
10544760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\bcryptprimitives.dll
10554760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
10564760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
10574760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
10584760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
10594760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'rpcrt4.dll'.
10604760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #55 'gdi32.dll'.
10614760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #56 'user32.dll'.
10624760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #57 'combase.dll'.
10634760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\ole32.dll) WinVerifyTrust
10644760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\ole32.dll
10654760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
10664760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
10674760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
10684760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume4\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
10694760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\combase.dll [lacks WinVerifyTrust]
10704760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
10714760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
10724760.2884: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\user32.dll'.
10734760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'win32u.dll'.
10744760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #34 'gdi32.dll'.
10754760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\user32.dll)
10764760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\user32.dll
10774760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
10784760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
10794760.2884: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\gdi32.dll'.
10804760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\gdi32.dll)
10814760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\gdi32.dll
10824760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
10834760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
10844760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
10854760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
10864760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
10874760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
10884760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume4\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
10894760.2884: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\win32u.dll'.
10904760.2884: '\Device\HarddiskVolume4\Windows\System32\win32u.dll' has no imports
10914760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\win32u.dll)
10924760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\win32u.dll
10934760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
10944760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
10954760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'win32u.dll'.
10964760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #34 'gdi32.dll'.
10974760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\user32.dll) WinVerifyTrust
10984760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5openglvbox.dll'...
10994760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5openglvbox.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qt5openglvbox.dll' [rcNtRedir=0xc0150008]
11004760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
11014760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
11024760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
11034760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
11044760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume4\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
11054760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\win32u.dll [lacks WinVerifyTrust]
11064760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
11074760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'qt5widgetsvbox.dll'.
11084760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'qt5guivbox.dll'.
11094760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5corevbox.dll'.
11104760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcr100.dll'.
11114760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll) WinVerifyTrust
11124760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll
11134760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
11144760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
11154760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
11164760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
11174760.2884: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
11184760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
11194760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
11204760.2884: Detected WinVerifyTrust recursion: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll'.
11214760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
11224760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'shell32.dll'.
11234760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ole32.dll'.
11244760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
11254760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ws2_32.dll'.
11264760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'mpr.dll'.
11274760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'msvcp100.dll'.
11284760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'msvcr100.dll'.
11294760.2884: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll)
11304760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
11314760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
11324760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
11334760.2884: Detected WinVerifyTrust recursion: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll'.
11344760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ole32.dll'.
11354760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'opengl32.dll'.
11364760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
11374760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
11384760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qt5corevbox.dll'.
11394760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcp100.dll'.
11404760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcr100.dll'.
11414760.2884: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll)
11424760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
11434760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
11444760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
11454760.2884: Detected WinVerifyTrust recursion: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll'.
11464760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
11474760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
11484760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5guivbox.dll'.
11494760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qt5corevbox.dll'.
11504760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'shell32.dll'.
11514760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcp100.dll'.
11524760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcr100.dll'.
11534760.2884: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll)
11544760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll
11554760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
11564760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
11574760.2884: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
11584760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
11594760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
11604760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll
11614760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
11624760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume4\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
11634760.2884: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\shell32.dll'.
11644760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
11654760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #75 'user32.dll'.
11664760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #77 'gdi32.dll'.
11674760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\shell32.dll)
11684760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\shell32.dll
11694760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
11704760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
11714760.2884: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [lacks WinVerifyTrust]
11724760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
11734760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
11744760.2884: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll [lacks WinVerifyTrust]
11754760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
11764760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
11774760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll [lacks WinVerifyTrust]
11784760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
11794760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
11804760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
11814760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
11824760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
11834760.2884: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
11844760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
11854760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
11864760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll
11874760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
11884760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
11894760.2884: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [lacks WinVerifyTrust]
11904760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
11914760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
11924760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll [lacks WinVerifyTrust]
11934760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
11944760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
11954760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
11964760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
11974760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume4\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
11984760.2884: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume4\Windows\System32\opengl32.dll'.
11994760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
12004760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
12014760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
12024760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
12034760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'glu32.dll'.
12044760.2884: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\System32\opengl32.dll)
12054760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\opengl32.dll
12064760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
12074760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
12084760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ole32.dll
12094760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
12104760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
12114760.2884: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
12124760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
12134760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
12144760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll
12154760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mpr.dll'...
12164760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'mpr.dll' -> '\Device\HarddiskVolume4\Windows\System32\mpr.dll' [rcNtRedir=0xc0150008]
12174760.2884: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\mpr.dll'.
12184760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\mpr.dll)
12194760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\mpr.dll
12204760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
12214760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
12224760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ws2_32.dll
12234760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
12244760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
12254760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\advapi32.dll
12264760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
12274760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
12284760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ole32.dll
12294760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
12304760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume4\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
12314760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\shell32.dll [lacks WinVerifyTrust]
12324760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
12334760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
12344760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll [lacks WinVerifyTrust]
12354760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'glu32.dll'...
12364760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'glu32.dll' -> '\Device\HarddiskVolume4\Windows\System32\glu32.dll' [rcNtRedir=0xc0150008]
12374760.2884: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume4\Windows\System32\glu32.dll'.
12384760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
12394760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
12404760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'opengl32.dll'.
12414760.2884: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\System32\glu32.dll)
12424760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\glu32.dll
12434760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
12444760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
12454760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
12464760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
12474760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
12484760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll [lacks WinVerifyTrust]
12494760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
12504760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
12514760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\advapi32.dll
12524760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
12534760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
12544760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll
12554760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
12564760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
12574760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
12584760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
12594760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
12604760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll [lacks WinVerifyTrust]
12614760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
12624760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
12634760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll
12644760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
12654760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume4\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
12664760.2884: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\opengl32.dll [lacks WinVerifyTrust]
12674760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
12684760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
12694760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll [lacks WinVerifyTrust]
12704760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
12714760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
12724760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
12734760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
12744760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
12754760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5guivbox.dll'.
12764760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qt5corevbox.dll'.
12774760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'shell32.dll'.
12784760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcp100.dll'.
12794760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcr100.dll'.
12804760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll) WinVerifyTrust
12814760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
12824760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
12834760.2884: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll [redoing WinVerifyTrust]
12844760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
12854760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
12864760.2884: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
12874760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
12884760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
12894760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll
12904760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
12914760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume4\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
12924760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\shell32.dll [lacks WinVerifyTrust]
12934760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
12944760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
12954760.2884: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [lacks WinVerifyTrust]
12964760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
12974760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
12984760.2884: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll [lacks WinVerifyTrust]
12994760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
13004760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
13014760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll [lacks WinVerifyTrust]
13024760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
13034760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
13044760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
13054760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
13064760.2884: supR3HardenedScreenImage/Imports: 0 (was 24202) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll'
13074760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
13084760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
13094760.2884: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [redoing WinVerifyTrust]
13104760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
13114760.2884: supR3HardenedScreenImage/Imports: 0 (was 24202) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll'
13124760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
13134760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
13144760.2884: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll [redoing WinVerifyTrust]
13154760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
13164760.2884: supR3HardenedScreenImage/Imports: 0 (was 24202) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll'
13174760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
13184760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
13194760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll
13204760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
13214760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
13224760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxglobal.dll'...
13234760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxglobal.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxglobal.dll' [rcNtRedir=0xc0150008]
13244760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
13254760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'vboxrt.dll'.
13264760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcr100.dll'.
13274760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5corevbox.dll'.
13284760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qt5guivbox.dll'.
13294760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qt5widgetsvbox.dll'.
13304760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
13314760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'advapi32.dll'.
13324760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'ole32.dll'.
13334760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'oleaut32.dll'.
13344760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxGlobal.dll) WinVerifyTrust
13354760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxGlobal.dll
13364760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
13374760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume4\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
13384760.2884: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\opengl32.dll [redoing WinVerifyTrust]
13394760.2884: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000490 pwszName=\Device\HarddiskVolume4\Windows\System32\opengl32.dll
13404760.2884: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000a97690
13414760.2884: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000a97690
13424760.2884: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F9EA7A084F8D34EE062D8C0EF5D96EF865883D56
13434760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
13444760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume4\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
13454760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\oleaut32.dll
13464760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
13474760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
13484760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ole32.dll
13494760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
13504760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
13514760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\advapi32.dll
13524760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
13534760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
13544760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll [lacks WinVerifyTrust]
13554760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
13564760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
13574760.2884: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll [lacks WinVerifyTrust]
13584760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
13594760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
13604760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
13614760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
13624760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
13634760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
13644760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
13654760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
13664760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
13674760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
13684760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
13694760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
13704760.2884: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0112~31bf3856ad364e35~amd64~~10.0.17763.1.cat'; file='\Device\HarddiskVolume4\Windows\System32\opengl32.dll'
13714760.2884: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
13724760.2884: supR3HardenedScreenImage/Imports: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\opengl32.dll'
13734760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000a01:<flags> [calling]
13744760.2884: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll
13754760.2884: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\opengl32.dll
13764760.2884: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxGlobal.dll
13774760.2884: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
13784760.2884: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
13794760.2884: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll [avoiding WinVerifyTrust]
13804760.2884: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll
13814760.2884: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmm.dll
13824760.2884: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\glu32.dll [avoiding WinVerifyTrust]
13834760.2884: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\mpr.dll [avoiding WinVerifyTrust]
13844760.2884: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmmbase.dll [avoiding WinVerifyTrust]
13854760.2884: supR3HardenedDllNotificationCallback: load 00007ffcb8350000 LB 0x00020000 C:\WINDOWS\System32\win32u.dll [fFlags=0x0]
13864760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\win32u.dll [avoiding WinVerifyTrust]
13874760.2884: supR3HardenedDllNotificationCallback: load 00007ffcb7b20000 LB 0x000a0000 C:\WINDOWS\System32\msvcp_win.dll [fFlags=0x0]
13884760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcp_win.dll [avoiding WinVerifyTrust]
13894760.2884: supR3HardenedDllNotificationCallback: load 00007ffcb7bc0000 LB 0x0019a000 C:\WINDOWS\System32\gdi32full.dll [fFlags=0x0]
13904760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
13914760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #33 'gdi32.dll'.
13924760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #35 'user32.dll'.
13934760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #36 'win32u.dll'.
13944760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\gdi32full.dll)
13954760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\gdi32full.dll
13964760.2884: supR3HardenedDllNotificationCallback: load 00007ffcb89f0000 LB 0x00029000 C:\WINDOWS\System32\GDI32.dll [fFlags=0x0]
13974760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gdi32.dll [avoiding WinVerifyTrust]
13984760.2884: supR3HardenedDllNotificationCallback: load 00007ffcb8d60000 LB 0x00197000 C:\WINDOWS\System32\USER32.dll [fFlags=0x0]
13994760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll [avoiding WinVerifyTrust]
14004760.2884: supR3HardenedDllNotificationCallback: load 00007ffc909b0000 LB 0x0002c000 C:\WINDOWS\SYSTEM32\GLU32.dll [fFlags=0x0]
14014760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\glu32.dll [avoiding WinVerifyTrust]
14024760.2884: supR3HardenedDllNotificationCallback: load 00007ffc8e940000 LB 0x00127000 C:\WINDOWS\SYSTEM32\OPENGL32.dll [fFlags=0x0]
14034760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\opengl32.dll
14044760.2884: supR3HardenedDllNotificationCallback: load 00007ffcb8060000 LB 0x0004a000 C:\WINDOWS\System32\cfgmgr32.dll [fFlags=0x0]
14054760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll)
14064760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll
14074760.2884: supR3HardenedDllNotificationCallback: load 00007ffcbae10000 LB 0x0032d000 C:\WINDOWS\System32\combase.dll [fFlags=0x0]
14084760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\combase.dll [avoiding WinVerifyTrust]
14094760.2884: supR3HardenedDllNotificationCallback: load 00007ffcb8cb0000 LB 0x000a8000 C:\WINDOWS\System32\shcore.dll [fFlags=0x0]
14104760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
14114760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #36 'rpcrt4.dll'.
14124760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #43 'combase.dll'.
14134760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\SHCore.dll)
14144760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\SHCore.dll
14154760.2884: supR3HardenedDllNotificationCallback: load 00007ffcb7170000 LB 0x0005d000 C:\WINDOWS\System32\powrprof.dll [fFlags=0x0]
14164760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'rpcrt4.dll'.
14174760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\powrprof.dll)
14184760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\powrprof.dll
14194760.2884: supR3HardenedDllNotificationCallback: load 00007ffcb8780000 LB 0x00052000 C:\WINDOWS\System32\shlwapi.dll [fFlags=0x0]
14204760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
14214760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #44 'gdi32.dll'.
14224760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #45 'user32.dll'.
14234760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\shlwapi.dll)
14244760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\shlwapi.dll
14254760.2884: supR3HardenedDllNotificationCallback: load 00007ffcb71f0000 LB 0x00011000 C:\WINDOWS\System32\kernel.appcore.dll [fFlags=0x0]
14264760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'msvcrt.dll'.
14274760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'rpcrt4.dll'.
14284760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\kernel.appcore.dll)
14294760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\kernel.appcore.dll
14304760.2884: supR3HardenedDllNotificationCallback: load 00007ffcb72c0000 LB 0x0074a000 C:\WINDOWS\System32\windows.storage.dll [fFlags=0x0]
14314760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #31 'combase.dll'.
14324760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #32 'msvcp_win.dll'.
14334760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #39 'rpcrt4.dll'.
14344760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #56 'profapi.dll'.
14354760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\windows.storage.dll)
14364760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\windows.storage.dll
14374760.2884: supR3HardenedDllNotificationCallback: load 00007ffcb9270000 LB 0x014ef000 C:\WINDOWS\System32\SHELL32.dll [fFlags=0x0]
14384760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\shell32.dll [avoiding WinVerifyTrust]
14394760.2884: supR3HardenedDllNotificationCallback: load 00007ffcb8f00000 LB 0x00155000 C:\WINDOWS\System32\ole32.dll [fFlags=0x0]
14404760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ole32.dll
14414760.2884: supR3HardenedDllNotificationCallback: load 00007ffca1390000 LB 0x0001a000 C:\WINDOWS\SYSTEM32\MPR.dll [fFlags=0x0]
14424760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\mpr.dll [avoiding WinVerifyTrust]
14434760.2884: supR3HardenedDllNotificationCallback: load 000000006c7d0000 LB 0x00565000 C:\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [fFlags=0x0]
14444760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
14454760.2884: supR3HardenedDllNotificationCallback: load 00007ffc573f0000 LB 0x005f7000 C:\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll [fFlags=0x0]
14464760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
14474760.2884: supR3HardenedDllNotificationCallback: load 000000006bf80000 LB 0x00561000 C:\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll [fFlags=0x0]
14484760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll [avoiding WinVerifyTrust]
14494760.2884: supR3HardenedDllNotificationCallback: load 00007ffcb8450000 LB 0x000cb000 C:\WINDOWS\System32\OLEAUT32.dll [fFlags=0x0]
14504760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\oleaut32.dll
14514760.2884: supR3HardenedDllNotificationCallback: load 00007ffc75f20000 LB 0x005b3000 C:\Program Files\Oracle\VirtualBox\VBoxGlobal.dll [fFlags=0x0]
14524760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxGlobal.dll
14534760.2884: supR3HardenedDllNotificationCallback: load 000000006c6d0000 LB 0x00054000 C:\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll [fFlags=0x0]
14544760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll
14554760.2884: supR3HardenedDllNotificationCallback: load 00007ffcb46c0000 LB 0x0002d000 C:\WINDOWS\SYSTEM32\WINMMBASE.dll [fFlags=0x0]
14564760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmmbase.dll [avoiding WinVerifyTrust]
14574760.2884: supR3HardenedDllNotificationCallback: load 00007ffcb46f0000 LB 0x00024000 C:\WINDOWS\SYSTEM32\WINMM.dll [fFlags=0x0]
14584760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmm.dll
14594760.2884: supR3HardenedDllNotificationCallback: load 00007ffc54e50000 LB 0x01f3c000 C:\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll [fFlags=0x0]
14604760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll
14614760.2884: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\windows.storage.dll'.
14624760.2884: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\windows.storage.dll' [rescheduled]
14634760.2884: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\kernel.appcore.dll'.
14644760.2884: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\kernel.appcore.dll' [rescheduled]
14654760.2884: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\shlwapi.dll'.
14664760.2884: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\shlwapi.dll' [rescheduled]
14674760.2884: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\powrprof.dll'.
14684760.2884: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\powrprof.dll' [rescheduled]
14694760.2884: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\SHCore.dll'.
14704760.2884: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\SHCore.dll' [rescheduled]
14714760.2884: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll'.
14724760.2884: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll' [rescheduled]
14734760.2884: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\gdi32full.dll'.
14744760.2884: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\gdi32full.dll' [rescheduled]
14754760.2884: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume4\Windows\System32\glu32.dll'.
14764760.2884: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\glu32.dll' [rescheduled]
14774760.2884: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\mpr.dll'.
14784760.2884: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\mpr.dll' [rescheduled]
14794760.2884: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\shell32.dll'.
14804760.2884: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\shell32.dll' [rescheduled]
14814760.2884: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll'.
14824760.2884: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll' [rescheduled]
14834760.2884: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\win32u.dll'.
14844760.2884: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\win32u.dll' [rescheduled]
14854760.2884: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\gdi32.dll'.
14864760.2884: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rescheduled]
14874760.2884: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\user32.dll'.
14884760.2884: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rescheduled]
14894760.2884: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\msvcp_win.dll'.
14904760.2884: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\msvcp_win.dll' [rescheduled]
14914760.2884: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\combase.dll'.
14924760.2884: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\combase.dll' [rescheduled]
14934760.2884: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\winmmbase.dll'.
14944760.2884: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\winmmbase.dll' [rescheduled]
14954760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\kernel32.dll
14964760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'profapi.dll'...
14974760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'profapi.dll' -> '\Device\HarddiskVolume4\Windows\System32\profapi.dll' [rcNtRedir=0xc0150008]
14984760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\profapi.dll
14994760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
15004760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
15014760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
15024760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
15034760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcp_win.dll [redoing WinVerifyTrust]
15044760.2884: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\msvcp_win.dll'.
15054760.2884: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume4\Windows\System32\msvcp_win.dll
15064760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
15074760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume4\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
15084760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\combase.dll [redoing WinVerifyTrust]
15094760.2884: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\combase.dll'.
15104760.2884: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume4\Windows\System32\combase.dll
15114760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
15124760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
15134760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
15144760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
15154760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
15164760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
15174760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll [redoing WinVerifyTrust]
15184760.2884: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\user32.dll'.
15194760.2884: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume4\Windows\System32\user32.dll
15204760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
15214760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
15224760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gdi32.dll [redoing WinVerifyTrust]
15234760.2884: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\gdi32.dll'.
15244760.2884: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume4\Windows\System32\gdi32.dll
15254760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
15264760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
15274760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
15284760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
15294760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
15304760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume4\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
15314760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\combase.dll [redoing WinVerifyTrust]
15324760.2884: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\combase.dll'.
15334760.2884: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume4\Windows\System32\combase.dll
15344760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
15354760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
15364760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
15374760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
15384760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
15394760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume4\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
15404760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\win32u.dll [redoing WinVerifyTrust]
15414760.2884: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\win32u.dll'.
15424760.2884: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume4\Windows\System32\win32u.dll
15434760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
15444760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
15454760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll [redoing WinVerifyTrust]
15464760.2884: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\user32.dll'.
15474760.2884: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume4\Windows\System32\user32.dll
15484760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
15494760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
15504760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gdi32.dll [redoing WinVerifyTrust]
15514760.2884: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\gdi32.dll'.
15524760.2884: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume4\Windows\System32\gdi32.dll
15534760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
15544760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
15554760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcp_win.dll [redoing WinVerifyTrust]
15564760.2884: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\msvcp_win.dll'.
15574760.2884: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume4\Windows\System32\msvcp_win.dll
15584760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\kernel32.dll (Input=kernel32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
15594760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcba7c0000 'C:\WINDOWS\System32\kernel32.dll'
15604760.2884: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-string-l1-1-0) -> 0x0, fPresent=1
15614760.2884: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-string-l1-1-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
15624760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb80b0000 'api-ms-win-core-string-l1-1-0'
15634760.2884: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-datetime-l1-1-1) -> 0x0, fPresent=1
15644760.2884: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-datetime-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
15654760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb80b0000 'api-ms-win-core-datetime-l1-1-1'
15664760.2884: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-obsolete-l1-2-0) -> 0x0, fPresent=1
15674760.2884: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-obsolete-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
15684760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb80b0000 'api-ms-win-core-localization-obsolete-l1-2-0'
15694760.2884: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\imm32.dll'.
15704760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'user32.dll'.
15714760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'win32u.dll'.
15724760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\imm32.dll)
15734760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\imm32.dll
15744760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
15754760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume4\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
15764760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\win32u.dll [redoing WinVerifyTrust]
15774760.2884: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\win32u.dll'.
15784760.2884: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume4\Windows\System32\win32u.dll
15794760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
15804760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
15814760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll [redoing WinVerifyTrust]
15824760.2884: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\user32.dll'.
15834760.2884: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume4\Windows\System32\user32.dll
15844760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\IMM32.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
15854760.2884: supR3HardenedDllNotificationCallback: load 00007ffcb8810000 LB 0x0002e000 C:\WINDOWS\System32\IMM32.DLL [fFlags=0x0]
15864760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\imm32.dll [avoiding WinVerifyTrust]
15874760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb8810000 'C:\WINDOWS\system32\IMM32.DLL'
15884760.2884: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\imm32.dll'.
15894760.2884: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\imm32.dll' [rescheduled]
15904760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\advapi32.dll
15914760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\ADVAPI32.DLL (Input=ADVAPI32.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
15924760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb8520000 'C:\WINDOWS\System32\ADVAPI32.DLL'
15934760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc54e50000 'C:\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll'
15944760.2884: SUPR3HardenedMain: Calling TrustedMain (00007ffc54e516c0)...
15954760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
15964760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
15974760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'ole32.dll'.
15984760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
15994760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'imm32.dll'.
16004760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'winmm.dll'.
16014760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
16024760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'shell32.dll'.
16034760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'advapi32.dll'.
16044760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'qt5guivbox.dll'.
16054760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'qt5corevbox.dll'.
16064760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'msvcr100.dll'.
16074760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\platforms\qwindows.dll) WinVerifyTrust
16084760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\platforms\qwindows.dll
16094760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
16104760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
16114760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
16124760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
16134760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
16144760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
16154760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
16164760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
16174760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
16184760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
16194760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\advapi32.dll
16204760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
16214760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume4\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
16224760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\shell32.dll [redoing WinVerifyTrust]
16234760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
16244760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
16254760.2884: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\shell32.dll'
16264760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
16274760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume4\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
16284760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\oleaut32.dll
16294760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
16304760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume4\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
16314760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmm.dll
16324760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
16334760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume4\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
16344760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\imm32.dll [redoing WinVerifyTrust]
16354760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
16364760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
16374760.2884: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\imm32.dll'
16384760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
16394760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
16404760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll [redoing WinVerifyTrust]
16414760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
16424760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
16434760.2884: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\user32.dll'
16444760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
16454760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
16464760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ole32.dll
16474760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
16484760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
16494760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gdi32.dll [redoing WinVerifyTrust]
16504760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
16514760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
16524760.2884: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\gdi32.dll'
16534760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\platforms\qwindows.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
16544760.2884: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\platforms\qwindows.dll
16554760.2884: supR3HardenedDllNotificationCallback: load 00007ffc7d310000 LB 0x0012e000 C:\Program Files\Oracle\VirtualBox\platforms\qwindows.dll [fFlags=0x0]
16564760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\platforms\qwindows.dll
16574760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc7d310000 'C:\Program Files\Oracle\VirtualBox\platforms\qwindows.dll'
16584760.2884: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000644 pwszName=\Device\HarddiskVolume4\Windows\System32\uxtheme.dll
16594760.2884: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000a97690
16604760.2884: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000a97690
16614760.2884: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=9E9C9DBAFB6FF286F236C72F471A61F524EAC54D
16624760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
16634760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
16644760.2884: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0315~31bf3856ad364e35~amd64~~10.0.17763.1.cat'; file='\Device\HarddiskVolume4\Windows\System32\uxtheme.dll'
16654760.2884: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
16664760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
16674760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #33 'gdi32.dll'.
16684760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #34 'user32.dll'.
16694760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\uxtheme.dll) WinVerifyTrust
16704760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\uxtheme.dll
16714760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
16724760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
16734760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
16744760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
16754760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
16764760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
16774760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
16784760.2884: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\uxtheme.dll
16794760.2884: supR3HardenedDllNotificationCallback: load 00007ffcb5390000 LB 0x0009c000 C:\WINDOWS\system32\uxtheme.dll [fFlags=0x0]
16804760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\uxtheme.dll
16814760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb5390000 'C:\WINDOWS\system32\uxtheme.dll'
16824760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb8d60000 'C:\WINDOWS\system32\user32.dll'
16834760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\shell32.dll
16844760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
16854760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb9270000 'C:\WINDOWS\system32\shell32.dll'
16864760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\SHCore.dll [redoing WinVerifyTrust]
16874760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
16884760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
16894760.2884: supR3HardenedScreenImage/LdrLoadDll: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\SHCore.dll'
16904760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\SHCore.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
16914760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb8cb0000 'C:\WINDOWS\system32\SHCore.dll'
16924760.2884: supR3HardenedMonitor_LdrLoadDll: error opening 'C:\WINDOWS\system32\wintab32.dll': 0 (NtPath=\??\C:\WINDOWS\system32\wintab32.dll; Input=C:\WINDOWS\system32\wintab32.dll; rcNtGetDll=0x0
16934760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000034 'C:\WINDOWS\system32\wintab32.dll'
16944760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll
16954760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\user32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
16964760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb8d60000 'C:\WINDOWS\system32\user32.dll'
16974760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
16984760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'crypt32.dll'.
16994760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'cryptsp.dll'.
17004760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'win32u.dll'.
17014760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 'user32.dll'.
17024760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #28 'gdi32.dll'.
17034760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\dwmapi.dll)
17044760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\dwmapi.dll
17054760.2884: supR3HardenedDllNotificationCallback: load 00007ffcb5670000 LB 0x0002e000 C:\WINDOWS\system32\dwmapi.dll [fFlags=0x0]
17064760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\dwmapi.dll [avoiding WinVerifyTrust]
17074760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
17084760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
17094760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
17104760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
17114760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
17124760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume4\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
17134760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\win32u.dll [lacks WinVerifyTrust]
17144760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cryptsp.dll'...
17154760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'cryptsp.dll' -> '\Device\HarddiskVolume4\Windows\System32\cryptsp.dll' [rcNtRedir=0xc0150008]
17164760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\cryptsp.dll
17174760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
17184760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume4\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
17194760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
17204760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
17214760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
17224760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
17234760.2884: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\dwmapi.dll'
17244760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmm.dll
17254760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\winmm.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
17264760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb46f0000 'C:\WINDOWS\system32\winmm.dll'
17274760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmm.dll
17284760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\winmm.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
17294760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb46f0000 'C:\WINDOWS\system32\winmm.dll'
17304760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\shell32.dll
17314760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
17324760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb9270000 'C:\WINDOWS\system32\shell32.dll'
17334760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\uxtheme.dll
17344760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
17354760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb5390000 'C:\WINDOWS\system32\uxtheme.dll'
17364760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\advapi32.dll
17374760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\advapi32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
17384760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb8520000 'C:\WINDOWS\system32\advapi32.dll'
17394760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
17404760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
17414760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'rpcrt4.dll'.
17424760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #29 'profapi.dll'.
17434760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\userenv.dll) WinVerifyTrust
17444760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\userenv.dll
17454760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'profapi.dll'...
17464760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'profapi.dll' -> '\Device\HarddiskVolume4\Windows\System32\profapi.dll' [rcNtRedir=0xc0150008]
17474760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\profapi.dll
17484760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
17494760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
17504760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\userenv.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
17514760.2884: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\userenv.dll
17524760.2884: supR3HardenedDllNotificationCallback: load 00007ffcb70a0000 LB 0x00028000 C:\WINDOWS\system32\userenv.dll [fFlags=0x0]
17534760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\userenv.dll
17544760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb70a0000 'C:\WINDOWS\system32\userenv.dll'
17554760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\kernel32.dll
17564760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\kernel32.dll (Input=kernel32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
17574760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcba7c0000 'C:\WINDOWS\System32\kernel32.dll'
17584760.2884: supR3HardenedDllNotificationCallback: load 00007ffcb83a0000 LB 0x000a2000 C:\WINDOWS\System32\clbcatq.dll [fFlags=0x0]
17594760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
17604760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #28 'rpcrt4.dll'.
17614760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\clbcatq.dll)
17624760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\clbcatq.dll
17634760.4a88: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
17644760.4a88: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
17654760.4a88: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll
17664760.4a88: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
17674760.4a88: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
17684760.4a88: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
17694760.4a88: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
17704760.4a88: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\clbcatq.dll'
17714760.4a88: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
17724760.4a88: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
17734760.4a88: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
17744760.4a88: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
17754760.4a88: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
17764760.4a88: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ole32.dll'.
17774760.4a88: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'oleaut32.dll'.
17784760.4a88: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxC.dll) WinVerifyTrust
17794760.4a88: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxC.dll
17804760.4a88: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
17814760.4a88: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume4\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
17824760.4a88: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\oleaut32.dll
17834760.4a88: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
17844760.4a88: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
17854760.4a88: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ole32.dll
17864760.4a88: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
17874760.4a88: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
17884760.4a88: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\advapi32.dll
17894760.4a88: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
17904760.4a88: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
17914760.4a88: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
17924760.4a88: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
17934760.4a88: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll
17944760.4a88: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
17954760.4a88: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
17964760.4a88: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxC.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
17974760.4a88: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxC.dll
17984760.4a88: supR3HardenedDllNotificationCallback: load 00007ffc57040000 LB 0x003a1000 C:\Program Files\Oracle\VirtualBox\VBoxC.dll [fFlags=0x0]
17994760.4a88: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxC.dll
18004760.4a88: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc57040000 'C:\Program Files\Oracle\VirtualBox\VBoxC.dll'
18014760.4a88: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
18024760.4a88: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
18034760.4a88: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
18044760.4a88: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
18054760.4a88: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'shlwapi.dll'.
18064760.4a88: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ole32.dll'.
18074760.4a88: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'oleaut32.dll'.
18084760.4a88: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
18094760.4a88: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll) WinVerifyTrust
18104760.4a88: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll
18114760.4a88: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
18124760.4a88: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
18134760.4a88: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
18144760.4a88: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume4\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
18154760.4a88: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\oleaut32.dll
18164760.4a88: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
18174760.4a88: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
18184760.4a88: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ole32.dll
18194760.4a88: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
18204760.4a88: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume4\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
18214760.4a88: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\shlwapi.dll [redoing WinVerifyTrust]
18224760.4a88: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
18234760.4a88: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
18244760.4a88: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\shlwapi.dll'
18254760.4a88: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
18264760.4a88: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
18274760.4a88: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\advapi32.dll
18284760.4a88: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
18294760.4a88: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
18304760.4a88: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
18314760.4a88: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
18324760.4a88: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
18334760.4a88: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll
18344760.4a88: supR3HardenedDllNotificationCallback: load 00007ffc7e3c0000 LB 0x000d4000 C:\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll [fFlags=0x0]
18354760.4a88: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll
18364760.4a88: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc7e3c0000 'C:\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll'
18374760.4a88: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\oleaut32.dll
18384760.4a88: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\oleaut32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
18394760.4a88: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb8450000 'C:\Windows\System32\oleaut32.dll'
18404760.2884: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000007a4 pwszName=\Device\HarddiskVolume4\Windows\System32\DWrite.dll
18414760.2884: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000a97690
18424760.2884: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000a97690
18434760.2884: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=ED58C840A4C96163B90C7F051FBCA4BFD3BE7921
18444760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
18454760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
18464760.2884: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_212_for_KB4483235~31bf3856ad364e35~amd64~~10.0.1.1.cat'; file='\Device\HarddiskVolume4\Windows\System32\DWrite.dll'
18474760.2884: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
18484760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
18494760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'rpcrt4.dll'.
18504760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\DWrite.dll) WinVerifyTrust
18514760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\DWrite.dll
18524760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
18534760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
18544760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
18554760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
18564760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll
18574760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\dwrite.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
18584760.2884: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\DWrite.dll
18594760.2884: supR3HardenedDllNotificationCallback: load 00007ffc92340000 LB 0x002ff000 C:\WINDOWS\system32\dwrite.dll [fFlags=0x0]
18604760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\DWrite.dll
18614760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc92340000 'C:\WINDOWS\system32\dwrite.dll'
18624760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\shell32.dll
18634760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
18644760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb9270000 'C:\WINDOWS\system32\shell32.dll'
18654760.2884: supR3HardenedDllNotificationCallback: load 00007ffcb8b40000 LB 0x0016a000 C:\WINDOWS\System32\MSCTF.dll [fFlags=0x0]
18664760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
18674760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'oleaut32.dll'.
18684760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #37 'user32.dll'.
18694760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #38 'gdi32.dll'.
18704760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #39 'imm32.dll'.
18714760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\msctf.dll)
18724760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\msctf.dll
18734760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
18744760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume4\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
18754760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\imm32.dll
18764760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
18774760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
18784760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
18794760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
18804760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
18814760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume4\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
18824760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\oleaut32.dll
18834760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
18844760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
18854760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
18864760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
18874760.2884: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\msctf.dll'
18884760.2884: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000009f4 pwszName=\Device\HarddiskVolume4\Windows\System32\DataExchange.dll
18894760.2884: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000a97690
18904760.2884: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000a97690
18914760.2884: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=59F3AE35C1BD7FF73B733C35DF45575279B981AF
18924760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
18934760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
18944760.2884: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0310~31bf3856ad364e35~amd64~~10.0.17763.1.cat'; file='\Device\HarddiskVolume4\Windows\System32\DataExchange.dll'
18954760.2884: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
18964760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
18974760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'shcore.dll'.
18984760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #28 'combase.dll'.
18994760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #33 'd3d11.dll'.
19004760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #34 'dcomp.dll'.
19014760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\DataExchange.dll) WinVerifyTrust
19024760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\DataExchange.dll
19034760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dcomp.dll'...
19044760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'dcomp.dll' -> '\Device\HarddiskVolume4\Windows\System32\dcomp.dll' [rcNtRedir=0xc0150008]
19054760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
19064760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
19074760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'win32u.dll'.
19084760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp_win.dll'.
19094760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #34 'oleaut32.dll'.
19104760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #35 'dxgi.dll'.
19114760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\dcomp.dll) WinVerifyTrust
19124760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\dcomp.dll
19134760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'd3d11.dll'...
19144760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'd3d11.dll' -> '\Device\HarddiskVolume4\Windows\System32\d3d11.dll' [rcNtRedir=0xc0150008]
19154760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dxgi.dll'...
19164760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'dxgi.dll' -> '\Device\HarddiskVolume4\Windows\System32\dxgi.dll' [rcNtRedir=0xc0150008]
19174760.2884: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\dxgi.dll'.
19184760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
19194760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'win32u.dll'.
19204760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\dxgi.dll)
19214760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\dxgi.dll
19224760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
19234760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume4\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
19244760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\oleaut32.dll
19254760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
19264760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
19274760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcp_win.dll [lacks WinVerifyTrust]
19284760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
19294760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume4\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
19304760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\win32u.dll [lacks WinVerifyTrust]
19314760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
19324760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume4\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
19334760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\win32u.dll [lacks WinVerifyTrust]
19344760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
19354760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
19364760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
19374760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
19384760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
19394760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'dxgi.dll'.
19404760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #35 'win32u.dll'.
19414760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\d3d11.dll) WinVerifyTrust
19424760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\d3d11.dll
19434760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
19444760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume4\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
19454760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\combase.dll [redoing WinVerifyTrust]
19464760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
19474760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume4\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
19484760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\win32u.dll [lacks WinVerifyTrust]
19494760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dxgi.dll'...
19504760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'dxgi.dll' -> '\Device\HarddiskVolume4\Windows\System32\dxgi.dll' [rcNtRedir=0xc0150008]
19514760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\dxgi.dll [lacks WinVerifyTrust]
19524760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
19534760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
19544760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
19554760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
19564760.2884: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\combase.dll'
19574760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shcore.dll'...
19584760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'shcore.dll' -> '\Device\HarddiskVolume4\Windows\System32\shcore.dll' [rcNtRedir=0xc0150008]
19594760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\SHCore.dll
19604760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
19614760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
19624760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\dataexchange.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
19634760.2884: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\DataExchange.dll
19644760.2884: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\d3d11.dll
19654760.2884: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\dcomp.dll
19664760.2884: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\dxgi.dll [avoiding WinVerifyTrust]
19674760.2884: supR3HardenedDllNotificationCallback: load 00007ffcb5f90000 LB 0x000c2000 C:\WINDOWS\system32\dxgi.dll [fFlags=0x0]
19684760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\dxgi.dll [avoiding WinVerifyTrust]
19694760.2884: supR3HardenedDllNotificationCallback: load 00007ffcb4210000 LB 0x0027e000 C:\WINDOWS\system32\d3d11.dll [fFlags=0x0]
19704760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\d3d11.dll
19714760.2884: supR3HardenedDllNotificationCallback: load 00007ffcb4b60000 LB 0x001c3000 C:\WINDOWS\system32\dcomp.dll [fFlags=0x0]
19724760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\dcomp.dll
19734760.2884: supR3HardenedDllNotificationCallback: load 00007ffc8e1e0000 LB 0x00056000 C:\WINDOWS\system32\dataexchange.dll [fFlags=0x0]
19744760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\DataExchange.dll
19754760.2884: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\dxgi.dll'.
19764760.2884: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\dxgi.dll' [rescheduled]
19774760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb89f0000 'C:\WINDOWS\System32\gdi32.dll'
19784760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc8e1e0000 'C:\WINDOWS\system32\dataexchange.dll'
19794760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rmclient.dll'.
19804760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #33 'rpcrt4.dll'.
19814760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #47 'combase.dll'.
19824760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #49 'msvcp_win.dll'.
19834760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\twinapi.appcore.dll)
19844760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\twinapi.appcore.dll
19854760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
19864760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'rpcrt4.dll'.
19874760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\rmclient.dll)
19884760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\rmclient.dll
19894760.2884: supR3HardenedDllNotificationCallback: load 00007ffcb56a0000 LB 0x00028000 C:\WINDOWS\system32\RMCLIENT.dll [fFlags=0x0]
19904760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rmclient.dll [avoiding WinVerifyTrust]
19914760.2884: supR3HardenedDllNotificationCallback: load 00007ffcb5450000 LB 0x0020d000 C:\WINDOWS\system32\twinapi.appcore.dll [fFlags=0x0]
19924760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\twinapi.appcore.dll [avoiding WinVerifyTrust]
19934760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll
19944760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
19954760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
19964760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
19974760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
19984760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
19994760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
20004760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcp_win.dll [lacks WinVerifyTrust]
20014760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
20024760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume4\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
20034760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\combase.dll
20044760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
20054760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
20064760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rmclient.dll'...
20074760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'rmclient.dll' -> '\Device\HarddiskVolume4\Windows\System32\rmclient.dll' [rcNtRedir=0xc0150008]
20084760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rmclient.dll [lacks WinVerifyTrust]
20094760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
20104760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
20114760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
20124760.2884: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\rmclient.dll'
20134760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
20144760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
20154760.2884: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\twinapi.appcore.dll'
20164760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\SHCore.dll
20174760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\Shcore.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
20184760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb8cb0000 'C:\WINDOWS\system32\Shcore.dll'
20194760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
20204760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #15 'rpcrt4.dll'.
20214760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #19 'coreuicomponents.dll'.
20224760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #20 'coremessaging.dll'.
20234760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\TextInputFramework.dll)
20244760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\TextInputFramework.dll
20254760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
20264760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #35 'coremessaging.dll'.
20274760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #48 'shcore.dll'.
20284760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\CoreUIComponents.dll)
20294760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\CoreUIComponents.dll
20304760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
20314760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #24 'rpcrt4.dll'.
20324760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\CoreMessaging.dll)
20334760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\CoreMessaging.dll
20344760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\ntmarta.dll)
20354760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\ntmarta.dll
20364760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'combase.dll'.
20374760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'rpcrt4.dll'.
20384760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #30 'bcryptprimitives.dll'.
20394760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\WinTypes.dll)
20404760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\WinTypes.dll
20414760.2884: supR3HardenedDllNotificationCallback: load 00007ffcb6230000 LB 0x00031000 C:\WINDOWS\SYSTEM32\ntmarta.dll [fFlags=0x0]
20424760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ntmarta.dll [avoiding WinVerifyTrust]
20434760.2884: supR3HardenedDllNotificationCallback: load 00007ffcb4e30000 LB 0x000e2000 C:\WINDOWS\System32\CoreMessaging.dll [fFlags=0x0]
20444760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\CoreMessaging.dll [avoiding WinVerifyTrust]
20454760.2884: supR3HardenedDllNotificationCallback: load 00007ffcb1d90000 LB 0x00153000 C:\WINDOWS\SYSTEM32\wintypes.dll [fFlags=0x0]
20464760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\WinTypes.dll [avoiding WinVerifyTrust]
20474760.2884: supR3HardenedDllNotificationCallback: load 00007ffcb1990000 LB 0x00322000 C:\WINDOWS\System32\CoreUIComponents.dll [fFlags=0x0]
20484760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\CoreUIComponents.dll [avoiding WinVerifyTrust]
20494760.2884: supR3HardenedDllNotificationCallback: load 00007ffc9a070000 LB 0x00095000 C:\WINDOWS\System32\TextInputFramework.dll [fFlags=0x0]
20504760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\TextInputFramework.dll [avoiding WinVerifyTrust]
20514760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcryptprimitives.dll'...
20524760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcryptprimitives.dll' -> '\Device\HarddiskVolume4\Windows\System32\bcryptprimitives.dll' [rcNtRedir=0xc0150008]
20534760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\bcryptprimitives.dll
20544760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
20554760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
20564760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
20574760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume4\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
20584760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\combase.dll
20594760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
20604760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
20614760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
20624760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
20634760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shcore.dll'...
20644760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'shcore.dll' -> '\Device\HarddiskVolume4\Windows\System32\shcore.dll' [rcNtRedir=0xc0150008]
20654760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\SHCore.dll
20664760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'coremessaging.dll'...
20674760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'coremessaging.dll' -> '\Device\HarddiskVolume4\Windows\System32\coremessaging.dll' [rcNtRedir=0xc0150008]
20684760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\CoreMessaging.dll [lacks WinVerifyTrust]
20694760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
20704760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
20714760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'coremessaging.dll'...
20724760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'coremessaging.dll' -> '\Device\HarddiskVolume4\Windows\System32\coremessaging.dll' [rcNtRedir=0xc0150008]
20734760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\CoreMessaging.dll [lacks WinVerifyTrust]
20744760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'coreuicomponents.dll'...
20754760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'coreuicomponents.dll' -> '\Device\HarddiskVolume4\Windows\System32\coreuicomponents.dll' [rcNtRedir=0xc0150008]
20764760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\CoreUIComponents.dll [lacks WinVerifyTrust]
20774760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
20784760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
20794760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
20804760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
20814760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
20824760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
20834760.2884: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\WinTypes.dll'
20844760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
20854760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
20864760.2884: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\ntmarta.dll'
20874760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
20884760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
20894760.2884: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\CoreMessaging.dll'
20904760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
20914760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
20924760.2884: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\CoreUIComponents.dll'
20934760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
20944760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
20954760.2884: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\TextInputFramework.dll'
20964760.2884: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(ext-ms-win-rtcore-ntuser-window-ext-l1-1-0.dll) -> 0x0, fPresent=1
20974760.2884: supR3HardenedMonitor_LdrLoadDll: pName=ext-ms-win-rtcore-ntuser-window-ext-l1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
20984760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb8d60000 'ext-ms-win-rtcore-ntuser-window-ext-l1-1-0.dll'
20994760.2884: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(ext-ms-win-rtcore-ntuser-integration-l1-1-0.dll) -> 0x0, fPresent=1
21004760.2884: supR3HardenedMonitor_LdrLoadDll: pName=ext-ms-win-rtcore-ntuser-integration-l1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
21014760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb8d60000 'ext-ms-win-rtcore-ntuser-integration-l1-1-0.dll'
21024760.2884: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-com-l1-1-0.dll) -> 0x0, fPresent=1
21034760.2884: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-com-l1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
21044760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcbae10000 'api-ms-win-core-com-l1-1-0.dll'
21054760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msctf.dll
21064760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\MSCTF.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
21074760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb8b40000 'C:\WINDOWS\System32\MSCTF.dll'
21084760.2884: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000b1c pwszName=\Device\HarddiskVolume4\Windows\System32\oleacc.dll
21094760.2884: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000a97690
21104760.2884: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000a97690
21114760.2884: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=92D0420A49287CA5BE482F6435FEDE1197E38D4E
21124760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
21134760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
21144760.2884: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package03113~31bf3856ad364e35~amd64~~10.0.17763.1.cat'; file='\Device\HarddiskVolume4\Windows\System32\oleacc.dll'
21154760.2884: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
21164760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'rpcrt4.dll'.
21174760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #30 'user32.dll'.
21184760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\oleacc.dll) WinVerifyTrust
21194760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\oleacc.dll
21204760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
21214760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
21224760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
21234760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
21244760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\Oleacc.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
21254760.2884: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\oleacc.dll
21264760.2884: supR3HardenedDllNotificationCallback: load 00007ffcaa8a0000 LB 0x0006c000 C:\WINDOWS\system32\Oleacc.dll [fFlags=0x0]
21274760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\oleacc.dll
21284760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcaa8a0000 'C:\WINDOWS\system32\Oleacc.dll'
21294760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb8450000 'C:\WINDOWS\System32\OLEAUT32.DLL'
21304760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\oleacc.dll
21314760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\oleacc.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
21324760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcaa8a0000 'C:\WINDOWS\system32\oleacc.dll'
21334760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\oleacc.dll
21344760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\oleacc.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
21354760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcaa8a0000 'C:\Windows\System32\oleacc.dll'
21364760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ole32.dll
21374760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\ole32.dll (Input=ole32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
21384760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb8f00000 'C:\WINDOWS\System32\ole32.dll'
21394760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb8450000 'C:\WINDOWS\System32\OLEAUT32.dll'
21404760.2884: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000b60 pwszName=\Device\HarddiskVolume4\Windows\System32\wbem\wbemprox.dll
21414760.2884: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000a97690
21424760.2884: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000a97690
21434760.2884: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=61B08AF50BF6163BDE34EB0C9B6605297BA2441A
21444760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
21454760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
21464760.2884: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package02~31bf3856ad364e35~amd64~~10.0.17763.1.cat'; file='\Device\HarddiskVolume4\Windows\System32\wbem\wbemprox.dll'
21474760.2884: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
21484760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
21494760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ws2_32.dll'.
21504760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'wbemcomn.dll'.
21514760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\wbem\wbemprox.dll) WinVerifyTrust
21524760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\wbem\wbemprox.dll
21534760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wbemcomn.dll'...
21544760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'wbemcomn.dll' -> '\Device\HarddiskVolume4\Windows\System32\wbemcomn.dll' [rcNtRedir=0xc0150008]
21554760.2884: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000af4 pwszName=\Device\HarddiskVolume4\Windows\System32\wbemcomn.dll
21564760.2884: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000a97690
21574760.2884: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000a97690
21584760.2884: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=585E55607969886FF9DCECA6C86E3FD6D59F65D2
21594760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
21604760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
21614760.2884: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package02~31bf3856ad364e35~amd64~~10.0.17763.1.cat'; file='\Device\HarddiskVolume4\Windows\System32\wbemcomn.dll'
21624760.2884: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
21634760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
21644760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'bcrypt.dll'.
21654760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'ws2_32.dll'.
21664760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\wbemcomn.dll) WinVerifyTrust
21674760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\wbemcomn.dll
21684760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
21694760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
21704760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ws2_32.dll
21714760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
21724760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
21734760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
21744760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
21754760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ws2_32.dll
21764760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
21774760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume4\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
21784760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\bcrypt.dll
21794760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
21804760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
21814760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\wbem\wbemprox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
21824760.2884: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wbem\wbemprox.dll
21834760.2884: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wbemcomn.dll
21844760.2884: supR3HardenedDllNotificationCallback: load 00007ffca25d0000 LB 0x00085000 C:\WINDOWS\SYSTEM32\wbemcomn.dll [fFlags=0x0]
21854760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wbemcomn.dll
21864760.2884: supR3HardenedDllNotificationCallback: load 00007ffc9ee90000 LB 0x00011000 C:\WINDOWS\system32\wbem\wbemprox.dll [fFlags=0x0]
21874760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wbem\wbemprox.dll
21884760.2884: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(API-MS-Win-Core-LocalRegistry-L1-1-0.dll) -> 0x0, fPresent=1
21894760.2884: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Core-LocalRegistry-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
21904760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb80b0000 'API-MS-Win-Core-LocalRegistry-L1-1-0.dll'
21914760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc9ee90000 'C:\WINDOWS\system32\wbem\wbemprox.dll'
21924760.2884: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000bb4 pwszName=\Device\HarddiskVolume4\Windows\System32\wbem\wbemsvc.dll
21934760.2884: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000a97690
21944760.2884: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000a97690
21954760.2884: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2479751D59078C3499423233D67A94D93457E663
21964760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
21974760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
21984760.2884: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package02~31bf3856ad364e35~amd64~~10.0.17763.1.cat'; file='\Device\HarddiskVolume4\Windows\System32\wbem\wbemsvc.dll'
21994760.2884: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
22004760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
22014760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'rpcrt4.dll'.
22024760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\wbem\wbemsvc.dll) WinVerifyTrust
22034760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\wbem\wbemsvc.dll
22044760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
22054760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
22064760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
22074760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
22084760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\wbem\wbemsvc.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
22094760.2884: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wbem\wbemsvc.dll
22104760.2884: supR3HardenedDllNotificationCallback: load 00007ffc9e170000 LB 0x00014000 C:\WINDOWS\system32\wbem\wbemsvc.dll [fFlags=0x0]
22114760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wbem\wbemsvc.dll
22124760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc9e170000 'C:\WINDOWS\system32\wbem\wbemsvc.dll'
22134760.2884: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-l1-2-0.dll) -> 0x0, fPresent=1
22144760.2884: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-l1-2-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
22154760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb80b0000 'api-ms-win-core-localization-l1-2-0.dll'
22164760.2884: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-obsolete-l1-1-0.dll) -> 0x0, fPresent=1
22174760.2884: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-obsolete-l1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
22184760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb80b0000 'api-ms-win-core-localization-obsolete-l1-1-0.dll'
22194760.2884: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000b78 pwszName=\Device\HarddiskVolume4\Windows\System32\wbem\fastprox.dll
22204760.2884: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000a97690
22214760.2884: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000a97690
22224760.2884: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=5D738E4890595C8890290239456518F354997BFD
22234760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
22244760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll
22254760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
22264760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
22274760.2884: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package02~31bf3856ad364e35~amd64~~10.0.17763.1.cat'; file='\Device\HarddiskVolume4\Windows\System32\wbem\fastprox.dll'
22284760.2884: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
22294760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
22304760.2884: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #19 'wbemcomn.dll'.
22314760.2884: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\wbem\fastprox.dll) WinVerifyTrust
22324760.2884: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\wbem\fastprox.dll
22334760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wbemcomn.dll'...
22344760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'wbemcomn.dll' -> '\Device\HarddiskVolume4\Windows\System32\wbemcomn.dll' [rcNtRedir=0xc0150008]
22354760.2884: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wbemcomn.dll
22364760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
22374760.2884: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
22384760.2884: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\wbem\fastprox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
22394760.2884: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wbem\fastprox.dll
22404760.2884: supR3HardenedDllNotificationCallback: load 00007ffc9e2d0000 LB 0x000f1000 C:\WINDOWS\system32\wbem\fastprox.dll [fFlags=0x0]
22414760.2884: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wbem\fastprox.dll
22424760.2884: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc9e2d0000 'C:\WINDOWS\system32\wbem\fastprox.dll'
22434760.4fc4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
22444760.4fc4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
22454760.4fc4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrem.dll'.
22464760.4fc4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
22474760.4fc4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxVMM.dll) WinVerifyTrust
22484760.4fc4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxVMM.dll
22494760.4fc4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
22504760.4fc4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
22514760.4fc4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrem.dll'...
22524760.4fc4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrem.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrem.dll' [rcNtRedir=0xc0150008]
22534760.4fc4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
22544760.4fc4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'vboxrt.dll'.
22554760.4fc4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
22564760.4fc4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcrt.dll'.
22574760.4fc4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxREM.dll) WinVerifyTrust
22584760.4fc4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxREM.dll
22594760.4fc4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
22604760.4fc4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
22614760.4fc4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
22624760.4fc4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
22634760.4fc4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
22644760.4fc4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
22654760.4fc4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxVMM.dll
22664760.4fc4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
22674760.4fc4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
22684760.4fc4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
22694760.4fc4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxVMM.dll
22704760.4fc4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxREM.dll
22714760.4fc4: supR3HardenedDllNotificationCallback: load 000000006be70000 LB 0x0010b000 C:\Program Files\Oracle\VirtualBox\VBoxREM.dll [fFlags=0x0]
22724760.4fc4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxREM.dll
22734760.4fc4: supR3HardenedDllNotificationCallback: load 00007ffc532e0000 LB 0x00330000 C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL [fFlags=0x0]
22744760.4fc4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxVMM.dll
22754760.4fc4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc532e0000 'C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL'
22764760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
22774760.57cc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
22784760.57cc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
22794760.57cc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
22804760.57cc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
22814760.57cc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
22824760.57cc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll) WinVerifyTrust
22834760.57cc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll
22844760.57cc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
22854760.57cc: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
22864760.57cc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
22874760.57cc: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
22884760.57cc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
22894760.57cc: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
22904760.57cc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxVMM.dll
22914760.57cc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
22924760.57cc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
22934760.57cc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
22944760.57cc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll
22954760.57cc: supR3HardenedDllNotificationCallback: load 00007ffcb0570000 LB 0x0000b000 C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL [fFlags=0x0]
22964760.57cc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll
22974760.57cc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb0570000 'C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL'
22984760.57cc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb8d60000 'C:\WINDOWS\system32\User32.dll'
22994760.5e54: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
23004760.5e54: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
23014760.5e54: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
23024760.5e54: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
23034760.5e54: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll) WinVerifyTrust
23044760.5e54: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll
23054760.5e54: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
23064760.5e54: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
23074760.5e54: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
23084760.5e54: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
23094760.5e54: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
23104760.5e54: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
23114760.5e54: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
23124760.5e54: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll
23134760.5e54: supR3HardenedDllNotificationCallback: load 00007ffcb0560000 LB 0x0000d000 C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL [fFlags=0x0]
23144760.5e54: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll
23154760.5e54: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb0560000 'C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL'
23164760.5bf4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\shell32.dll
23174760.5bf4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\Shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
23184760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb9270000 'C:\WINDOWS\system32\Shell32.dll'
23194760.5bf4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000c40 pwszName=\Device\HarddiskVolume4\Windows\System32\WinHvPlatform.dll
23204760.5bf4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000a97690
23214760.5bf4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000a97690
23224760.5bf4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=9143E96BE13DAE364B45A7FAC5B6C12AFE680873
23234760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
23244760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
23254760.5bf4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package01~31bf3856ad364e35~amd64~~10.0.17763.1.cat'; file='\Device\HarddiskVolume4\Windows\System32\WinHvPlatform.dll'
23264760.5bf4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
23274760.5bf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'vid.dll'.
23284760.5bf4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\WinHvPlatform.dll) WinVerifyTrust
23294760.5bf4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\WinHvPlatform.dll
23304760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vid.dll'...
23314760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vid.dll' -> '\Device\HarddiskVolume4\Windows\System32\vid.dll' [rcNtRedir=0xc0150008]
23324760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
23334760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
23344760.5bf4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\vid.dll) WinVerifyTrust
23354760.5bf4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\vid.dll
23364760.5bf4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\WinHvPlatform.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
23374760.5bf4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\WinHvPlatform.dll
23384760.5bf4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\vid.dll
23394760.5bf4: supR3HardenedDllNotificationCallback: load 00007ffca1bd0000 LB 0x00017000 C:\WINDOWS\SYSTEM32\vid.dll [fFlags=0x0]
23404760.5bf4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\vid.dll
23414760.5bf4: supR3HardenedDllNotificationCallback: load 00007ffca0d30000 LB 0x0001f000 C:\WINDOWS\system32\WinHvPlatform.dll [fFlags=0x0]
23424760.5bf4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\WinHvPlatform.dll
23434760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffca0d30000 'C:\WINDOWS\system32\WinHvPlatform.dll'
23444760.5bf4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\vid.dll
23454760.5bf4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\vid.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
23464760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffca1bd0000 'C:\WINDOWS\system32\vid.dll'
23474760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
23484760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
23494760.5bf4: '\Device\HarddiskVolume4\Windows\System32\ntdll.dll' has no imports
23504760.5bf4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\ntdll.dll) WinVerifyTrust
23514760.5bf4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\ntdll.dll
23524760.5bf4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\NTDLL.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
23534760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcbb170000 'C:\WINDOWS\system32\NTDLL.DLL'
23544760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
23554760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
23564760.5bf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
23574760.5bf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
23584760.5bf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
23594760.5bf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vboxddu.dll'.
23604760.5bf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'vboxdd2.dll'.
23614760.5bf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
23624760.5bf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'setupapi.dll'.
23634760.5bf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'ws2_32.dll'.
23644760.5bf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'ole32.dll'.
23654760.5bf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'iphlpapi.dll'.
23664760.5bf4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDD.dll) WinVerifyTrust
23674760.5bf4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDD.dll
23684760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'iphlpapi.dll'...
23694760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'iphlpapi.dll' -> '\Device\HarddiskVolume4\Windows\System32\iphlpapi.dll' [rcNtRedir=0xc0150008]
23704760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
23714760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
23724760.5bf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #21 'rpcrt4.dll'.
23734760.5bf4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\IPHLPAPI.DLL) WinVerifyTrust
23744760.5bf4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\IPHLPAPI.DLL
23754760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
23764760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
23774760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
23784760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
23794760.5bf4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ws2_32.dll
23804760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
23814760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume4\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
23824760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
23834760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
23844760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
23854760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
23864760.5bf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
23874760.5bf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #29 'rpcrt4.dll'.
23884760.5bf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #37 'cfgmgr32.dll'.
23894760.5bf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #41 'bcrypt.dll'.
23904760.5bf4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\setupapi.dll) WinVerifyTrust
23914760.5bf4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\setupapi.dll
23924760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
23934760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
23944760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxdd2.dll'...
23954760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxdd2.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxdd2.dll' [rcNtRedir=0xc0150008]
23964760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
23974760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume4\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
23984760.5bf4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\bcrypt.dll
23994760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
24004760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
24014760.5bf4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll [lacks WinVerifyTrust]
24024760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
24034760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
24044760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
24054760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
24064760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
24074760.5bf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
24084760.5bf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
24094760.5bf4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDD2.dll) WinVerifyTrust
24104760.5bf4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDD2.dll
24114760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxddu.dll'...
24124760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxddu.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxddu.dll' [rcNtRedir=0xc0150008]
24134760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
24144760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
24154760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
24164760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
24174760.5bf4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll
24184760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
24194760.5bf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
24204760.5bf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
24214760.5bf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
24224760.5bf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'setupapi.dll'.
24234760.5bf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'advapi32.dll'.
24244760.5bf4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDDU.dll) WinVerifyTrust
24254760.5bf4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDDU.dll
24264760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
24274760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
24284760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
24294760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
24304760.5bf4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxVMM.dll
24314760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
24324760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
24334760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
24344760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
24354760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
24364760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume4\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
24374760.5bf4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\setupapi.dll
24384760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
24394760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
24404760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
24414760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
24424760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
24434760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
24444760.5bf4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxDD.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
24454760.5bf4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDD.dll
24464760.5bf4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDDU.dll
24474760.5bf4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDD2.dll
24484760.5bf4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\IPHLPAPI.DLL
24494760.5bf4: supR3HardenedDllNotificationCallback: load 00007ffcba890000 LB 0x00475000 C:\WINDOWS\System32\SETUPAPI.dll [fFlags=0x0]
24504760.5bf4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\setupapi.dll
24514760.5bf4: supR3HardenedDllNotificationCallback: load 00007ffc7f3b0000 LB 0x00063000 C:\Program Files\Oracle\VirtualBox\VBoxDDU.dll [fFlags=0x0]
24524760.5bf4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDDU.dll
24534760.5bf4: supR3HardenedDllNotificationCallback: load 00007ffc9aa50000 LB 0x0005c000 C:\Program Files\Oracle\VirtualBox\VBoxDD2.dll [fFlags=0x0]
24544760.5bf4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDD2.dll
24554760.5bf4: supR3HardenedDllNotificationCallback: load 00007ffcb66c0000 LB 0x0003d000 C:\WINDOWS\SYSTEM32\IPHLPAPI.DLL [fFlags=0x0]
24564760.5bf4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\IPHLPAPI.DLL
24574760.5bf4: supR3HardenedDllNotificationCallback: load 00007ffc52900000 LB 0x009d7000 C:\Program Files\Oracle\VirtualBox\VBoxDD.DLL [fFlags=0x0]
24584760.5bf4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDD.dll
24594760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc52900000 'C:\Program Files\Oracle\VirtualBox\VBoxDD.DLL'
24604760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
24614760.5bf4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxC.dll
24624760.5bf4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxC.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
24634760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc57040000 'C:\Program Files\Oracle\VirtualBox\VBoxC.DLL'
24644760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
24654760.5bf4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDD2.dll
24664760.5bf4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxDD2.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
24674760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc9aa50000 'C:\Program Files\Oracle\VirtualBox\VBoxDD2.DLL'
24684760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
24694760.4c80: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
24704760.4c80: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
24714760.4c80: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
24724760.4c80: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
24734760.4c80: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll) WinVerifyTrust
24744760.4c80: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll
24754760.4c80: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
24764760.4c80: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
24774760.4c80: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
24784760.4c80: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
24794760.4c80: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxVMM.dll
24804760.4c80: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
24814760.4c80: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
24824760.4c80: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
24834760.4c80: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll
24844760.4c80: supR3HardenedDllNotificationCallback: load 00007ffca0cb0000 LB 0x00012000 C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL [fFlags=0x0]
24854760.4c80: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll
24864760.4c80: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffca0cb0000 'C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL'
24874760.5704: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
24884760.5704: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
24894760.5704: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
24904760.5704: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxvmm.dll'.
24914760.5704: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vboxrt.dll'.
24924760.5704: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll) WinVerifyTrust
24934760.5704: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll
24944760.5704: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
24954760.5704: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
24964760.5704: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
24974760.5704: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
24984760.5704: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxVMM.dll
24994760.5704: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
25004760.5704: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
25014760.5704: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
25024760.5704: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
25034760.5704: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
25044760.5704: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll
25054760.5704: supR3HardenedDllNotificationCallback: load 00007ffcaac20000 LB 0x0000c000 C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL [fFlags=0x0]
25064760.5704: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll
25074760.5704: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcaac20000 'C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL'
25084760.498c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
25094760.498c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
25104760.498c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
25114760.498c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
25124760.498c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll) WinVerifyTrust
25134760.498c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll
25144760.498c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
25154760.498c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
25164760.498c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
25174760.498c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
25184760.498c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
25194760.498c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
25204760.498c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
25214760.498c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll
25224760.498c: supR3HardenedDllNotificationCallback: load 00007ffcaab80000 LB 0x0000d000 C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL [fFlags=0x0]
25234760.498c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll
25244760.498c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcaab80000 'C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL'
25254760.5bf4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\IPHLPAPI.DLL
25264760.5bf4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\Iphlpapi.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
25274760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb66c0000 'C:\WINDOWS\system32\Iphlpapi.dll'
25284760.5bf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rpcrt4.dll'.
25294760.5bf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'nsi.dll'.
25304760.5bf4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\winnsi.dll)
25314760.5bf4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\winnsi.dll
25324760.5bf4: supR3HardenedDllNotificationCallback: load 00007ffcba880000 LB 0x00008000 C:\WINDOWS\System32\NSI.dll [fFlags=0x0]
25334760.5bf4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\nsi.dll)
25344760.5bf4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\nsi.dll
25354760.5bf4: supR3HardenedDllNotificationCallback: load 00007ffcb0820000 LB 0x0000b000 C:\WINDOWS\SYSTEM32\WINNSI.DLL [fFlags=0x0]
25364760.5bf4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winnsi.dll [avoiding WinVerifyTrust]
25374760.5bf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rpcrt4.dll'.
25384760.5bf4: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\System32\dhcpcsvc6.dll)
25394760.5bf4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\dhcpcsvc6.dll
25404760.5bf4: supR3HardenedDllNotificationCallback: load 00007ffcaf8a0000 LB 0x00016000 C:\WINDOWS\SYSTEM32\dhcpcsvc6.DLL [fFlags=0x0]
25414760.5bf4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\dhcpcsvc6.dll [avoiding WinVerifyTrust]
25424760.5bf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rpcrt4.dll'.
25434760.5bf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ws2_32.dll'.
25444760.5bf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'nsi.dll'.
25454760.5bf4: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\System32\dhcpcsvc.dll)
25464760.5bf4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\dhcpcsvc.dll
25474760.5bf4: supR3HardenedDllNotificationCallback: load 00007ffcaf810000 LB 0x0001c000 C:\WINDOWS\SYSTEM32\dhcpcsvc.DLL [fFlags=0x0]
25484760.5bf4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\dhcpcsvc.dll [avoiding WinVerifyTrust]
25494760.5bf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #21 'ws2_32.dll'.
25504760.5bf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'nsi.dll'.
25514760.5bf4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\dnsapi.dll)
25524760.5bf4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\dnsapi.dll
25534760.5bf4: supR3HardenedDllNotificationCallback: load 00007ffcb6700000 LB 0x000c6000 C:\WINDOWS\SYSTEM32\DNSAPI.dll [fFlags=0x0]
25544760.5bf4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\dnsapi.dll [avoiding WinVerifyTrust]
25554760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
25564760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume4\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
25574760.5bf4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\nsi.dll [lacks WinVerifyTrust]
25584760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
25594760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
25604760.5bf4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ws2_32.dll
25614760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
25624760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume4\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
25634760.5bf4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\nsi.dll [lacks WinVerifyTrust]
25644760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
25654760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
25664760.5bf4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ws2_32.dll
25674760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
25684760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
25694760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
25704760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
25714760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
25724760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume4\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
25734760.5bf4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\nsi.dll [lacks WinVerifyTrust]
25744760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
25754760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
25764760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
25774760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
25784760.5bf4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\dnsapi.dll'
25794760.5bf4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000e00 pwszName=\Device\HarddiskVolume4\Windows\System32\dhcpcsvc.dll
25804760.5bf4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000a97690
25814760.5bf4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000a97690
25824760.5bf4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=023C8DA2B39F9AA3A5B23F6B14BA6DD8E8288590
25834760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
25844760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
25854760.5bf4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0316~31bf3856ad364e35~amd64~~10.0.17763.1.cat'; file='\Device\HarddiskVolume4\Windows\System32\dhcpcsvc.dll'
25864760.5bf4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
25874760.5bf4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\dhcpcsvc.dll'
25884760.5bf4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000f18 pwszName=\Device\HarddiskVolume4\Windows\System32\dhcpcsvc6.dll
25894760.5bf4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000a97690
25904760.5bf4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000a97690
25914760.5bf4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=E0A1EEF9F9131F768A30314D53D98D8EC54A521D
25924760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
25934760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
25944760.5bf4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0316~31bf3856ad364e35~amd64~~10.0.17763.1.cat'; file='\Device\HarddiskVolume4\Windows\System32\dhcpcsvc6.dll'
25954760.5bf4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
25964760.5bf4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\dhcpcsvc6.dll'
25974760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
25984760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
25994760.5bf4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\nsi.dll'
26004760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
26014760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
26024760.5bf4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\winnsi.dll'
26034760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
26044760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
26054760.5bf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'rpcrt4.dll'.
26064760.5bf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'devobj.dll'.
26074760.5bf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #37 'propsys.dll'.
26084760.5bf4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\MMDevAPI.dll) WinVerifyTrust
26094760.5bf4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\MMDevAPI.dll
26104760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'propsys.dll'...
26114760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'propsys.dll' -> '\Device\HarddiskVolume4\Windows\System32\propsys.dll' [rcNtRedir=0xc0150008]
26124760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
26134760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
26144760.5bf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
26154760.5bf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #15 'oleaut32.dll'.
26164760.5bf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #31 'rpcrt4.dll'.
26174760.5bf4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\propsys.dll) WinVerifyTrust
26184760.5bf4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\propsys.dll
26194760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'devobj.dll'...
26204760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'devobj.dll' -> '\Device\HarddiskVolume4\Windows\System32\devobj.dll' [rcNtRedir=0xc0150008]
26214760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
26224760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
26234760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
26244760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume4\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
26254760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
26264760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
26274760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
26284760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
26294760.5bf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'cfgmgr32.dll'.
26304760.5bf4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\devobj.dll) WinVerifyTrust
26314760.5bf4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\devobj.dll
26324760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
26334760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
26344760.5bf4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll
26354760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
26364760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
26374760.5bf4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll [redoing WinVerifyTrust]
26384760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
26394760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
26404760.5bf4: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll'
26414760.5bf4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\MMDevApi.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
26424760.5bf4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\MMDevAPI.dll
26434760.5bf4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\devobj.dll
26444760.5bf4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\propsys.dll
26454760.5bf4: supR3HardenedDllNotificationCallback: load 00007ffcb6f20000 LB 0x00029000 C:\WINDOWS\System32\DEVOBJ.dll [fFlags=0x0]
26464760.5bf4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\devobj.dll
26474760.5bf4: supR3HardenedDllNotificationCallback: load 00007ffcb3f70000 LB 0x001a8000 C:\WINDOWS\System32\PROPSYS.dll [fFlags=0x0]
26484760.5bf4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\propsys.dll
26494760.5bf4: supR3HardenedDllNotificationCallback: load 00007ffcaf830000 LB 0x00070000 C:\WINDOWS\System32\MMDevApi.dll [fFlags=0x0]
26504760.5bf4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\MMDevAPI.dll
26514760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcaf830000 'C:\WINDOWS\System32\MMDevApi.dll'
26524760.5bf4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000fa0 pwszName=\Device\HarddiskVolume4\Windows\System32\dsound.dll
26534760.5bf4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000a97690
26544760.5bf4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000a97690
26554760.5bf4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B973A852091636F8493626192E69AE7AC7CBBB7F
26564760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
26574760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
26584760.5bf4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package~31bf3856ad364e35~amd64~~10.0.17763.1.cat'; file='\Device\HarddiskVolume4\Windows\System32\dsound.dll'
26594760.5bf4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
26604760.5bf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
26614760.5bf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #32 'winmm.dll'.
26624760.5bf4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\dsound.dll) WinVerifyTrust
26634760.5bf4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\dsound.dll
26644760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
26654760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume4\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
26664760.5bf4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmm.dll
26674760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
26684760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
26694760.5bf4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll
26704760.5bf4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
26714760.5bf4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\dsound.dll
26724760.5bf4: supR3HardenedDllNotificationCallback: load 00007ffc91be0000 LB 0x00096000 C:\WINDOWS\System32\dsound.dll [fFlags=0x0]
26734760.5bf4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\dsound.dll
26744760.5bf4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\dsound.dll
26754760.5bf4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
26764760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc91be0000 'C:\WINDOWS\System32\dsound.dll'
26774760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc91be0000 'C:\WINDOWS\System32\dsound.dll'
26784760.5bf4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\dsound.dll
26794760.5bf4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
26804760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc91be0000 'C:\WINDOWS\system32\dsound.dll'
26814760.5bf4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\MMDevAPI.dll
26824760.5bf4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\MMDEVAPI.DLL (Input=MMDEVAPI.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
26834760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcaf830000 'C:\WINDOWS\System32\MMDEVAPI.DLL'
26844760.5bf4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmm.dll
26854760.5bf4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\winmm.dll (Input=winmm.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
26864760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb46f0000 'C:\WINDOWS\System32\winmm.dll'
26874760.5bf4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000ff4 pwszName=\Device\HarddiskVolume4\Windows\System32\wdmaud.drv
26884760.5bf4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000a97690
26894760.5bf4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000a97690
26904760.5bf4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=22E5B934FBB9B8EED168F5BD0121AD902CCB797A
26914760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
26924760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
26934760.5bf4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package~31bf3856ad364e35~amd64~~10.0.17763.1.cat'; file='\Device\HarddiskVolume4\Windows\System32\wdmaud.drv'
26944760.5bf4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
26954760.5bf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
26964760.5bf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'mmdevapi.dll'.
26974760.5bf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 'ksuser.dll'.
26984760.5bf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #28 'avrt.dll'.
26994760.5bf4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\wdmaud.drv) WinVerifyTrust
27004760.5bf4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\wdmaud.drv
27014760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'avrt.dll'...
27024760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'avrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\avrt.dll' [rcNtRedir=0xc0150008]
27034760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
27044760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
27054760.5bf4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\avrt.dll) WinVerifyTrust
27064760.5bf4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\avrt.dll
27074760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ksuser.dll'...
27084760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ksuser.dll' -> '\Device\HarddiskVolume4\Windows\System32\ksuser.dll' [rcNtRedir=0xc0150008]
27094760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
27104760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
27114760.5bf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
27124760.5bf4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\ksuser.dll) WinVerifyTrust
27134760.5bf4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\ksuser.dll
27144760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mmdevapi.dll'...
27154760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'mmdevapi.dll' -> '\Device\HarddiskVolume4\Windows\System32\mmdevapi.dll' [rcNtRedir=0xc0150008]
27164760.5bf4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\MMDevAPI.dll
27174760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
27184760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
27194760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
27204760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
27214760.5bf4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
27224760.5bf4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wdmaud.drv
27234760.5bf4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ksuser.dll
27244760.5bf4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\avrt.dll
27254760.5bf4: supR3HardenedDllNotificationCallback: load 00007ffc953d0000 LB 0x00009000 C:\WINDOWS\SYSTEM32\ksuser.dll [fFlags=0x0]
27264760.5bf4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ksuser.dll
27274760.5bf4: supR3HardenedDllNotificationCallback: load 00007ffcb2c80000 LB 0x0000a000 C:\WINDOWS\SYSTEM32\AVRT.dll [fFlags=0x0]
27284760.5bf4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\avrt.dll
27294760.5bf4: supR3HardenedDllNotificationCallback: load 00007ffcb37f0000 LB 0x00044000 C:\WINDOWS\System32\wdmaud.drv [fFlags=0x0]
27304760.5bf4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wdmaud.drv
27314760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb37f0000 'C:\WINDOWS\System32\wdmaud.drv'
27324760.5bf4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wdmaud.drv
27334760.5bf4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
27344760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb37f0000 'C:\WINDOWS\System32\wdmaud.drv'
27354760.5bf4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wdmaud.drv
27364760.5bf4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
27374760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb37f0000 'C:\WINDOWS\System32\wdmaud.drv'
27384760.5bf4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wdmaud.drv
27394760.5bf4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
27404760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb37f0000 'C:\WINDOWS\System32\wdmaud.drv'
27414760.5bf4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wdmaud.drv
27424760.5bf4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
27434760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb37f0000 'C:\WINDOWS\System32\wdmaud.drv'
27444760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
27454760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
27464760.5bf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
27474760.5bf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'rpcrt4.dll'.
27484760.5bf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'oleaut32.dll'.
27494760.5bf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #57 'mmdevapi.dll'.
27504760.5bf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #58 'avrt.dll'.
27514760.5bf4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\AudioSes.dll) WinVerifyTrust
27524760.5bf4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\AudioSes.dll
27534760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'avrt.dll'...
27544760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'avrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\avrt.dll' [rcNtRedir=0xc0150008]
27554760.5bf4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\avrt.dll
27564760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mmdevapi.dll'...
27574760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'mmdevapi.dll' -> '\Device\HarddiskVolume4\Windows\System32\mmdevapi.dll' [rcNtRedir=0xc0150008]
27584760.5bf4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\MMDevAPI.dll
27594760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
27604760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume4\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
27614760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
27624760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
27634760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
27644760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
27654760.5bf4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcp_win.dll [redoing WinVerifyTrust]
27664760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
27674760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
27684760.5bf4: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\msvcp_win.dll'
27694760.5bf4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\AUDIOSES.DLL (Input=AUDIOSES.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
27704760.5bf4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\AudioSes.dll
27714760.5bf4: supR3HardenedDllNotificationCallback: load 00007ffcaf8c0000 LB 0x00148000 C:\WINDOWS\System32\AUDIOSES.DLL [fFlags=0x0]
27724760.5bf4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\AudioSes.dll
27734760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcaf8c0000 'C:\WINDOWS\System32\AUDIOSES.DLL'
27744760.5bf4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wdmaud.drv
27754760.5bf4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
27764760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb37f0000 'C:\WINDOWS\System32\wdmaud.drv'
27774760.5bf4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wdmaud.drv
27784760.5bf4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
27794760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb37f0000 'C:\WINDOWS\System32\wdmaud.drv'
27804760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb37f0000 'C:\WINDOWS\System32\wdmaud.drv'
27814760.5bf4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000e38 pwszName=\Device\HarddiskVolume4\Windows\System32\msacm32.drv
27824760.5bf4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000a97690
27834760.5bf4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000a97690
27844760.5bf4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=DF9222E8F115E50DE05D7AD2D27BDC071ADD62AF
27854760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
27864760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
27874760.5bf4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package~31bf3856ad364e35~amd64~~10.0.17763.1.cat'; file='\Device\HarddiskVolume4\Windows\System32\msacm32.drv'
27884760.5bf4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
27894760.5bf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
27904760.5bf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'mmdevapi.dll'.
27914760.5bf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'msacm32.dll'.
27924760.5bf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'winmmbase.dll'.
27934760.5bf4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\msacm32.drv) WinVerifyTrust
27944760.5bf4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\msacm32.drv
27954760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmmbase.dll'...
27964760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmmbase.dll' -> '\Device\HarddiskVolume4\Windows\System32\winmmbase.dll' [rcNtRedir=0xc0150008]
27974760.5bf4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmmbase.dll [redoing WinVerifyTrust]
27984760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
27994760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
28004760.5bf4: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\winmmbase.dll'
28014760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msacm32.dll'...
28024760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msacm32.dll' -> '\Device\HarddiskVolume4\Windows\System32\msacm32.dll' [rcNtRedir=0xc0150008]
28034760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
28044760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
28054760.5bf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
28064760.5bf4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\msacm32.dll) WinVerifyTrust
28074760.5bf4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\msacm32.dll
28084760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mmdevapi.dll'...
28094760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'mmdevapi.dll' -> '\Device\HarddiskVolume4\Windows\System32\mmdevapi.dll' [rcNtRedir=0xc0150008]
28104760.5bf4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\MMDevAPI.dll
28114760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
28124760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
28134760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
28144760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
28154760.5bf4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
28164760.5bf4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msacm32.drv
28174760.5bf4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msacm32.dll
28184760.5bf4: supR3HardenedDllNotificationCallback: load 00007ffcb37c0000 LB 0x0001c000 C:\WINDOWS\SYSTEM32\MSACM32.dll [fFlags=0x0]
28194760.5bf4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msacm32.dll
28204760.5bf4: supR3HardenedDllNotificationCallback: load 00007ffcb37e0000 LB 0x0000d000 C:\WINDOWS\System32\msacm32.drv [fFlags=0x0]
28214760.5bf4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msacm32.drv
28224760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb37e0000 'C:\WINDOWS\System32\msacm32.drv'
28234760.5bf4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msacm32.drv
28244760.5bf4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
28254760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb37e0000 'C:\WINDOWS\System32\msacm32.drv'
28264760.5bf4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msacm32.drv
28274760.5bf4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
28284760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb37e0000 'C:\WINDOWS\System32\msacm32.drv'
28294760.5bf4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msacm32.drv
28304760.5bf4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
28314760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb37e0000 'C:\WINDOWS\System32\msacm32.drv'
28324760.5bf4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msacm32.drv
28334760.5bf4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
28344760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb37e0000 'C:\WINDOWS\System32\msacm32.drv'
28354760.5bf4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msacm32.drv
28364760.5bf4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
28374760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb37e0000 'C:\WINDOWS\System32\msacm32.drv'
28384760.5bf4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msacm32.drv
28394760.5bf4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
28404760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb37e0000 'C:\WINDOWS\System32\msacm32.drv'
28414760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb37e0000 'C:\WINDOWS\System32\msacm32.drv'
28424760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb37e0000 'C:\WINDOWS\System32\msacm32.drv'
28434760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb37e0000 'C:\WINDOWS\System32\msacm32.drv'
28444760.5bf4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000010a4 pwszName=\Device\HarddiskVolume4\Windows\System32\midimap.dll
28454760.5bf4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000a97690
28464760.5bf4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000a97690
28474760.5bf4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=FE1B51D5EFA4634DA5F3478BB920BDCB24116539
28484760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
28494760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
28504760.5bf4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package~31bf3856ad364e35~amd64~~10.0.17763.1.cat'; file='\Device\HarddiskVolume4\Windows\System32\midimap.dll'
28514760.5bf4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
28524760.5bf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
28534760.5bf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'winmm.dll'.
28544760.5bf4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\midimap.dll) WinVerifyTrust
28554760.5bf4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\midimap.dll
28564760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
28574760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume4\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
28584760.5bf4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmm.dll
28594760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
28604760.5bf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
28614760.5bf4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
28624760.5bf4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\midimap.dll
28634760.5bf4: supR3HardenedDllNotificationCallback: load 00007ffcb37b0000 LB 0x0000a000 C:\WINDOWS\System32\midimap.dll [fFlags=0x0]
28644760.5bf4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\midimap.dll
28654760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb37b0000 'C:\WINDOWS\System32\midimap.dll'
28664760.5bf4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\midimap.dll
28674760.5bf4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
28684760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb37b0000 'C:\WINDOWS\System32\midimap.dll'
28694760.5bf4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\midimap.dll
28704760.5bf4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
28714760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb37b0000 'C:\WINDOWS\System32\midimap.dll'
28724760.5bf4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\midimap.dll
28734760.5bf4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
28744760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb37b0000 'C:\WINDOWS\System32\midimap.dll'
28754760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb46f0000 'C:\WINDOWS\System32\winmm.dll'
28764760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb46f0000 'C:\WINDOWS\System32\winmm.dll'
28774760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb46f0000 'C:\WINDOWS\System32\winmm.dll'
28784760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb46f0000 'C:\WINDOWS\System32\winmm.dll'
28794760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb46f0000 'C:\WINDOWS\System32\winmm.dll'
28804760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb46f0000 'C:\WINDOWS\System32\winmm.dll'
28814760.5bf4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\dsound.dll
28824760.5bf4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
28834760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc91be0000 'C:\WINDOWS\system32\dsound.dll'
28844760.5bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb46f0000 'C:\WINDOWS\System32\winmm.dll'
28855170.55f8: supR3HardNtChildWaitFor[2]: Quitting: ExitCode=0xcfffffff (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 182530 ms, the end);
28864a9c.4d9c: supR3HardNtChildWaitFor[1]: Quitting: ExitCode=0xcfffffff (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 183287 ms, the end);

© 2024 Oracle Support Privacy / Do Not Sell My Info Terms of Use Trademark Policy Automated Access Etiquette