VirtualBox

Ticket #18594: VBoxHardening.3.log

File VBoxHardening.3.log, 394.1 KB (added by James Fade, 6 years ago)
Line 
112c4.39c0: Log file opened: 6.0.6r130049 g_hStartupLog=0000000000000070 g_uNtVerCombined=0xa0456300
212c4.39c0: \SystemRoot\System32\ntdll.dll:
312c4.39c0: CreationTime: 2019-04-16T14:28:19.371663500Z
412c4.39c0: LastWriteTime: 2019-04-16T14:28:19.397039200Z
512c4.39c0: ChangeTime: 2019-04-16T17:59:00.884852400Z
612c4.39c0: FileAttributes: 0x20
712c4.39c0: Size: 0x1e7010
812c4.39c0: NT Headers: 0xe0
912c4.39c0: Timestamp: 0xbf6ea104
1012c4.39c0: Machine: 0x8664 - amd64
1112c4.39c0: Timestamp: 0xbf6ea104
1212c4.39c0: Image Version: 10.0
1312c4.39c0: SizeOfImage: 0x1ed000 (2019328)
1412c4.39c0: Resource Dir: 0x17d000 LB 0x6ea08
1512c4.39c0: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
1612c4.39c0: [Raw version resource data: 0x17d0f0 LB 0x380, codepage 0x0 (reserved 0x0)]
1712c4.39c0: ProductName: Microsoft® Windows® Operating System
1812c4.39c0: ProductVersion: 10.0.17763.404
1912c4.39c0: FileVersion: 10.0.17763.404 (WinBuild.160101.0800)
2012c4.39c0: FileDescription: NT Layer DLL
2112c4.39c0: \SystemRoot\System32\kernel32.dll:
2212c4.39c0: CreationTime: 2019-04-16T14:28:17.650736300Z
2312c4.39c0: LastWriteTime: 2019-04-16T14:28:17.658541500Z
2412c4.39c0: ChangeTime: 2019-04-16T17:59:00.463076400Z
2512c4.39c0: FileAttributes: 0x20
2612c4.39c0: Size: 0xb13a8
2712c4.39c0: NT Headers: 0xe8
2812c4.39c0: Timestamp: 0xa9e3d878
2912c4.39c0: Machine: 0x8664 - amd64
3012c4.39c0: Timestamp: 0xa9e3d878
3112c4.39c0: Image Version: 10.0
3212c4.39c0: SizeOfImage: 0xb3000 (733184)
3312c4.39c0: Resource Dir: 0xb1000 LB 0x520
3412c4.39c0: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
3512c4.39c0: [Raw version resource data: 0xb10b0 LB 0x3a4, codepage 0x0 (reserved 0x0)]
3612c4.39c0: ProductName: Microsoft® Windows® Operating System
3712c4.39c0: ProductVersion: 10.0.17763.437
3812c4.39c0: FileVersion: 10.0.17763.437 (WinBuild.160101.0800)
3912c4.39c0: FileDescription: Windows NT BASE API Client DLL
4012c4.39c0: \SystemRoot\System32\KernelBase.dll:
4112c4.39c0: CreationTime: 2019-04-16T14:28:19.033065300Z
4212c4.39c0: LastWriteTime: 2019-04-16T14:28:19.068203600Z
4312c4.39c0: ChangeTime: 2019-04-16T17:59:00.916095800Z
4412c4.39c0: FileAttributes: 0x20
4512c4.39c0: Size: 0x2937f8
4612c4.39c0: NT Headers: 0xf8
4712c4.39c0: Timestamp: 0x2528b630
4812c4.39c0: Machine: 0x8664 - amd64
4912c4.39c0: Timestamp: 0x2528b630
5012c4.39c0: Image Version: 10.0
5112c4.39c0: SizeOfImage: 0x293000 (2699264)
5212c4.39c0: Resource Dir: 0x26f000 LB 0x548
5312c4.39c0: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
5412c4.39c0: [Raw version resource data: 0x26f0b0 LB 0x3bc, codepage 0x0 (reserved 0x0)]
5512c4.39c0: ProductName: Microsoft® Windows® Operating System
5612c4.39c0: ProductVersion: 10.0.17763.404
5712c4.39c0: FileVersion: 10.0.17763.404 (WinBuild.160101.0800)
5812c4.39c0: FileDescription: Windows NT BASE API Client DLL
5912c4.39c0: \SystemRoot\System32\apisetschema.dll:
6012c4.39c0: CreationTime: 2018-09-15T07:28:25.403122600Z
6112c4.39c0: LastWriteTime: 2018-09-15T07:28:25.403122600Z
6212c4.39c0: ChangeTime: 2019-03-23T01:02:21.080644700Z
6312c4.39c0: FileAttributes: 0x20
6412c4.39c0: Size: 0x1c738
6512c4.39c0: NT Headers: 0xd0
6612c4.39c0: Timestamp: 0x33775897
6712c4.39c0: Machine: 0x8664 - amd64
6812c4.39c0: Timestamp: 0x33775897
6912c4.39c0: Image Version: 10.0
7012c4.39c0: SizeOfImage: 0x1d000 (118784)
7112c4.39c0: Resource Dir: 0x1c000 LB 0x408
7212c4.39c0: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
7312c4.39c0: [Raw version resource data: 0x1c060 LB 0x3a8, codepage 0x0 (reserved 0x0)]
7412c4.39c0: ProductName: Microsoft® Windows® Operating System
7512c4.39c0: ProductVersion: 10.0.17763.1
7612c4.39c0: FileVersion: 10.0.17763.1 (WinBuild.160101.0800)
7712c4.39c0: FileDescription: ApiSet Schema DLL
7812c4.39c0: NtOpenDirectoryObject failed on \Driver: 0xc0000022
7912c4.39c0: supR3HardenedWinFindAdversaries: 0x0
8012c4.39c0: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox'
8112c4.39c0: Calling main()
8212c4.39c0: SUPR3HardenedMain: pszProgName=VirtualBoxVM fFlags=0x2
8312c4.39c0: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox'
8412c4.39c0: SUPR3HardenedMain: Respawn #1
8512c4.39c0: System32: \Device\HarddiskVolume3\Windows\System32
8612c4.39c0: WinSxS: \Device\HarddiskVolume3\Windows\WinSxS
8712c4.39c0: KnownDllPath: C:\Windows\System32
8812c4.39c0: '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
8912c4.39c0: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe)
9012c4.39c0: supR3HardNtEnableThreadCreation:
9112c4.39c0: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffd48395660 pvNtTerminateThread=00007ffd483c00e0
9212c4.39c0: supR3HardenedWinDoReSpawn(1): New child 1030.2c68 [kernel32].
9312c4.39c0: supR3HardNtChildGatherData: PebBaseAddress=0000000000796000 cbPeb=0x388
9412c4.39c0: supR3HardNtPuChFindNtdll: uNtDllParentAddr=00007ffd48320000 uNtDllChildAddr=00007ffd48320000
9512c4.39c0: supR3HardenedWinSetupChildInit: uLdrInitThunk=00007ffd48395660
9612c4.39c0: supR3HardenedWinSetupChildInit: Start child.
9712c4.39c0: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
9812c4.39c0: supR3HardNtChildPurify: Startup delay kludge #1/0: 267 ms, 15 sleeps
9912c4.39c0: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
10012c4.39c0: *0000000000000000-000000000046ffff 0x0001/0x0000 0x0000000
10112c4.39c0: *0000000000470000-000000000048ffff 0x0004/0x0004 0x0020000
10212c4.39c0: *0000000000490000-00000000004a9fff 0x0002/0x0002 0x0040000
10312c4.39c0: 00000000004aa000-00000000004affff 0x0001/0x0000 0x0000000
10412c4.39c0: *00000000004b0000-00000000005aafff 0x0000/0x0004 0x0020000
10512c4.39c0: 00000000005ab000-00000000005adfff 0x0104/0x0004 0x0020000
10612c4.39c0: 00000000005ae000-00000000005affff 0x0004/0x0004 0x0020000
10712c4.39c0: *00000000005b0000-00000000005b3fff 0x0002/0x0002 0x0040000
10812c4.39c0: 00000000005b4000-00000000005bffff 0x0001/0x0000 0x0000000
10912c4.39c0: *00000000005c0000-00000000005c1fff 0x0004/0x0004 0x0020000
11012c4.39c0: 00000000005c2000-00000000005fffff 0x0001/0x0000 0x0000000
11112c4.39c0: *0000000000600000-0000000000795fff 0x0000/0x0004 0x0020000
11212c4.39c0: 0000000000796000-0000000000798fff 0x0004/0x0004 0x0020000
11312c4.39c0: 0000000000799000-00000000007fffff 0x0000/0x0004 0x0020000
11412c4.39c0: 0000000000800000-000000007ffdffff 0x0001/0x0000 0x0000000
11512c4.39c0: *000000007ffe0000-000000007ffe0fff 0x0002/0x0002 0x0020000
11612c4.39c0: 000000007ffe1000-000000007ffeafff 0x0001/0x0000 0x0000000
11712c4.39c0: *000000007ffeb000-000000007ffebfff 0x0002/0x0002 0x0020000
11812c4.39c0: 000000007ffec000-00007ff5963fffff 0x0001/0x0000 0x0000000
11912c4.39c0: *00007ff596400000-00007ff596400fff 0x0002/0x0002 0x0040000
12012c4.39c0: 00007ff596401000-00007ff59640ffff 0x0001/0x0000 0x0000000
12112c4.39c0: *00007ff596410000-00007ff596432fff 0x0002/0x0002 0x0040000
12212c4.39c0: 00007ff596433000-00007ff78e8bffff 0x0001/0x0000 0x0000000
12312c4.39c0: *00007ff78e8c0000-00007ff78e8c0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
12412c4.39c0: 00007ff78e8c1000-00007ff78e934fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
12512c4.39c0: 00007ff78e935000-00007ff78e935fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
12612c4.39c0: 00007ff78e936000-00007ff78e97cfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
12712c4.39c0: 00007ff78e97d000-00007ff78e97dfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
12812c4.39c0: 00007ff78e97e000-00007ff78e97efff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
12912c4.39c0: 00007ff78e97f000-00007ff78e983fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
13012c4.39c0: 00007ff78e984000-00007ff78e984fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
13112c4.39c0: 00007ff78e985000-00007ff78e985fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
13212c4.39c0: 00007ff78e986000-00007ff78e989fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
13312c4.39c0: 00007ff78e98a000-00007ff78e9d2fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
13412c4.39c0: 00007ff78e9d3000-00007ffd4831ffff 0x0001/0x0000 0x0000000
13512c4.39c0: *00007ffd48320000-00007ffd48320fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
13612c4.39c0: 00007ffd48321000-00007ffd48437fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
13712c4.39c0: 00007ffd48438000-00007ffd4847efff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
13812c4.39c0: 00007ffd4847f000-00007ffd48489fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
13912c4.39c0: 00007ffd4848a000-00007ffd48497fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
14012c4.39c0: 00007ffd48498000-00007ffd48498fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
14112c4.39c0: 00007ffd48499000-00007ffd4849bfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
14212c4.39c0: 00007ffd4849c000-00007ffd4850cfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
14312c4.39c0: 00007ffd4850d000-00007ffffffeffff 0x0001/0x0000 0x0000000
14412c4.39c0: VirtualBoxVM.exe: timestamp 0x5cb5a5f0 (rc=VINF_SUCCESS)
14512c4.39c0: '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
14612c4.39c0: '\Device\HarddiskVolume3\Windows\System32\ntdll.dll' has no imports
14712c4.39c0: supR3HardNtChildPurify: Done after 288 ms and 0 fixes (loop #0).
1481030.2c68: Log file opened: 6.0.6r130049 g_hStartupLog=0000000000000004 g_uNtVerCombined=0xa0456300
1491030.2c68: supR3HardenedVmProcessInit: uNtDllAddr=00007ffd48320000 g_uNtVerCombined=0xa0456300
15012c4.39c0: supR3HardNtEnableThreadCreation:
1511030.2c68: ntdll.dll: timestamp 0xbf6ea104 (rc=VINF_SUCCESS)
1521030.2c68: New simple heap: #1 0000000000900000 LB 0x400000 (for 2019328 allocation)
1531030.2c68: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox'
1541030.2c68: System32: \Device\HarddiskVolume3\Windows\System32
1551030.2c68: WinSxS: \Device\HarddiskVolume3\Windows\WinSxS
1561030.2c68: KnownDllPath: C:\Windows\System32
1571030.2c68: supR3HardenedVmProcessInit: Opening vboxdrv stub...
1581030.2c68: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
1591030.2c68: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
1601030.2c68: Registered Dll notification callback with NTDLL.
1611030.2c68: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\kernel32.dll)
1621030.2c68: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\kernel32.dll
1631030.2c68: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\KERNEL32.DLL (Input=KERNEL32.DLL, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000004001:<flags> [calling]
1641030.2c68: supR3HardenedDllNotificationCallback: load 00007ffd45160000 LB 0x00293000 C:\Windows\System32\KERNELBASE.dll [fFlags=0x0]
1651030.2c68: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\KernelBase.dll)
1661030.2c68: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\KernelBase.dll
1671030.2c68: supR3HardenedDllNotificationCallback: load 00007ffd47ba0000 LB 0x000b3000 C:\Windows\System32\KERNEL32.DLL [fFlags=0x0]
1681030.2c68: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
1691030.2c68: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd47ba0000 'C:\Windows\System32\KERNEL32.DLL'
1701030.2c68: supR3HardenedDllNotificationCallback: load 00007ff78e8c0000 LB 0x00113000 C:\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe [fFlags=0x0]
1711030.2c68: '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
1721030.2c68: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe)
1731030.2c68: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
1741030.2c68: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffd48395660 pvNtTerminateThread=00007ffd483c00e0
17512c4.39c0: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 62 ms.
1761030.2c68: \SystemRoot\System32\ntdll.dll:
1771030.2c68: CreationTime: 2019-04-16T14:28:19.371663500Z
1781030.2c68: LastWriteTime: 2019-04-16T14:28:19.397039200Z
1791030.2c68: ChangeTime: 2019-04-16T17:59:00.884852400Z
1801030.2c68: FileAttributes: 0x20
1811030.2c68: Size: 0x1e7010
1821030.2c68: NT Headers: 0xe0
1831030.2c68: Timestamp: 0xbf6ea104
1841030.2c68: Machine: 0x8664 - amd64
1851030.2c68: Timestamp: 0xbf6ea104
1861030.2c68: Image Version: 10.0
1871030.2c68: SizeOfImage: 0x1ed000 (2019328)
1881030.2c68: Resource Dir: 0x17d000 LB 0x6ea08
1891030.2c68: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
1901030.2c68: [Raw version resource data: 0x17d0f0 LB 0x380, codepage 0x0 (reserved 0x0)]
1911030.2c68: ProductName: Microsoft® Windows® Operating System
1921030.2c68: ProductVersion: 10.0.17763.404
1931030.2c68: FileVersion: 10.0.17763.404 (WinBuild.160101.0800)
1941030.2c68: FileDescription: NT Layer DLL
1951030.2c68: \SystemRoot\System32\kernel32.dll:
1961030.2c68: CreationTime: 2019-04-16T14:28:17.650736300Z
1971030.2c68: LastWriteTime: 2019-04-16T14:28:17.658541500Z
1981030.2c68: ChangeTime: 2019-04-16T17:59:00.463076400Z
1991030.2c68: FileAttributes: 0x20
2001030.2c68: Size: 0xb13a8
2011030.2c68: NT Headers: 0xe8
2021030.2c68: Timestamp: 0xa9e3d878
2031030.2c68: Machine: 0x8664 - amd64
2041030.2c68: Timestamp: 0xa9e3d878
2051030.2c68: Image Version: 10.0
2061030.2c68: SizeOfImage: 0xb3000 (733184)
2071030.2c68: Resource Dir: 0xb1000 LB 0x520
2081030.2c68: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
2091030.2c68: [Raw version resource data: 0xb10b0 LB 0x3a4, codepage 0x0 (reserved 0x0)]
2101030.2c68: ProductName: Microsoft® Windows® Operating System
2111030.2c68: ProductVersion: 10.0.17763.437
2121030.2c68: FileVersion: 10.0.17763.437 (WinBuild.160101.0800)
2131030.2c68: FileDescription: Windows NT BASE API Client DLL
2141030.2c68: \SystemRoot\System32\KernelBase.dll:
2151030.2c68: CreationTime: 2019-04-16T14:28:19.033065300Z
2161030.2c68: LastWriteTime: 2019-04-16T14:28:19.068203600Z
2171030.2c68: ChangeTime: 2019-04-16T17:59:00.916095800Z
2181030.2c68: FileAttributes: 0x20
2191030.2c68: Size: 0x2937f8
2201030.2c68: NT Headers: 0xf8
2211030.2c68: Timestamp: 0x2528b630
2221030.2c68: Machine: 0x8664 - amd64
2231030.2c68: Timestamp: 0x2528b630
2241030.2c68: Image Version: 10.0
2251030.2c68: SizeOfImage: 0x293000 (2699264)
2261030.2c68: Resource Dir: 0x26f000 LB 0x548
2271030.2c68: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
2281030.2c68: [Raw version resource data: 0x26f0b0 LB 0x3bc, codepage 0x0 (reserved 0x0)]
2291030.2c68: ProductName: Microsoft® Windows® Operating System
2301030.2c68: ProductVersion: 10.0.17763.404
2311030.2c68: FileVersion: 10.0.17763.404 (WinBuild.160101.0800)
2321030.2c68: FileDescription: Windows NT BASE API Client DLL
2331030.2c68: \SystemRoot\System32\apisetschema.dll:
2341030.2c68: CreationTime: 2018-09-15T07:28:25.403122600Z
2351030.2c68: LastWriteTime: 2018-09-15T07:28:25.403122600Z
2361030.2c68: ChangeTime: 2019-03-23T01:02:21.080644700Z
2371030.2c68: FileAttributes: 0x20
2381030.2c68: Size: 0x1c738
2391030.2c68: NT Headers: 0xd0
2401030.2c68: Timestamp: 0x33775897
2411030.2c68: Machine: 0x8664 - amd64
2421030.2c68: Timestamp: 0x33775897
2431030.2c68: Image Version: 10.0
2441030.2c68: SizeOfImage: 0x1d000 (118784)
2451030.2c68: Resource Dir: 0x1c000 LB 0x408
2461030.2c68: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
2471030.2c68: [Raw version resource data: 0x1c060 LB 0x3a8, codepage 0x0 (reserved 0x0)]
2481030.2c68: ProductName: Microsoft® Windows® Operating System
2491030.2c68: ProductVersion: 10.0.17763.1
2501030.2c68: FileVersion: 10.0.17763.1 (WinBuild.160101.0800)
2511030.2c68: FileDescription: ApiSet Schema DLL
2521030.2c68: NtOpenDirectoryObject failed on \Driver: 0xc0000022
2531030.2c68: supR3HardenedWinFindAdversaries: 0x0
2541030.2c68: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox'
2551030.2c68: Calling main()
2561030.2c68: SUPR3HardenedMain: pszProgName=VirtualBoxVM fFlags=0x2
2571030.2c68: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox'
2581030.2c68: '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
2591030.2c68: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe)
2601030.2c68: SUPR3HardenedMain: Respawn #2
2611030.2c68: supR3HardNtEnableThreadCreation:
2621030.2c68: supR3HardenedDllNotificationCallback: load 00007ffd46f90000 LB 0x00122000 C:\Windows\System32\RPCRT4.dll [fFlags=0x0]
2631030.2c68: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll)
2641030.2c68: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll
2651030.2c68: supR3HardenedDllNotificationCallback: load 00007ffd47b00000 LB 0x0009e000 C:\Windows\System32\sechost.dll [fFlags=0x0]
2661030.2c68: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'rpcrt4.dll'.
2671030.2c68: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\sechost.dll)
2681030.2c68: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\sechost.dll
2691030.2c68: '\Device\HarddiskVolume3\Windows\System32\ntdll.dll' has no imports
2701030.2c68: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\ntdll.dll)
2711030.2c68: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\ntdll.dll
2721030.2c68: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
2731030.2c68: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
2741030.2c68: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
2751030.2c68: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\ntdll.dll (Input=ntdll.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
2761030.2c68: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd48320000 'C:\Windows\System32\ntdll.dll'
2771030.2c68: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffd48395660 pvNtTerminateThread=00007ffd483c00e0
2781030.2c68: supR3HardenedWinDoReSpawn(2): New child 6e4.57c [kernel32].
2791030.2c68: supR3HardenedWinReSpawn: NtSetInformationThread/ThreadHideFromDebugger failed: 0xc0000022 (harmless)
2801030.2c68: supR3HardNtChildGatherData: PebBaseAddress=0000000000d24000 cbPeb=0x388
2811030.2c68: supR3HardNtPuChFindNtdll: uNtDllParentAddr=00007ffd48320000 uNtDllChildAddr=00007ffd48320000
2821030.2c68: supR3HardenedWinSetupChildInit: uLdrInitThunk=00007ffd48395660
2831030.2c68: supR3HardenedWinSetupChildInit: Start child.
2841030.2c68: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 1 ms.
2851030.2c68: supR3HardNtChildPurify: Startup delay kludge #1/0: 262 ms, 30 sleeps
2861030.2c68: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
2871030.2c68: *0000000000000000-0000000000a4ffff 0x0001/0x0000 0x0000000
2881030.2c68: *0000000000a50000-0000000000a6ffff 0x0004/0x0004 0x0020000
2891030.2c68: *0000000000a70000-0000000000a89fff 0x0002/0x0002 0x0040000
2901030.2c68: 0000000000a8a000-0000000000a8ffff 0x0001/0x0000 0x0000000
2911030.2c68: *0000000000a90000-0000000000b8afff 0x0000/0x0004 0x0020000
2921030.2c68: 0000000000b8b000-0000000000b8dfff 0x0104/0x0004 0x0020000
2931030.2c68: 0000000000b8e000-0000000000b8ffff 0x0004/0x0004 0x0020000
2941030.2c68: *0000000000b90000-0000000000b93fff 0x0002/0x0002 0x0040000
2951030.2c68: 0000000000b94000-0000000000b9ffff 0x0001/0x0000 0x0000000
2961030.2c68: *0000000000ba0000-0000000000ba1fff 0x0004/0x0004 0x0020000
2971030.2c68: 0000000000ba2000-0000000000bfffff 0x0001/0x0000 0x0000000
2981030.2c68: *0000000000c00000-0000000000d23fff 0x0000/0x0004 0x0020000
2991030.2c68: 0000000000d24000-0000000000d26fff 0x0004/0x0004 0x0020000
3001030.2c68: 0000000000d27000-0000000000dfffff 0x0000/0x0004 0x0020000
3011030.2c68: 0000000000e00000-000000007ffdffff 0x0001/0x0000 0x0000000
3021030.2c68: *000000007ffe0000-000000007ffe0fff 0x0002/0x0002 0x0020000
3031030.2c68: 000000007ffe1000-000000007ffeafff 0x0001/0x0000 0x0000000
3041030.2c68: *000000007ffeb000-000000007ffebfff 0x0002/0x0002 0x0020000
3051030.2c68: 000000007ffec000-00007ff5269bffff 0x0001/0x0000 0x0000000
3061030.2c68: *00007ff5269c0000-00007ff5269c0fff 0x0002/0x0002 0x0040000
3071030.2c68: 00007ff5269c1000-00007ff5269cffff 0x0001/0x0000 0x0000000
3081030.2c68: *00007ff5269d0000-00007ff5269f2fff 0x0002/0x0002 0x0040000
3091030.2c68: 00007ff5269f3000-00007ff78e8bffff 0x0001/0x0000 0x0000000
3101030.2c68: *00007ff78e8c0000-00007ff78e8c0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
3111030.2c68: 00007ff78e8c1000-00007ff78e934fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
3121030.2c68: 00007ff78e935000-00007ff78e935fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
3131030.2c68: 00007ff78e936000-00007ff78e97cfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
3141030.2c68: 00007ff78e97d000-00007ff78e97dfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
3151030.2c68: 00007ff78e97e000-00007ff78e97efff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
3161030.2c68: 00007ff78e97f000-00007ff78e983fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
3171030.2c68: 00007ff78e984000-00007ff78e984fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
3181030.2c68: 00007ff78e985000-00007ff78e985fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
3191030.2c68: 00007ff78e986000-00007ff78e989fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
3201030.2c68: 00007ff78e98a000-00007ff78e9d2fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
3211030.2c68: 00007ff78e9d3000-00007ffd4831ffff 0x0001/0x0000 0x0000000
3221030.2c68: *00007ffd48320000-00007ffd48320fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
3231030.2c68: 00007ffd48321000-00007ffd48437fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
3241030.2c68: 00007ffd48438000-00007ffd4847efff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
3251030.2c68: 00007ffd4847f000-00007ffd48489fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
3261030.2c68: 00007ffd4848a000-00007ffd48497fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
3271030.2c68: 00007ffd48498000-00007ffd48498fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
3281030.2c68: 00007ffd48499000-00007ffd4849bfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
3291030.2c68: 00007ffd4849c000-00007ffd4850cfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
3301030.2c68: 00007ffd4850d000-00007ffffffeffff 0x0001/0x0000 0x0000000
3311030.2c68: VirtualBoxVM.exe: timestamp 0x5cb5a5f0 (rc=VINF_SUCCESS)
3321030.2c68: '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
3331030.2c68: '\Device\HarddiskVolume3\Windows\System32\ntdll.dll' has no imports
3341030.2c68: supR3HardNtChildPurify: Done after 289 ms and 0 fixes (loop #0).
3356e4.57c: Log file opened: 6.0.6r130049 g_hStartupLog=0000000000000004 g_uNtVerCombined=0xa0456300
3366e4.57c: supR3HardenedVmProcessInit: uNtDllAddr=00007ffd48320000 g_uNtVerCombined=0xa0456300
3371030.2c68: supR3HardenedEarlyCompact: Removed heap 1 (0x00000000900000 LB 0x400000)
3381030.2c68: supR3HardNtEnableThreadCreation:
3396e4.57c: ntdll.dll: timestamp 0xbf6ea104 (rc=VINF_SUCCESS)
3406e4.57c: New simple heap: #1 0000000000f00000 LB 0x400000 (for 2019328 allocation)
3416e4.57c: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox'
3426e4.57c: System32: \Device\HarddiskVolume3\Windows\System32
3436e4.57c: WinSxS: \Device\HarddiskVolume3\Windows\WinSxS
3446e4.57c: KnownDllPath: C:\Windows\System32
3456e4.57c: supR3HardenedVmProcessInit: Opening vboxdrv...
3466e4.57c: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
3476e4.57c: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
3486e4.57c: Registered Dll notification callback with NTDLL.
3496e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\kernel32.dll)
3506e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\kernel32.dll
3516e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\KERNEL32.DLL (Input=KERNEL32.DLL, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000004001:<flags> [calling]
3526e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd45160000 LB 0x00293000 C:\Windows\System32\KERNELBASE.dll [fFlags=0x0]
3536e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\KernelBase.dll)
3546e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\KernelBase.dll
3556e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd47ba0000 LB 0x000b3000 C:\Windows\System32\KERNEL32.DLL [fFlags=0x0]
3566e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
3576e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd47ba0000 'C:\Windows\System32\KERNEL32.DLL'
3586e4.57c: supR3HardenedDllNotificationCallback: load 00007ff78e8c0000 LB 0x00113000 C:\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe [fFlags=0x0]
3596e4.57c: '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
3606e4.57c: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe)
3616e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
3626e4.57c: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffd48395660 pvNtTerminateThread=00007ffd483c00e0
3631030.2c68: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 71 ms.
3646e4.57c: \SystemRoot\System32\ntdll.dll:
3656e4.57c: CreationTime: 2019-04-16T14:28:19.371663500Z
3666e4.57c: LastWriteTime: 2019-04-16T14:28:19.397039200Z
3676e4.57c: ChangeTime: 2019-04-16T17:59:00.884852400Z
3686e4.57c: FileAttributes: 0x20
3696e4.57c: Size: 0x1e7010
3706e4.57c: NT Headers: 0xe0
3716e4.57c: Timestamp: 0xbf6ea104
3726e4.57c: Machine: 0x8664 - amd64
3736e4.57c: Timestamp: 0xbf6ea104
3746e4.57c: Image Version: 10.0
3756e4.57c: SizeOfImage: 0x1ed000 (2019328)
3766e4.57c: Resource Dir: 0x17d000 LB 0x6ea08
3776e4.57c: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
3786e4.57c: [Raw version resource data: 0x17d0f0 LB 0x380, codepage 0x0 (reserved 0x0)]
3796e4.57c: ProductName: Microsoft® Windows® Operating System
3806e4.57c: ProductVersion: 10.0.17763.404
3816e4.57c: FileVersion: 10.0.17763.404 (WinBuild.160101.0800)
3826e4.57c: FileDescription: NT Layer DLL
3836e4.57c: \SystemRoot\System32\kernel32.dll:
3846e4.57c: CreationTime: 2019-04-16T14:28:17.650736300Z
3856e4.57c: LastWriteTime: 2019-04-16T14:28:17.658541500Z
3866e4.57c: ChangeTime: 2019-04-16T17:59:00.463076400Z
3876e4.57c: FileAttributes: 0x20
3886e4.57c: Size: 0xb13a8
3896e4.57c: NT Headers: 0xe8
3906e4.57c: Timestamp: 0xa9e3d878
3916e4.57c: Machine: 0x8664 - amd64
3926e4.57c: Timestamp: 0xa9e3d878
3936e4.57c: Image Version: 10.0
3946e4.57c: SizeOfImage: 0xb3000 (733184)
3956e4.57c: Resource Dir: 0xb1000 LB 0x520
3966e4.57c: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
3976e4.57c: [Raw version resource data: 0xb10b0 LB 0x3a4, codepage 0x0 (reserved 0x0)]
3986e4.57c: ProductName: Microsoft® Windows® Operating System
3996e4.57c: ProductVersion: 10.0.17763.437
4006e4.57c: FileVersion: 10.0.17763.437 (WinBuild.160101.0800)
4016e4.57c: FileDescription: Windows NT BASE API Client DLL
4026e4.57c: \SystemRoot\System32\KernelBase.dll:
4036e4.57c: CreationTime: 2019-04-16T14:28:19.033065300Z
4046e4.57c: LastWriteTime: 2019-04-16T14:28:19.068203600Z
4056e4.57c: ChangeTime: 2019-04-16T17:59:00.916095800Z
4066e4.57c: FileAttributes: 0x20
4076e4.57c: Size: 0x2937f8
4086e4.57c: NT Headers: 0xf8
4096e4.57c: Timestamp: 0x2528b630
4106e4.57c: Machine: 0x8664 - amd64
4116e4.57c: Timestamp: 0x2528b630
4126e4.57c: Image Version: 10.0
4136e4.57c: SizeOfImage: 0x293000 (2699264)
4146e4.57c: Resource Dir: 0x26f000 LB 0x548
4156e4.57c: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
4166e4.57c: [Raw version resource data: 0x26f0b0 LB 0x3bc, codepage 0x0 (reserved 0x0)]
4176e4.57c: ProductName: Microsoft® Windows® Operating System
4186e4.57c: ProductVersion: 10.0.17763.404
4196e4.57c: FileVersion: 10.0.17763.404 (WinBuild.160101.0800)
4206e4.57c: FileDescription: Windows NT BASE API Client DLL
4216e4.57c: \SystemRoot\System32\apisetschema.dll:
4226e4.57c: CreationTime: 2018-09-15T07:28:25.403122600Z
4236e4.57c: LastWriteTime: 2018-09-15T07:28:25.403122600Z
4246e4.57c: ChangeTime: 2019-03-23T01:02:21.080644700Z
4256e4.57c: FileAttributes: 0x20
4266e4.57c: Size: 0x1c738
4276e4.57c: NT Headers: 0xd0
4286e4.57c: Timestamp: 0x33775897
4296e4.57c: Machine: 0x8664 - amd64
4306e4.57c: Timestamp: 0x33775897
4316e4.57c: Image Version: 10.0
4326e4.57c: SizeOfImage: 0x1d000 (118784)
4336e4.57c: Resource Dir: 0x1c000 LB 0x408
4346e4.57c: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
4356e4.57c: [Raw version resource data: 0x1c060 LB 0x3a8, codepage 0x0 (reserved 0x0)]
4366e4.57c: ProductName: Microsoft® Windows® Operating System
4376e4.57c: ProductVersion: 10.0.17763.1
4386e4.57c: FileVersion: 10.0.17763.1 (WinBuild.160101.0800)
4396e4.57c: FileDescription: ApiSet Schema DLL
4406e4.57c: NtOpenDirectoryObject failed on \Driver: 0xc0000022
4416e4.57c: supR3HardenedWinFindAdversaries: 0x0
4426e4.57c: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox'
4436e4.57c: Calling main()
4446e4.57c: SUPR3HardenedMain: pszProgName=VirtualBoxVM fFlags=0x2
4456e4.57c: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox'
4466e4.57c: '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
4476e4.57c: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe)
4486e4.57c: SUPR3HardenedMain: Final process, opening VBoxDrv...
4496e4.57c: supR3HardenedEarlyCompact: Removed heap 1 (0x00000000f00000 LB 0x400000)
4506e4.57c: supR3HardNtEnableThreadCreation:
4516e4.57c: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSupLib.dll)
4526e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSupLib.dll
4536e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
4546e4.57c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
4556e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd40380000 LB 0x00005000 C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL [fFlags=0x0]
4566e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
4576e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
4586e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
4596e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd40380000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
4606e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
4616e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
4626e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd40380000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
4636e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd40380000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
4646e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
4656e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msasn1.dll'.
4666e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'crypt32.dll'.
4676e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 'rpcrt4.dll'.
4686e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\wintrust.dll)
4696e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\wintrust.dll
4706e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
4716e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
4726e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll)
4736e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll
4746e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
4756e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume3\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
4766e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #34 'msasn1.dll'.
4776e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\crypt32.dll)
4786e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\crypt32.dll
4796e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
4806e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume3\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
4816e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\msasn1.dll)
4826e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\msasn1.dll
4836e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
4846e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
4856e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\msvcrt.dll)
4866e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\msvcrt.dll
4876e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
4886e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume3\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
4896e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
4906e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
4916e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd47a60000 LB 0x0009e000 C:\Windows\System32\msvcrt.dll [fFlags=0x0]
4926e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
4936e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd44320000 LB 0x00012000 C:\Windows\System32\MSASN1.dll [fFlags=0x0]
4946e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
4956e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd45450000 LB 0x000fa000 C:\Windows\System32\ucrtbase.dll [fFlags=0x0]
4966e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\ucrtbase.dll)
4976e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\ucrtbase.dll
4986e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd44f00000 LB 0x001db000 C:\Windows\System32\CRYPT32.dll [fFlags=0x0]
4996e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
5006e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd46f90000 LB 0x00122000 C:\Windows\System32\RPCRT4.dll [fFlags=0x0]
5016e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
5026e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd44ea0000 LB 0x00059000 C:\Windows\System32\Wintrust.dll [fFlags=0x0]
5036e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
5046e4.57c: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
5056e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
5066e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd45160000 'api-ms-win-core-synch-l1-2-0'
5076e4.57c: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
5086e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
5096e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd45160000 'api-ms-win-core-fibers-l1-1-1'
5106e4.57c: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
5116e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
5126e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd45160000 'api-ms-win-core-fibers-l1-1-1'
5136e4.57c: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
5146e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
5156e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd45160000 'api-ms-win-core-synch-l1-2-0'
5166e4.57c: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-l1-2-1) -> 0x0, fPresent=1
5176e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-l1-2-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
5186e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd45160000 'api-ms-win-core-localization-l1-2-1'
5196e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44ea0000 'C:\Windows\system32\Wintrust.dll'
5206e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\bcrypt.dll)
5216e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\bcrypt.dll
5226e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcrypt.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
5236e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd45420000 LB 0x00026000 C:\Windows\System32\bcrypt.dll [fFlags=0x0]
5246e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
5256e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd45420000 'C:\Windows\system32\bcrypt.dll'
5266e4.57c: bcrypt.dll loaded at 00007ffd45420000, BCryptOpenAlgorithmProvider at 00007ffd45424d60, preloading providers:
5276e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\bcryptprimitives.dll)
5286e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\bcryptprimitives.dll
5296e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcryptprimitives.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
5306e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd450e0000 LB 0x0007e000 C:\Windows\System32\bcryptprimitives.dll [fFlags=0x0]
5316e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
5326e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd450e0000 'C:\Windows\system32\bcryptprimitives.dll'
5336e4.57c: BCryptOpenAlgorithmProvider(,'MD2',0,0) -> 0x0 (hAlgo=000000000132e720)
5346e4.57c: BCryptOpenAlgorithmProvider(,'MD4',0,0) -> 0x0 (hAlgo=000000000132f480)
5356e4.57c: BCryptOpenAlgorithmProvider(,'MD5',0,0) -> 0x0 (hAlgo=000000000132f780)
5366e4.57c: BCryptOpenAlgorithmProvider(,'SHA1',0,0) -> 0x0 (hAlgo=000000000132fa80)
5376e4.57c: BCryptOpenAlgorithmProvider(,'SHA256',0,0) -> 0x0 (hAlgo=000000000132fd80)
5386e4.57c: BCryptOpenAlgorithmProvider(,'SHA512',0,0) -> 0x0 (hAlgo=0000000001330080)
5396e4.57c: BCryptOpenAlgorithmProvider(,'RSA',0,0) -> 0x0 (hAlgo=0000000001330380)
5406e4.57c: BCryptOpenAlgorithmProvider(,'DSA',0,0) -> 0x0 (hAlgo=0000000001330680)
5416e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd45400000 LB 0x00017000 C:\Windows\System32\CRYPTSP.dll [fFlags=0x0]
5426e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\cryptsp.dll)
5436e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\cryptsp.dll
5446e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'bcrypt.dll'.
5456e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\rsaenh.dll)
5466e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\rsaenh.dll
5476e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
5486e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume3\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
5496e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
5506e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
5516e4.57c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
5526e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd43700000 LB 0x00033000 C:\Windows\system32\rsaenh.dll [fFlags=0x0]
5536e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
5546e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
5556e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'bcryptprimitives.dll'.
5566e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\cryptbase.dll)
5576e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\cryptbase.dll
5586e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd43d10000 LB 0x0000c000 C:\Windows\SYSTEM32\CRYPTBASE.dll [fFlags=0x0]
5596e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\cryptbase.dll [lacks WinVerifyTrust]
5606e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
5616e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcryptprimitives.dll'...
5626e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcryptprimitives.dll' -> '\Device\HarddiskVolume3\Windows\System32\bcryptprimitives.dll' [rcNtRedir=0xc0150008]
5636e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
5646e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
5656e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd47ba0000 'C:\Windows\System32\kernel32.dll'
5666e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
5676e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (Input=WINTRUST.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
5686e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44ea0000 'C:\Windows\System32\WINTRUST.DLL'
5696e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
5706e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\CRYPT32.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
5716e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\CRYPT32.dll'
5726e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd45790000 LB 0x0001d000 C:\Windows\System32\imagehlp.dll [fFlags=0x0]
5736e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\imagehlp.dll)
5746e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\imagehlp.dll
5756e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
5766e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
5776e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
5786e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd47b00000 LB 0x0009e000 C:\Windows\System32\sechost.dll [fFlags=0x0]
5796e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'rpcrt4.dll'.
5806e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\sechost.dll)
5816e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\sechost.dll
5826e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
5836e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'rpcrt4.dll'.
5846e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\gpapi.dll)
5856e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\gpapi.dll
5866e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd43000000 LB 0x00022000 C:\Windows\SYSTEM32\gpapi.dll [fFlags=0x0]
5876e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gpapi.dll [lacks WinVerifyTrust]
5886e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd443c0000 LB 0x00024000 C:\Windows\System32\profapi.dll [fFlags=0x0]
5896e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\profapi.dll)
5906e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\profapi.dll
5916e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
5926e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'crypt32.dll'.
5936e4.57c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\cryptnet.dll)
5946e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\cryptnet.dll
5956e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
5966e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume3\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
5976e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
5986e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
5996e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
6006e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
6016e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
6026e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
6036e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
6046e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
6056e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
6066e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
6076e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
6086e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
6096e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
6106e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\cryptnet.dll (Input=cryptnet.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
6116e4.57c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6126e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd24a40000 LB 0x0002f000 C:\Windows\System32\cryptnet.dll [fFlags=0x0]
6136e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6146e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6156e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
6166e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd24a40000 'C:\Windows\System32\cryptnet.dll'
6176e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6186e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
6196e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd24a40000 'C:\Windows\System32\cryptnet.dll'
6206e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6216e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
6226e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd24a40000 'C:\Windows\System32\cryptnet.dll'
6236e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6246e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
6256e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd24a40000 'C:\Windows\System32\cryptnet.dll'
6266e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6276e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
6286e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd24a40000 'C:\Windows\System32\cryptnet.dll'
6296e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6306e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
6316e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd24a40000 'C:\Windows\System32\cryptnet.dll'
6326e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6336e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd24a40000 'C:\Windows\System32\cryptnet.dll'
6346e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6356e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd24a40000 'C:\Windows\System32\cryptnet.dll'
6366e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6376e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd24a40000 'C:\Windows\System32\cryptnet.dll'
6386e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6396e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd24a40000 'C:\Windows\System32\cryptnet.dll'
6406e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6416e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd24a40000 'C:\Windows\System32\cryptnet.dll'
6426e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd24a40000 'C:\Windows\System32\cryptnet.dll'
6436e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6446e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd24a40000 'C:\Windows\System32\cryptnet.dll'
6456e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd45550000 LB 0x000a3000 C:\Windows\System32\advapi32.dll [fFlags=0x0]
6466e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
6476e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'sechost.dll'.
6486e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 'rpcrt4.dll'.
6496e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\advapi32.dll)
6506e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\advapi32.dll
6516e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
6526e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
6536e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
6546e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
6556e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'sechost.dll'...
6566e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'sechost.dll' -> '\Device\HarddiskVolume3\Windows\System32\sechost.dll' [rcNtRedir=0xc0150008]
6576e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\sechost.dll [lacks WinVerifyTrust]
6586e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
6596e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
6606e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
6616e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
6626e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
6636e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
6646e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
6656e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
6666e4.57c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000000 pwszName=\SystemRoot\System32\ntdll.dll
6676e4.57c: supR3HardNtViCallWinVerifyTrustCatFile: New context 000000000136ecf0
6686e4.57c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000136ecf0
6696e4.57c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=E3D8AF7C786FEA745EBC3F0965B6CCC901373C14
6706e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
6716e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\rpcrt4.dll (Input=rpcrt4.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
6726e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd46f90000 'C:\Windows\System32\rpcrt4.dll'
6736e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
6746e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
6756e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
6766e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
6776e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
6786e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
6796e4.57c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_590_for_KB4493509~31bf3856ad364e35~amd64~~10.0.1.6.cat'; file='\SystemRoot\System32\ntdll.dll'
6806e4.57c: g_pfnWinVerifyTrust=00007ffd44ea6370
6816e4.57c: supR3HardenedScreenImage/preload: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll [redoing WinVerifyTrust]
6826e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
6836e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
6846e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
6856e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
6866e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
6876e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
6886e4.57c: supR3HardenedScreenImage/preload: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\crypt32.dll'
6896e4.57c: supR3HardenedScreenImage/preload: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wintrust.dll [redoing WinVerifyTrust]
6906e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
6916e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
6926e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
6936e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll
6946e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
6956e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
6966e4.57c: supR3HardenedScreenImage/preload: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\wintrust.dll'
6976e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
6986e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
6996e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
7006e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
7016e4.57c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\advapi32.dll'
7026e4.57c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000398 pwszName=\Device\HarddiskVolume3\Windows\System32\cryptnet.dll
7036e4.57c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000136ecf0
7046e4.57c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000136ecf0
7056e4.57c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=A71FAF93E7F6555CF5752D6A603A870E378E49E6
7066e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
7076e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
7086e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
7096e4.57c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0316~31bf3856ad364e35~amd64~~10.0.17763.1.cat'; file='\Device\HarddiskVolume3\Windows\System32\cryptnet.dll'
7106e4.57c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
7116e4.57c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\cryptnet.dll'
7126e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
7136e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
7146e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
7156e4.57c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\profapi.dll'
7166e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
7176e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
7186e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
7196e4.57c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\gpapi.dll'
7206e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
7216e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
7226e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
7236e4.57c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\sechost.dll'
7246e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
7256e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
7266e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
7276e4.57c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\imagehlp.dll'
7286e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
7296e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
7306e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
7316e4.57c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\cryptbase.dll'
7326e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
7336e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
7346e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll
7356e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
7366e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
7376e4.57c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\rsaenh.dll'
7386e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll
7396e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
7406e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
7416e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
7426e4.57c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\cryptsp.dll'
7436e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
7446e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
7456e4.57c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\bcryptprimitives.dll'
7466e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
7476e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
7486e4.57c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\bcrypt.dll'
7496e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
7506e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
7516e4.57c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\ucrtbase.dll'
7526e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
7536e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
7546e4.57c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll'
7556e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
7566e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
7576e4.57c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\msasn1.dll'
7586e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
7596e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
7606e4.57c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll'
7616e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
7626e4.57c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 24202) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSupLib.dll'
7636e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
7646e4.57c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 24202) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe'
7656e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
7666e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
7676e4.57c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\KernelBase.dll'
7686e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
7696e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
7706e4.57c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\kernel32.dll'
7716e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\system32\crypt32.dll'
7726e4.57c: supR3HardenedWinIsDesiredRootCA: Adding 0x5ad46780fa5df300 DC=com, DC=microsoft, CN=Microsoft Root Certificate Authority
7736e4.57c: supR3HardenedWinIsDesiredRootCA: Adding 0xea5386456178582b C=ZA, ST=Western Cape, L=Durbanville, O=Thawte, OU=Thawte Certification, CN=Thawte Timestamping CA
7746e4.57c: supR3HardenedWinIsDesiredRootCA: Adding 0x3be670c1bd02a900 OU=Copyright (c) 1997 Microsoft Corp., OU=Microsoft Corporation, CN=Microsoft Root Authority
7756e4.57c: supR3HardenedWinIsDesiredRootCA: Adding 0xe991ee72b03db500 C=US, O=Symantec Corporation, CN=Symantec Enterprise Mobile Root for Microsoft
7766e4.57c: supR3HardenedWinIsDesiredRootCA: Adding 0x4d3835aa4180b200 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2011
7776e4.57c: supR3HardenedWinIsDesiredRootCA: Adding 0x646e3fe3ba08df00 C=US, O=MSFT, CN=Microsoft Authenticode(tm) Root Authority
7786e4.57c: supR3HardenedWinIsDesiredRootCA: Adding 0xece4e4289e08b900 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010
7796e4.57c: supR3HardenedWinIsDesiredRootCA: Adding 0x3401b15e3761c700 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2008 VeriSign, Inc. - For authorized use only, CN=VeriSign Universal Root Certification Authority
7806e4.57c: supR3HardenedWinIsDesiredRootCA: Adding 0xf3bb4d7e894b420 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft ECC TS Root Certificate Authority 2018
7816e4.57c: supR3HardenedWinIsDesiredRootCA: Adding 0x43a9cc371ff5385a O=Microsoft Trust Network, OU=Microsoft Corporation, OU=Microsoft Time Stamping Service Root, OU=Copyright (c) 1997 Microsoft Corp.
7826e4.57c: supR3HardenedWinIsDesiredRootCA: Adding 0x2e2d2c7c68f0202e O=VeriSign Trust Network, OU=VeriSign, Inc., OU=VeriSign Time Stamping Service Root, OU=NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.
7836e4.57c: supR3HardenedWinIsDesiredRootCA: Adding 0xcec3d46562b9be8e C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft ECC Product Root Certificate Authority 2018
7846e4.57c: supR3HardenedWinIsDesiredRootCA: Adding 0x61a3a33f81aace00 C=US, ST=UT, L=Salt Lake City, O=The USERTRUST Network, OU=http://www.usertrust.com, CN=UTN-USERFirst-Object
7856e4.57c: supR3HardenedWinIsDesiredRootCA: Adding 0x6b7bdc34cd37bb00 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root G2
7866e4.57c: supR3HardenedWinIsDesiredRootCA: Adding 0x57ba5395b561bf00 C=BM, O=QuoVadis Limited, OU=Root Certification Authority, CN=QuoVadis Root Certification Authority
7876e4.57c: supR3HardenedWinIsDesiredRootCA: Adding 0x83085097e9afdf00 O=Digital Signature Trust Co., CN=DST Root CA X3
7886e4.57c: supR3HardenedWinIsDesiredRootCA: Adding 0x780679907625cc00 OU=GlobalSign Root CA - R3, O=GlobalSign, CN=GlobalSign
7896e4.57c: supR3HardenedWinIsDesiredRootCA: Adding 0x3d98ab22bb04a300 C=IE, O=Baltimore, OU=CyberTrust, CN=Baltimore CyberTrust Root
7906e4.57c: supR3HardenedWinIsDesiredRootCA: Adding 0x8ff6fc03c1edbd00 C=US, ST=Arizona, L=Scottsdale, O=Starfield Technologies, Inc., CN=Starfield Root Certificate Authority - G2
7916e4.57c: supR3HardenedWinIsDesiredRootCA: Adding 0xc6fa4243b695b600 C=US, O=Entrust, Inc., OU=www.entrust.net/CPS is incorporated by reference, OU=(c) 2006 Entrust, Inc., CN=Entrust Root Certification Authority
7926e4.57c: supR3HardenedWinIsDesiredRootCA: Adding 0xa3ce8d99e60eda00 C=BE, O=GlobalSign nv-sa, OU=Root CA, CN=GlobalSign Root CA
7936e4.57c: supR3HardenedWinIsDesiredRootCA: Adding 0x560ad29254e89100 C=GB, ST=Greater Manchester, L=Salford, O=COMODO CA Limited, CN=COMODO RSA Certification Authority
7946e4.57c: supR3HardenedWinIsDesiredRootCA: Adding 0xa671e9fec832b700 C=US, O=Starfield Technologies, Inc., OU=Starfield Class 2 Certification Authority
7956e4.57c: supR3HardenedWinIsDesiredRootCA: Adding 0xa8de7211e13be200 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root CA
7966e4.57c: supR3HardenedWinIsDesiredRootCA: Adding 0xf5cd95e581a4ab00 C=US, O=SecureTrust Corporation, CN=SecureTrust CA
7976e4.57c: supR3HardenedWinIsDesiredRootCA: Adding 0x6f2ebe0e24cfa600 OU=GlobalSign Root CA - R2, O=GlobalSign, CN=GlobalSign
7986e4.57c: supR3HardenedWinIsDesiredRootCA: Adding 0x14018a1bf29e595c C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority
7996e4.57c: supR3HardenedWinIsDesiredRootCA: Adding 0x7c4fd32ec1b1ce00 C=PL, O=Unizeto Sp. z o.o., CN=Certum CA
8006e4.57c: supR3HardenedWinIsDesiredRootCA: Adding 0xd4fbe673e5ccc600 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA
8016e4.57c: supR3HardenedWinIsDesiredRootCA: Adding 0xef477acf4ab2d300 C=DE, O=D-Trust GmbH, CN=D-TRUST Root Class 3 CA 2 2009
8026e4.57c: supR3HardenedWinIsDesiredRootCA: Adding 0x1b8578514b74ac00 C=US, O=WFA Hotspot 2.0, CN=Hotspot 2.0 Trust Root CA - 03
8036e4.57c: supR3HardenedWinIsDesiredRootCA: Adding 0x357a29080824af00 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2006 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G5
8046e4.57c: supR3HardenedWinIsDesiredRootCA: Adding 0x59faf1086271bf00 C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com, Inc., CN=Go Daddy Root Certificate Authority - G2
8056e4.57c: supR3HardenedWinIsDesiredRootCA: Adding 0x3401b15e3761c700 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2008 VeriSign, Inc. - For authorized use only, CN=VeriSign Universal Root Certification Authority
8066e4.57c: supR3HardenedWinIsDesiredRootCA: Adding 0xc30e361765128000 C=US, ST=New Jersey, L=Jersey City, O=The USERTRUST Network, CN=USERTrust RSA Certification Authority
8076e4.57c: supR3HardenedWinIsDesiredRootCA: Adding 0x491857ead79dde00 C=US, O=The Go Daddy Group, Inc., OU=Go Daddy Class 2 Certification Authority
8086e4.57c: supR3HardenedWinIsDesiredRootCA: Adding 0xc2ba72a37dfbe300 C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Trusted Network CA
8096e4.57c: supR3HardenedWinIsDesiredRootCA: Adding 0x8043e4ce150ead00 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID Root CA
8106e4.57c: supR3HardenedWinIsDesiredRootCA: Adding 0xf2e6331af7b700 C=SE, O=AddTrust AB, OU=AddTrust External TTP Network, CN=AddTrust External CA Root
8116e4.57c: supR3HardenedWinRetrieveTrustedRootCAs: cAdded=39
8126e4.57c: SUPR3HardenedMain: Load Runtime...
8136e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
8146e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
8156e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
8166e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rpcrt4.dll'.
8176e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ws2_32.dll'.
8186e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll) WinVerifyTrust
8196e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll
8206e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
8216e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
8226e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
8236e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
8246e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'rpcrt4.dll'.
8256e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\ws2_32.dll) WinVerifyTrust
8266e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\ws2_32.dll
8276e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
8286e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
8296e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll
8306e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
8316e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
8326e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
8336e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
8346e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll
8356e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
8366e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
8376e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll) WinVerifyTrust
8386e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll
8396e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
8406e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
8416e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
8426e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
8436e4.57c: Detected WinVerifyTrust recursion: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
8446e4.57c: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll)
8456e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll
8466e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
8476e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll) WinVerifyTrust
8486e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000a01:<flags> [calling]
8496e4.57c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll
8506e4.57c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll [avoiding WinVerifyTrust]
8516e4.57c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll
8526e4.57c: supR3HardenedDllNotificationCallback: load 00000000676d0000 LB 0x000d2000 C:\Program Files\Oracle\VirtualBox\MSVCR100.dll [fFlags=0x0]
8536e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll [avoiding WinVerifyTrust]
8546e4.57c: supR3HardenedDllNotificationCallback: load 00000000670c0000 LB 0x00098000 C:\Program Files\Oracle\VirtualBox\MSVCP100.dll [fFlags=0x0]
8556e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll
8566e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd459c0000 LB 0x0006d000 C:\Windows\System32\WS2_32.dll [fFlags=0x0]
8576e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ws2_32.dll
8586e4.57c: supR3HardenedDllNotificationCallback: load 00007ffcde430000 LB 0x0052f000 C:\Program Files\Oracle\VirtualBox\VBoxRT.dll [fFlags=0x0]
8596e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll
8606e4.57c: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
8616e4.57c: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
8626e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll
8636e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
8646e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcde430000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
8656e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll
8666e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
8676e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcde430000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
8686e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll
8696e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
8706e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcde430000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
8716e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll
8726e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
8736e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcde430000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
8746e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll
8756e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
8766e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcde430000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
8776e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll
8786e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
8796e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcde430000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
8806e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcde430000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
8816e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcde430000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
8826e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcde430000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
8836e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcde430000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
8846e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcde430000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
8856e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcde430000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
8866e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcde430000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
8876e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll
8886e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
8896e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcde430000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
8906e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcde430000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
8916e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcde430000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
8926e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcde430000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
8936e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcde430000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
8946e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcde430000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
8956e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcde430000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
8966e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcde430000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
8976e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcde430000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
8986e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcde430000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
8996e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcde430000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9006e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcde430000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9016e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcde430000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9026e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcde430000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9036e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcde430000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9046e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcde430000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9056e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll
9066e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9076e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcde430000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9086e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcde430000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9096e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcde430000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9106e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcde430000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9116e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wintrust.dll
9126e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
9136e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44ea0000 'C:\Windows\system32\Wintrust.dll'
9146e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
9156e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
9166e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll
9176e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9186e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
9196e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
9206e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\system32\crypt32.dll'
9216e4.57c: SUPR3HardenedMain: Load TrustedMain...
9226e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
9236e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'opengl32.dll'.
9246e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxglobal.dll'.
9256e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
9266e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcp100.dll'.
9276e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msvcr100.dll'.
9286e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'qt5corevbox.dll'.
9296e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'qt5guivbox.dll'.
9306e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'qt5widgetsvbox.dll'.
9316e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'qt5openglvbox.dll'.
9326e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'user32.dll'.
9336e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'ole32.dll'.
9346e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'oleaut32.dll'.
9356e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'winmm.dll'.
9366e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll) WinVerifyTrust
9376e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll
9386e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
9396e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume3\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
9406e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
9416e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
9426e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'winmmbase.dll'.
9436e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msvcrt.dll'.
9446e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\winmm.dll) WinVerifyTrust
9456e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\winmm.dll
9466e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
9476e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume3\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
9486e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
9496e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
9506e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll
9516e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmmbase.dll'...
9526e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmmbase.dll' -> '\Device\HarddiskVolume3\Windows\System32\winmmbase.dll' [rcNtRedir=0xc0150008]
9536e4.57c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\winmmbase.dll'.
9546e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
9556e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\winmmbase.dll)
9566e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\winmmbase.dll
9576e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
9586e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
9596e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll
9606e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
9616e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll
9626e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9636e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
9646e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
9656e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'combase.dll'.
9666e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'rpcrt4.dll'.
9676e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\oleaut32.dll) WinVerifyTrust
9686e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\oleaut32.dll
9696e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
9706e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
9716e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
9726e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
9736e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll
9746e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
9756e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
9766e4.57c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\combase.dll'.
9776e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rpcrt4.dll'.
9786e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #46 'bcryptprimitives.dll'.
9796e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\combase.dll)
9806e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\combase.dll
9816e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
9826e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
9836e4.57c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll'.
9846e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll)
9856e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\msvcp_win.dll
9866e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcryptprimitives.dll'...
9876e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcryptprimitives.dll' -> '\Device\HarddiskVolume3\Windows\System32\bcryptprimitives.dll' [rcNtRedir=0xc0150008]
9886e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\bcryptprimitives.dll
9896e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
9906e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
9916e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
9926e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
9936e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'rpcrt4.dll'.
9946e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #55 'gdi32.dll'.
9956e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #56 'user32.dll'.
9966e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #57 'combase.dll'.
9976e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\ole32.dll) WinVerifyTrust
9986e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\ole32.dll
9996e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
10006e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
10016e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
10026e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
10036e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\combase.dll [lacks WinVerifyTrust]
10046e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
10056e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
10066e4.57c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\user32.dll'.
10076e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'win32u.dll'.
10086e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #34 'gdi32.dll'.
10096e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\user32.dll)
10106e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\user32.dll
10116e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
10126e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
10136e4.57c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32.dll'.
10146e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\gdi32.dll)
10156e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\gdi32.dll
10166e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
10176e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
10186e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
10196e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
10206e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
10216e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
10226e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
10236e4.57c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\win32u.dll'.
10246e4.57c: '\Device\HarddiskVolume3\Windows\System32\win32u.dll' has no imports
10256e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\win32u.dll)
10266e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\win32u.dll
10276e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
10286e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
10296e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'win32u.dll'.
10306e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #34 'gdi32.dll'.
10316e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\user32.dll) WinVerifyTrust
10326e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5openglvbox.dll'...
10336e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5openglvbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5openglvbox.dll' [rcNtRedir=0xc0150008]
10346e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
10356e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
10366e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
10376e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
10386e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
10396e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\win32u.dll [lacks WinVerifyTrust]
10406e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
10416e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'qt5widgetsvbox.dll'.
10426e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'qt5guivbox.dll'.
10436e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5corevbox.dll'.
10446e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcr100.dll'.
10456e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll) WinVerifyTrust
10466e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll
10476e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
10486e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
10496e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
10506e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
10516e4.57c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
10526e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
10536e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
10546e4.57c: Detected WinVerifyTrust recursion: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll'.
10556e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
10566e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'shell32.dll'.
10576e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ole32.dll'.
10586e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
10596e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ws2_32.dll'.
10606e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'mpr.dll'.
10616e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'msvcp100.dll'.
10626e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'msvcr100.dll'.
10636e4.57c: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll)
10646e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
10656e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
10666e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
10676e4.57c: Detected WinVerifyTrust recursion: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll'.
10686e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ole32.dll'.
10696e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'opengl32.dll'.
10706e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
10716e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
10726e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qt5corevbox.dll'.
10736e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcp100.dll'.
10746e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcr100.dll'.
10756e4.57c: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll)
10766e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
10776e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
10786e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
10796e4.57c: Detected WinVerifyTrust recursion: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll'.
10806e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
10816e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
10826e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5guivbox.dll'.
10836e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qt5corevbox.dll'.
10846e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'shell32.dll'.
10856e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcp100.dll'.
10866e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcr100.dll'.
10876e4.57c: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll)
10886e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll
10896e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
10906e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
10916e4.57c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
10926e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
10936e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
10946e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll
10956e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
10966e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume3\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
10976e4.57c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\shell32.dll'.
10986e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
10996e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #75 'user32.dll'.
11006e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #77 'gdi32.dll'.
11016e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\shell32.dll)
11026e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\shell32.dll
11036e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
11046e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
11056e4.57c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [lacks WinVerifyTrust]
11066e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
11076e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
11086e4.57c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll [lacks WinVerifyTrust]
11096e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
11106e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
11116e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\user32.dll [lacks WinVerifyTrust]
11126e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
11136e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
11146e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
11156e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
11166e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
11176e4.57c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
11186e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
11196e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
11206e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll
11216e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
11226e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
11236e4.57c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [lacks WinVerifyTrust]
11246e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
11256e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
11266e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\user32.dll [lacks WinVerifyTrust]
11276e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
11286e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
11296e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
11306e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
11316e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume3\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
11326e4.57c: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume3\Windows\System32\opengl32.dll'.
11336e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
11346e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
11356e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
11366e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
11376e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'glu32.dll'.
11386e4.57c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\opengl32.dll)
11396e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\opengl32.dll
11406e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
11416e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
11426e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ole32.dll
11436e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
11446e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
11456e4.57c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
11466e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
11476e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
11486e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll
11496e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mpr.dll'...
11506e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'mpr.dll' -> '\Device\HarddiskVolume3\Windows\System32\mpr.dll' [rcNtRedir=0xc0150008]
11516e4.57c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\mpr.dll'.
11526e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\mpr.dll)
11536e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\mpr.dll
11546e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
11556e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
11566e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ws2_32.dll
11576e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
11586e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
11596e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\advapi32.dll
11606e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
11616e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
11626e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ole32.dll
11636e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
11646e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume3\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
11656e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shell32.dll [lacks WinVerifyTrust]
11666e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
11676e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
11686e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\user32.dll [lacks WinVerifyTrust]
11696e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'glu32.dll'...
11706e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'glu32.dll' -> '\Device\HarddiskVolume3\Windows\System32\glu32.dll' [rcNtRedir=0xc0150008]
11716e4.57c: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume3\Windows\System32\glu32.dll'.
11726e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
11736e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
11746e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'opengl32.dll'.
11756e4.57c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\glu32.dll)
11766e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\glu32.dll
11776e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
11786e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
11796e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
11806e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
11816e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
11826e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\user32.dll [lacks WinVerifyTrust]
11836e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
11846e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
11856e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\advapi32.dll
11866e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
11876e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
11886e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll
11896e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
11906e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
11916e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
11926e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
11936e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
11946e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\user32.dll [lacks WinVerifyTrust]
11956e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
11966e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
11976e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll
11986e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
11996e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume3\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
12006e4.57c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\opengl32.dll [lacks WinVerifyTrust]
12016e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
12026e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
12036e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\user32.dll [lacks WinVerifyTrust]
12046e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
12056e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
12066e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
12076e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
12086e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
12096e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5guivbox.dll'.
12106e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qt5corevbox.dll'.
12116e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'shell32.dll'.
12126e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcp100.dll'.
12136e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcr100.dll'.
12146e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll) WinVerifyTrust
12156e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
12166e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
12176e4.57c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll [redoing WinVerifyTrust]
12186e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
12196e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
12206e4.57c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
12216e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
12226e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
12236e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll
12246e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
12256e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume3\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
12266e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shell32.dll [lacks WinVerifyTrust]
12276e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
12286e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
12296e4.57c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [lacks WinVerifyTrust]
12306e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
12316e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
12326e4.57c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll [lacks WinVerifyTrust]
12336e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
12346e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
12356e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\user32.dll [lacks WinVerifyTrust]
12366e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
12376e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
12386e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
12396e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
12406e4.57c: supR3HardenedScreenImage/Imports: 0 (was 24202) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll'
12416e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
12426e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
12436e4.57c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [redoing WinVerifyTrust]
12446e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
12456e4.57c: supR3HardenedScreenImage/Imports: 0 (was 24202) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll'
12466e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
12476e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
12486e4.57c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll [redoing WinVerifyTrust]
12496e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
12506e4.57c: supR3HardenedScreenImage/Imports: 0 (was 24202) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'
12516e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
12526e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
12536e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll
12546e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
12556e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
12566e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxglobal.dll'...
12576e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxglobal.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxglobal.dll' [rcNtRedir=0xc0150008]
12586e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
12596e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'vboxrt.dll'.
12606e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcr100.dll'.
12616e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5corevbox.dll'.
12626e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qt5guivbox.dll'.
12636e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qt5widgetsvbox.dll'.
12646e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
12656e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'advapi32.dll'.
12666e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'ole32.dll'.
12676e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'oleaut32.dll'.
12686e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'rpcrt4.dll'.
12696e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxGlobal.dll) WinVerifyTrust
12706e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxGlobal.dll
12716e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
12726e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume3\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
12736e4.57c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\opengl32.dll [redoing WinVerifyTrust]
12746e4.57c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004a8 pwszName=\Device\HarddiskVolume3\Windows\System32\opengl32.dll
12756e4.57c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000136ecf0
12766e4.57c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000136ecf0
12776e4.57c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F9EA7A084F8D34EE062D8C0EF5D96EF865883D56
12786e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
12796e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
12806e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
12816e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume3\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
12826e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\oleaut32.dll
12836e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
12846e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
12856e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ole32.dll
12866e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
12876e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
12886e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\advapi32.dll
12896e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
12906e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
12916e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\user32.dll [lacks WinVerifyTrust]
12926e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
12936e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
12946e4.57c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll [lacks WinVerifyTrust]
12956e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
12966e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
12976e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
12986e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
12996e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
13006e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
13016e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
13026e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
13036e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
13046e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
13056e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
13066e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
13076e4.57c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0112~31bf3856ad364e35~amd64~~10.0.17763.1.cat'; file='\Device\HarddiskVolume3\Windows\System32\opengl32.dll'
13086e4.57c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
13096e4.57c: supR3HardenedScreenImage/Imports: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\opengl32.dll'
13106e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000a01:<flags> [calling]
13116e4.57c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll
13126e4.57c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\opengl32.dll
13136e4.57c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxGlobal.dll
13146e4.57c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
13156e4.57c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
13166e4.57c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll [avoiding WinVerifyTrust]
13176e4.57c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll
13186e4.57c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winmm.dll
13196e4.57c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\glu32.dll [avoiding WinVerifyTrust]
13206e4.57c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\mpr.dll [avoiding WinVerifyTrust]
13216e4.57c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winmmbase.dll [avoiding WinVerifyTrust]
13226e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd44e30000 LB 0x00020000 C:\Windows\System32\win32u.dll [fFlags=0x0]
13236e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\win32u.dll [avoiding WinVerifyTrust]
13246e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd44640000 LB 0x000a0000 C:\Windows\System32\msvcp_win.dll [fFlags=0x0]
13256e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcp_win.dll [avoiding WinVerifyTrust]
13266e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd443f0000 LB 0x0019a000 C:\Windows\System32\gdi32full.dll [fFlags=0x0]
13276e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
13286e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #33 'gdi32.dll'.
13296e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #35 'user32.dll'.
13306e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #36 'win32u.dll'.
13316e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\gdi32full.dll)
13326e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\gdi32full.dll
13336e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd45760000 LB 0x00029000 C:\Windows\System32\GDI32.dll [fFlags=0x0]
13346e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [avoiding WinVerifyTrust]
13356e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd48150000 LB 0x00197000 C:\Windows\System32\USER32.dll [fFlags=0x0]
13366e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\user32.dll [avoiding WinVerifyTrust]
13376e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd33480000 LB 0x0002c000 C:\Windows\SYSTEM32\GLU32.dll [fFlags=0x0]
13386e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\glu32.dll [avoiding WinVerifyTrust]
13396e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd314d0000 LB 0x00127000 C:\Windows\SYSTEM32\OPENGL32.dll [fFlags=0x0]
13406e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\opengl32.dll
13416e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd44e50000 LB 0x0004a000 C:\Windows\System32\cfgmgr32.dll [fFlags=0x0]
13426e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\cfgmgr32.dll)
13436e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\cfgmgr32.dll
13446e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd47c60000 LB 0x0032c000 C:\Windows\System32\combase.dll [fFlags=0x0]
13456e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\combase.dll [avoiding WinVerifyTrust]
13466e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd458e0000 LB 0x000a8000 C:\Windows\System32\shcore.dll [fFlags=0x0]
13476e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
13486e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #36 'rpcrt4.dll'.
13496e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #43 'combase.dll'.
13506e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\SHCore.dll)
13516e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\SHCore.dll
13526e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd44360000 LB 0x0005d000 C:\Windows\System32\powrprof.dll [fFlags=0x0]
13536e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'rpcrt4.dll'.
13546e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\powrprof.dll)
13556e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\powrprof.dll
13566e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd47810000 LB 0x00052000 C:\Windows\System32\shlwapi.dll [fFlags=0x0]
13576e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
13586e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #44 'gdi32.dll'.
13596e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #45 'user32.dll'.
13606e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\shlwapi.dll)
13616e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\shlwapi.dll
13626e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd44340000 LB 0x00011000 C:\Windows\System32\kernel.appcore.dll [fFlags=0x0]
13636e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'msvcrt.dll'.
13646e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'rpcrt4.dll'.
13656e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\kernel.appcore.dll)
13666e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\kernel.appcore.dll
13676e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd446e0000 LB 0x0074a000 C:\Windows\System32\windows.storage.dll [fFlags=0x0]
13686e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #31 'combase.dll'.
13696e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #32 'msvcp_win.dll'.
13706e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #39 'rpcrt4.dll'.
13716e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #56 'profapi.dll'.
13726e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\windows.storage.dll)
13736e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\windows.storage.dll
13746e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd45aa0000 LB 0x014f0000 C:\Windows\System32\SHELL32.dll [fFlags=0x0]
13756e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shell32.dll [avoiding WinVerifyTrust]
13766e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd47ff0000 LB 0x00155000 C:\Windows\System32\ole32.dll [fFlags=0x0]
13776e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ole32.dll
13786e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd34e60000 LB 0x0001b000 C:\Windows\SYSTEM32\MPR.dll [fFlags=0x0]
13796e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\mpr.dll [avoiding WinVerifyTrust]
13806e4.57c: supR3HardenedDllNotificationCallback: load 0000000067160000 LB 0x00565000 C:\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [fFlags=0x0]
13816e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
13826e4.57c: supR3HardenedDllNotificationCallback: load 00007ffcdbac0000 LB 0x005f7000 C:\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll [fFlags=0x0]
13836e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
13846e4.57c: supR3HardenedDllNotificationCallback: load 0000000066440000 LB 0x00561000 C:\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll [fFlags=0x0]
13856e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll [avoiding WinVerifyTrust]
13866e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd45680000 LB 0x000c4000 C:\Windows\System32\OLEAUT32.dll [fFlags=0x0]
13876e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\oleaut32.dll
13886e4.57c: supR3HardenedDllNotificationCallback: load 00007ffcdc0c0000 LB 0x0236b000 C:\Program Files\Oracle\VirtualBox\VBoxGlobal.dll [fFlags=0x0]
13896e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxGlobal.dll
13906e4.57c: supR3HardenedDllNotificationCallback: load 0000000066c70000 LB 0x00054000 C:\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll [fFlags=0x0]
13916e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll
13926e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd41de0000 LB 0x0002d000 C:\Windows\SYSTEM32\WINMMBASE.dll [fFlags=0x0]
13936e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winmmbase.dll [avoiding WinVerifyTrust]
13946e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd41f30000 LB 0x00024000 C:\Windows\SYSTEM32\WINMM.dll [fFlags=0x0]
13956e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winmm.dll
13966e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd072d0000 LB 0x00188000 C:\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll [fFlags=0x0]
13976e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll
13986e4.57c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\windows.storage.dll'.
13996e4.57c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\windows.storage.dll' [rescheduled]
14006e4.57c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\kernel.appcore.dll'.
14016e4.57c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\kernel.appcore.dll' [rescheduled]
14026e4.57c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\shlwapi.dll'.
14036e4.57c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\shlwapi.dll' [rescheduled]
14046e4.57c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\powrprof.dll'.
14056e4.57c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\powrprof.dll' [rescheduled]
14066e4.57c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\SHCore.dll'.
14076e4.57c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\SHCore.dll' [rescheduled]
14086e4.57c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\cfgmgr32.dll'.
14096e4.57c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\cfgmgr32.dll' [rescheduled]
14106e4.57c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll'.
14116e4.57c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll' [rescheduled]
14126e4.57c: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume3\Windows\System32\glu32.dll'.
14136e4.57c: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\glu32.dll' [rescheduled]
14146e4.57c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\mpr.dll'.
14156e4.57c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\mpr.dll' [rescheduled]
14166e4.57c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\shell32.dll'.
14176e4.57c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\shell32.dll' [rescheduled]
14186e4.57c: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll'.
14196e4.57c: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll' [rescheduled]
14206e4.57c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\win32u.dll'.
14216e4.57c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rescheduled]
14226e4.57c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32.dll'.
14236e4.57c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rescheduled]
14246e4.57c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\user32.dll'.
14256e4.57c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rescheduled]
14266e4.57c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll'.
14276e4.57c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rescheduled]
14286e4.57c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\combase.dll'.
14296e4.57c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rescheduled]
14306e4.57c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\winmmbase.dll'.
14316e4.57c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\winmmbase.dll' [rescheduled]
14326e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\kernel32.dll
14336e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'profapi.dll'...
14346e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'profapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\profapi.dll' [rcNtRedir=0xc0150008]
14356e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\profapi.dll
14366e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
14376e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
14386e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
14396e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
14406e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcp_win.dll [redoing WinVerifyTrust]
14416e4.57c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll'.
14426e4.57c: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume3\Windows\System32\msvcp_win.dll
14436e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
14446e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
14456e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\combase.dll [redoing WinVerifyTrust]
14466e4.57c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\combase.dll'.
14476e4.57c: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume3\Windows\System32\combase.dll
14486e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
14496e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
14506e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
14516e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
14526e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
14536e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
14546e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\user32.dll [redoing WinVerifyTrust]
14556e4.57c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\user32.dll'.
14566e4.57c: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume3\Windows\System32\user32.dll
14576e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
14586e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
14596e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [redoing WinVerifyTrust]
14606e4.57c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32.dll'.
14616e4.57c: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume3\Windows\System32\gdi32.dll
14626e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
14636e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
14646e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
14656e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
14666e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
14676e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
14686e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\combase.dll [redoing WinVerifyTrust]
14696e4.57c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\combase.dll'.
14706e4.57c: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume3\Windows\System32\combase.dll
14716e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
14726e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
14736e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
14746e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
14756e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
14766e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
14776e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\win32u.dll [redoing WinVerifyTrust]
14786e4.57c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\win32u.dll'.
14796e4.57c: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume3\Windows\System32\win32u.dll
14806e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
14816e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
14826e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\user32.dll [redoing WinVerifyTrust]
14836e4.57c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\user32.dll'.
14846e4.57c: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume3\Windows\System32\user32.dll
14856e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
14866e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
14876e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [redoing WinVerifyTrust]
14886e4.57c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32.dll'.
14896e4.57c: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume3\Windows\System32\gdi32.dll
14906e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
14916e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
14926e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcp_win.dll [redoing WinVerifyTrust]
14936e4.57c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll'.
14946e4.57c: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume3\Windows\System32\msvcp_win.dll
14956e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\kernel32.dll (Input=kernel32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
14966e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd47ba0000 'C:\Windows\System32\kernel32.dll'
14976e4.57c: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-string-l1-1-0) -> 0x0, fPresent=1
14986e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-string-l1-1-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
14996e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd45160000 'api-ms-win-core-string-l1-1-0'
15006e4.57c: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-datetime-l1-1-1) -> 0x0, fPresent=1
15016e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-datetime-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
15026e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd45160000 'api-ms-win-core-datetime-l1-1-1'
15036e4.57c: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-obsolete-l1-2-0) -> 0x0, fPresent=1
15046e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-obsolete-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
15056e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd45160000 'api-ms-win-core-localization-obsolete-l1-2-0'
15066e4.57c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\imm32.dll'.
15076e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'user32.dll'.
15086e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'win32u.dll'.
15096e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\imm32.dll)
15106e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\imm32.dll
15116e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
15126e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
15136e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\win32u.dll [redoing WinVerifyTrust]
15146e4.57c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\win32u.dll'.
15156e4.57c: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume3\Windows\System32\win32u.dll
15166e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
15176e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
15186e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\user32.dll [redoing WinVerifyTrust]
15196e4.57c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\user32.dll'.
15206e4.57c: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume3\Windows\System32\user32.dll
15216e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\IMM32.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
15226e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd45990000 LB 0x0002e000 C:\Windows\System32\IMM32.DLL [fFlags=0x0]
15236e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\imm32.dll [avoiding WinVerifyTrust]
15246e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd45990000 'C:\Windows\system32\IMM32.DLL'
15256e4.57c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\imm32.dll'.
15266e4.57c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\imm32.dll' [rescheduled]
15276e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\advapi32.dll
15286e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\ADVAPI32.DLL (Input=ADVAPI32.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
15296e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd45550000 'C:\Windows\System32\ADVAPI32.DLL'
15306e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd072d0000 'C:\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll'
15316e4.57c: SUPR3HardenedMain: Calling TrustedMain (00007ffd072d16c0)...
15326e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
15336e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
15346e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'ole32.dll'.
15356e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
15366e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'imm32.dll'.
15376e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'winmm.dll'.
15386e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
15396e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'shell32.dll'.
15406e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'advapi32.dll'.
15416e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'qt5guivbox.dll'.
15426e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'qt5corevbox.dll'.
15436e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'msvcr100.dll'.
15446e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\platforms\qwindows.dll) WinVerifyTrust
15456e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\platforms\qwindows.dll
15466e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
15476e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
15486e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
15496e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
15506e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
15516e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
15526e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
15536e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
15546e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
15556e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
15566e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\advapi32.dll
15576e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
15586e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume3\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
15596e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shell32.dll [redoing WinVerifyTrust]
15606e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
15616e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
15626e4.57c: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\shell32.dll'
15636e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
15646e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume3\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
15656e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\oleaut32.dll
15666e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
15676e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume3\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
15686e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winmm.dll
15696e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
15706e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume3\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
15716e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\imm32.dll [redoing WinVerifyTrust]
15726e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
15736e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
15746e4.57c: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\imm32.dll'
15756e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
15766e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
15776e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\user32.dll [redoing WinVerifyTrust]
15786e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
15796e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
15806e4.57c: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\user32.dll'
15816e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
15826e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
15836e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ole32.dll
15846e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
15856e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
15866e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [redoing WinVerifyTrust]
15876e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
15886e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
15896e4.57c: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\gdi32.dll'
15906e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\platforms\qwindows.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
15916e4.57c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\platforms\qwindows.dll
15926e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd193d0000 LB 0x0012e000 C:\Program Files\Oracle\VirtualBox\platforms\qwindows.dll [fFlags=0x0]
15936e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\platforms\qwindows.dll
15946e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd193d0000 'C:\Program Files\Oracle\VirtualBox\platforms\qwindows.dll'
15956e4.57c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000061c pwszName=\Device\HarddiskVolume3\Windows\System32\uxtheme.dll
15966e4.57c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000136ecf0
15976e4.57c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000136ecf0
15986e4.57c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=9E9C9DBAFB6FF286F236C72F471A61F524EAC54D
15996e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
16006e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
16016e4.57c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0315~31bf3856ad364e35~amd64~~10.0.17763.1.cat'; file='\Device\HarddiskVolume3\Windows\System32\uxtheme.dll'
16026e4.57c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
16036e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
16046e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #33 'gdi32.dll'.
16056e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #34 'user32.dll'.
16066e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\uxtheme.dll) WinVerifyTrust
16076e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\uxtheme.dll
16086e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
16096e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
16106e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
16116e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
16126e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
16136e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
16146e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
16156e4.57c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\uxtheme.dll
16166e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd42310000 LB 0x0009c000 C:\Windows\system32\uxtheme.dll [fFlags=0x0]
16176e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\uxtheme.dll
16186e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd42310000 'C:\Windows\system32\uxtheme.dll'
16196e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd48150000 'C:\Windows\system32\user32.dll'
16206e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shell32.dll
16216e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
16226e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd45aa0000 'C:\Windows\system32\shell32.dll'
16236e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\SHCore.dll [redoing WinVerifyTrust]
16246e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
16256e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
16266e4.57c: supR3HardenedScreenImage/LdrLoadDll: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\SHCore.dll'
16276e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\SHCore.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
16286e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd458e0000 'C:\Windows\system32\SHCore.dll'
16296e4.57c: supR3HardenedMonitor_LdrLoadDll: error opening 'C:\Windows\system32\wintab32.dll': 0 (NtPath=\??\C:\Windows\system32\wintab32.dll; Input=C:\Windows\system32\wintab32.dll; rcNtGetDll=0x0
16306e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000034 'C:\Windows\system32\wintab32.dll'
16316e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
16326e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'crypt32.dll'.
16336e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'cryptsp.dll'.
16346e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'win32u.dll'.
16356e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 'user32.dll'.
16366e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #28 'gdi32.dll'.
16376e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\dwmapi.dll)
16386e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\dwmapi.dll
16396e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd425f0000 LB 0x0002e000 C:\Windows\system32\dwmapi.dll [fFlags=0x0]
16406e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dwmapi.dll [avoiding WinVerifyTrust]
16416e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
16426e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
16436e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
16446e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
16456e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\user32.dll
16466e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
16476e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
16486e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\win32u.dll [lacks WinVerifyTrust]
16496e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cryptsp.dll'...
16506e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'cryptsp.dll' -> '\Device\HarddiskVolume3\Windows\System32\cryptsp.dll' [rcNtRedir=0xc0150008]
16516e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\cryptsp.dll
16526e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
16536e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume3\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
16546e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
16556e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
16566e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
16576e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
16586e4.57c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\dwmapi.dll'
16596e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winmm.dll
16606e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\winmm.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
16616e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd41f30000 'C:\Windows\system32\winmm.dll'
16626e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winmm.dll
16636e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\winmm.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
16646e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd41f30000 'C:\Windows\system32\winmm.dll'
16656e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shell32.dll
16666e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
16676e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd45aa0000 'C:\Windows\system32\shell32.dll'
16686e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\uxtheme.dll
16696e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
16706e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd42310000 'C:\Windows\system32\uxtheme.dll'
16716e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\advapi32.dll
16726e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\advapi32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
16736e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd45550000 'C:\Windows\system32\advapi32.dll'
16746e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
16756e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
16766e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'rpcrt4.dll'.
16776e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #29 'profapi.dll'.
16786e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\userenv.dll) WinVerifyTrust
16796e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\userenv.dll
16806e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'profapi.dll'...
16816e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'profapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\profapi.dll' [rcNtRedir=0xc0150008]
16826e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\profapi.dll
16836e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
16846e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
16856e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll
16866e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\userenv.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
16876e4.57c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\userenv.dll
16886e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd44220000 LB 0x00028000 C:\Windows\system32\userenv.dll [fFlags=0x0]
16896e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\userenv.dll
16906e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44220000 'C:\Windows\system32\userenv.dll'
16916e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\kernel32.dll
16926e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\kernel32.dll (Input=kernel32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
16936e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd47ba0000 'C:\Windows\System32\kernel32.dll'
16946e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd47550000 LB 0x000a2000 C:\Windows\System32\clbcatq.dll [fFlags=0x0]
16956e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
16966e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #28 'rpcrt4.dll'.
16976e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\clbcatq.dll)
16986e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\clbcatq.dll
16996e4.1cc4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
17006e4.1cc4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
17016e4.1cc4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
17026e4.1cc4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
17036e4.1cc4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
17046e4.1cc4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
17056e4.1cc4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\clbcatq.dll'
17066e4.1cc4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
17076e4.1cc4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
17086e4.1cc4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
17096e4.1cc4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
17106e4.1cc4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
17116e4.1cc4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ole32.dll'.
17126e4.1cc4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'oleaut32.dll'.
17136e4.1cc4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxC.dll) WinVerifyTrust
17146e4.1cc4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxC.dll
17156e4.1cc4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
17166e4.1cc4: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume3\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
17176e4.1cc4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\oleaut32.dll
17186e4.1cc4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
17196e4.1cc4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
17206e4.1cc4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ole32.dll
17216e4.1cc4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
17226e4.1cc4: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
17236e4.1cc4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\advapi32.dll
17246e4.1cc4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
17256e4.1cc4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
17266e4.1cc4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
17276e4.1cc4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
17286e4.1cc4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll
17296e4.1cc4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
17306e4.1cc4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
17316e4.1cc4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxC.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
17326e4.1cc4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxC.dll
17336e4.1cc4: supR3HardenedDllNotificationCallback: load 00007ffcdb720000 LB 0x003a0000 C:\Program Files\Oracle\VirtualBox\VBoxC.dll [fFlags=0x0]
17346e4.1cc4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxC.dll
17356e4.1cc4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcdb720000 'C:\Program Files\Oracle\VirtualBox\VBoxC.dll'
17366e4.1cc4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
17376e4.1cc4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
17386e4.1cc4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
17396e4.1cc4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
17406e4.1cc4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'shlwapi.dll'.
17416e4.1cc4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ole32.dll'.
17426e4.1cc4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'oleaut32.dll'.
17436e4.1cc4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
17446e4.1cc4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll) WinVerifyTrust
17456e4.1cc4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll
17466e4.1cc4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
17476e4.1cc4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
17486e4.1cc4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
17496e4.1cc4: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume3\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
17506e4.1cc4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\oleaut32.dll
17516e4.1cc4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
17526e4.1cc4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
17536e4.1cc4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ole32.dll
17546e4.1cc4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
17556e4.1cc4: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
17566e4.1cc4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shlwapi.dll [redoing WinVerifyTrust]
17576e4.1cc4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
17586e4.1cc4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
17596e4.1cc4: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\shlwapi.dll'
17606e4.1cc4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
17616e4.1cc4: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
17626e4.1cc4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\advapi32.dll
17636e4.1cc4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
17646e4.1cc4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
17656e4.1cc4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
17666e4.1cc4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
17676e4.1cc4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
17686e4.1cc4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll
17696e4.1cc4: supR3HardenedDllNotificationCallback: load 00007ffd185f0000 LB 0x000d4000 C:\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll [fFlags=0x0]
17706e4.1cc4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll
17716e4.1cc4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd185f0000 'C:\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll'
17726e4.1cc4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\oleaut32.dll
17736e4.1cc4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\oleaut32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
17746e4.1cc4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd45680000 'C:\Windows\System32\oleaut32.dll'
17756e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd45760000 'C:\Windows\system32\gdi32.dll'
17766e4.2748: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
17776e4.2748: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
17786e4.2748: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
17796e4.2748: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
17806e4.2748: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
17816e4.2748: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMainVM.dll) WinVerifyTrust
17826e4.2748: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMainVM.dll
17836e4.2748: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
17846e4.2748: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
17856e4.2748: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
17866e4.2748: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
17876e4.2748: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMainVM.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
17886e4.2748: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMainVM.dll
17896e4.2748: supR3HardenedDllNotificationCallback: load 00007ffd3a460000 LB 0x0000e000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMainVM.DLL [fFlags=0x0]
17906e4.2748: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMainVM.dll
17916e4.2748: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd3a460000 'C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMainVM.DLL'
17926e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shell32.dll
17936e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
17946e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd45aa0000 'C:\Windows\system32\shell32.dll'
17956e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
17966e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
17976e4.57c: '\Device\HarddiskVolume3\Windows\System32\ntdll.dll' has no imports
17986e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\ntdll.dll) WinVerifyTrust
17996e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\ntdll.dll
18006e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\ntdll.dll (Input=ntdll.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
18016e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd48320000 'C:\Windows\System32\ntdll.dll'
18026e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd47870000 LB 0x0016a000 C:\Windows\System32\MSCTF.dll [fFlags=0x0]
18036e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
18046e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'oleaut32.dll'.
18056e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #37 'user32.dll'.
18066e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #38 'gdi32.dll'.
18076e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #39 'imm32.dll'.
18086e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\msctf.dll)
18096e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\msctf.dll
18106e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
18116e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume3\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
18126e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\imm32.dll
18136e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
18146e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
18156e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
18166e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
18176e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
18186e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume3\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
18196e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\oleaut32.dll
18206e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
18216e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
18226e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll
18236e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
18246e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
18256e4.57c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\msctf.dll'
18266e4.57c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000a00 pwszName=\Device\HarddiskVolume3\Windows\System32\DataExchange.dll
18276e4.57c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000136ecf0
18286e4.57c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000136ecf0
18296e4.57c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=59F3AE35C1BD7FF73B733C35DF45575279B981AF
18306e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
18316e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
18326e4.57c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0310~31bf3856ad364e35~amd64~~10.0.17763.1.cat'; file='\Device\HarddiskVolume3\Windows\System32\DataExchange.dll'
18336e4.57c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
18346e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
18356e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'shcore.dll'.
18366e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #28 'combase.dll'.
18376e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #33 'd3d11.dll'.
18386e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #34 'dcomp.dll'.
18396e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\DataExchange.dll) WinVerifyTrust
18406e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\DataExchange.dll
18416e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dcomp.dll'...
18426e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'dcomp.dll' -> '\Device\HarddiskVolume3\Windows\System32\dcomp.dll' [rcNtRedir=0xc0150008]
18436e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll
18446e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
18456e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
18466e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
18476e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'win32u.dll'.
18486e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp_win.dll'.
18496e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #34 'oleaut32.dll'.
18506e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #35 'dxgi.dll'.
18516e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\dcomp.dll) WinVerifyTrust
18526e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\dcomp.dll
18536e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'd3d11.dll'...
18546e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'd3d11.dll' -> '\Device\HarddiskVolume3\Windows\System32\d3d11.dll' [rcNtRedir=0xc0150008]
18556e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dxgi.dll'...
18566e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'dxgi.dll' -> '\Device\HarddiskVolume3\Windows\System32\dxgi.dll' [rcNtRedir=0xc0150008]
18576e4.57c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\dxgi.dll'.
18586e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
18596e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'win32u.dll'.
18606e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\dxgi.dll)
18616e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\dxgi.dll
18626e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
18636e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume3\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
18646e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\oleaut32.dll
18656e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
18666e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
18676e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcp_win.dll [lacks WinVerifyTrust]
18686e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
18696e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
18706e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\win32u.dll [lacks WinVerifyTrust]
18716e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
18726e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
18736e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\win32u.dll [lacks WinVerifyTrust]
18746e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
18756e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
18766e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
18776e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
18786e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
18796e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'dxgi.dll'.
18806e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #35 'win32u.dll'.
18816e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\d3d11.dll) WinVerifyTrust
18826e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\d3d11.dll
18836e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
18846e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
18856e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\combase.dll [redoing WinVerifyTrust]
18866e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
18876e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
18886e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\win32u.dll [lacks WinVerifyTrust]
18896e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dxgi.dll'...
18906e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'dxgi.dll' -> '\Device\HarddiskVolume3\Windows\System32\dxgi.dll' [rcNtRedir=0xc0150008]
18916e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dxgi.dll [lacks WinVerifyTrust]
18926e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
18936e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
18946e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
18956e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
18966e4.57c: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\combase.dll'
18976e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shcore.dll'...
18986e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'shcore.dll' -> '\Device\HarddiskVolume3\Windows\System32\shcore.dll' [rcNtRedir=0xc0150008]
18996e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\SHCore.dll
19006e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
19016e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
19026e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\dataexchange.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
19036e4.57c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\DataExchange.dll
19046e4.57c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\d3d11.dll
19056e4.57c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dcomp.dll
19066e4.57c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dxgi.dll [avoiding WinVerifyTrust]
19076e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd430a0000 LB 0x000c2000 C:\Windows\system32\dxgi.dll [fFlags=0x0]
19086e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dxgi.dll [avoiding WinVerifyTrust]
19096e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd40f30000 LB 0x0027e000 C:\Windows\system32\d3d11.dll [fFlags=0x0]
19106e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\d3d11.dll
19116e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd41770000 LB 0x001c3000 C:\Windows\system32\dcomp.dll [fFlags=0x0]
19126e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dcomp.dll
19136e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd2a920000 LB 0x00056000 C:\Windows\system32\dataexchange.dll [fFlags=0x0]
19146e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\DataExchange.dll
19156e4.57c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\dxgi.dll'.
19166e4.57c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\dxgi.dll' [rescheduled]
19176e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll
19186e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\gdi32.dll (Input=gdi32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
19196e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd45760000 'C:\Windows\System32\gdi32.dll'
19206e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd2a920000 'C:\Windows\system32\dataexchange.dll'
19216e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rmclient.dll'.
19226e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #33 'rpcrt4.dll'.
19236e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #47 'combase.dll'.
19246e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #49 'msvcp_win.dll'.
19256e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\twinapi.appcore.dll)
19266e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\twinapi.appcore.dll
19276e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
19286e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'rpcrt4.dll'.
19296e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\rmclient.dll)
19306e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\rmclient.dll
19316e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd42620000 LB 0x00028000 C:\Windows\system32\RMCLIENT.dll [fFlags=0x0]
19326e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rmclient.dll [avoiding WinVerifyTrust]
19336e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd423e0000 LB 0x0020d000 C:\Windows\system32\twinapi.appcore.dll [fFlags=0x0]
19346e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\twinapi.appcore.dll [avoiding WinVerifyTrust]
19356e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
19366e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
19376e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
19386e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
19396e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
19406e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
19416e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcp_win.dll [lacks WinVerifyTrust]
19426e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
19436e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
19446e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\combase.dll
19456e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
19466e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
19476e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rmclient.dll'...
19486e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rmclient.dll' -> '\Device\HarddiskVolume3\Windows\System32\rmclient.dll' [rcNtRedir=0xc0150008]
19496e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rmclient.dll [lacks WinVerifyTrust]
19506e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
19516e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
19526e4.57c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\rmclient.dll'
19536e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
19546e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
19556e4.57c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\twinapi.appcore.dll'
19566e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\SHCore.dll
19576e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\Shcore.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
19586e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd458e0000 'C:\Windows\system32\Shcore.dll'
19596e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
19606e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #15 'rpcrt4.dll'.
19616e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #19 'coreuicomponents.dll'.
19626e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #20 'coremessaging.dll'.
19636e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\TextInputFramework.dll)
19646e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\TextInputFramework.dll
19656e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
19666e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #35 'coremessaging.dll'.
19676e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #48 'shcore.dll'.
19686e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\CoreUIComponents.dll)
19696e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\CoreUIComponents.dll
19706e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
19716e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #24 'rpcrt4.dll'.
19726e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\CoreMessaging.dll)
19736e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\CoreMessaging.dll
19746e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\ntmarta.dll)
19756e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\ntmarta.dll
19766e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'combase.dll'.
19776e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'rpcrt4.dll'.
19786e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #30 'bcryptprimitives.dll'.
19796e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\WinTypes.dll)
19806e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\WinTypes.dll
19816e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd433e0000 LB 0x00031000 C:\Windows\SYSTEM32\ntmarta.dll [fFlags=0x0]
19826e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ntmarta.dll [avoiding WinVerifyTrust]
19836e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd41cf0000 LB 0x000e2000 C:\Windows\System32\CoreMessaging.dll [fFlags=0x0]
19846e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\CoreMessaging.dll [avoiding WinVerifyTrust]
19856e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd3f650000 LB 0x00153000 C:\Windows\SYSTEM32\wintypes.dll [fFlags=0x0]
19866e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\WinTypes.dll [avoiding WinVerifyTrust]
19876e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd3f7b0000 LB 0x00322000 C:\Windows\System32\CoreUIComponents.dll [fFlags=0x0]
19886e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\CoreUIComponents.dll [avoiding WinVerifyTrust]
19896e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd30bb0000 LB 0x00095000 C:\Windows\System32\TextInputFramework.dll [fFlags=0x0]
19906e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\TextInputFramework.dll [avoiding WinVerifyTrust]
19916e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcryptprimitives.dll'...
19926e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcryptprimitives.dll' -> '\Device\HarddiskVolume3\Windows\System32\bcryptprimitives.dll' [rcNtRedir=0xc0150008]
19936e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\bcryptprimitives.dll
19946e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
19956e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
19966e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
19976e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
19986e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\combase.dll
19996e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
20006e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
20016e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
20026e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
20036e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shcore.dll'...
20046e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'shcore.dll' -> '\Device\HarddiskVolume3\Windows\System32\shcore.dll' [rcNtRedir=0xc0150008]
20056e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\SHCore.dll
20066e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'coremessaging.dll'...
20076e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'coremessaging.dll' -> '\Device\HarddiskVolume3\Windows\System32\coremessaging.dll' [rcNtRedir=0xc0150008]
20086e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\CoreMessaging.dll [lacks WinVerifyTrust]
20096e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
20106e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
20116e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'coremessaging.dll'...
20126e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'coremessaging.dll' -> '\Device\HarddiskVolume3\Windows\System32\coremessaging.dll' [rcNtRedir=0xc0150008]
20136e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\CoreMessaging.dll [lacks WinVerifyTrust]
20146e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'coreuicomponents.dll'...
20156e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'coreuicomponents.dll' -> '\Device\HarddiskVolume3\Windows\System32\coreuicomponents.dll' [rcNtRedir=0xc0150008]
20166e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\CoreUIComponents.dll [lacks WinVerifyTrust]
20176e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
20186e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
20196e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
20206e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
20216e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
20226e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
20236e4.57c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\WinTypes.dll'
20246e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
20256e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
20266e4.57c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\ntmarta.dll'
20276e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
20286e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
20296e4.57c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\CoreMessaging.dll'
20306e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
20316e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
20326e4.57c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\CoreUIComponents.dll'
20336e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
20346e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
20356e4.57c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\TextInputFramework.dll'
20366e4.57c: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(ext-ms-win-rtcore-ntuser-window-ext-l1-1-0.dll) -> 0x0, fPresent=1
20376e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=ext-ms-win-rtcore-ntuser-window-ext-l1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
20386e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd48150000 'ext-ms-win-rtcore-ntuser-window-ext-l1-1-0.dll'
20396e4.57c: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(ext-ms-win-rtcore-ntuser-integration-l1-1-0.dll) -> 0x0, fPresent=1
20406e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=ext-ms-win-rtcore-ntuser-integration-l1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
20416e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd48150000 'ext-ms-win-rtcore-ntuser-integration-l1-1-0.dll'
20426e4.57c: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-com-l1-1-0.dll) -> 0x0, fPresent=1
20436e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-com-l1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
20446e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd47c60000 'api-ms-win-core-com-l1-1-0.dll'
20456e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msctf.dll
20466e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\MSCTF.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
20476e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd47870000 'C:\Windows\System32\MSCTF.dll'
20486e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ole32.dll
20496e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\ole32.dll (Input=ole32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
20506e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd47ff0000 'C:\Windows\System32\ole32.dll'
20516e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd45680000 'C:\Windows\System32\OLEAUT32.dll'
20526e4.57c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000b38 pwszName=\Device\HarddiskVolume3\Windows\System32\wbem\wbemprox.dll
20536e4.57c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000136ecf0
20546e4.57c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000136ecf0
20556e4.57c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=61B08AF50BF6163BDE34EB0C9B6605297BA2441A
20566e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
20576e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
20586e4.57c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_347_for_KB4493509~31bf3856ad364e35~amd64~~10.0.1.6.cat'; file='\Device\HarddiskVolume3\Windows\System32\wbem\wbemprox.dll'
20596e4.57c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
20606e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
20616e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ws2_32.dll'.
20626e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'wbemcomn.dll'.
20636e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\wbem\wbemprox.dll) WinVerifyTrust
20646e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\wbem\wbemprox.dll
20656e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wbemcomn.dll'...
20666e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'wbemcomn.dll' -> '\Device\HarddiskVolume3\Windows\System32\wbemcomn.dll' [rcNtRedir=0xc0150008]
20676e4.57c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000b44 pwszName=\Device\HarddiskVolume3\Windows\System32\wbemcomn.dll
20686e4.57c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000136ecf0
20696e4.57c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000136ecf0
20706e4.57c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=585E55607969886FF9DCECA6C86E3FD6D59F65D2
20716e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
20726e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
20736e4.57c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package02~31bf3856ad364e35~amd64~~10.0.17763.1.cat'; file='\Device\HarddiskVolume3\Windows\System32\wbemcomn.dll'
20746e4.57c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
20756e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
20766e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'bcrypt.dll'.
20776e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'ws2_32.dll'.
20786e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\wbemcomn.dll) WinVerifyTrust
20796e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\wbemcomn.dll
20806e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
20816e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
20826e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ws2_32.dll
20836e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
20846e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
20856e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
20866e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
20876e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ws2_32.dll
20886e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
20896e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume3\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
20906e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\bcrypt.dll
20916e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
20926e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
20936e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wbem\wbemprox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
20946e4.57c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wbem\wbemprox.dll
20956e4.57c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wbemcomn.dll
20966e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd29c10000 LB 0x00085000 C:\Windows\SYSTEM32\wbemcomn.dll [fFlags=0x0]
20976e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wbemcomn.dll
20986e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd28cf0000 LB 0x00011000 C:\Windows\system32\wbem\wbemprox.dll [fFlags=0x0]
20996e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wbem\wbemprox.dll
21006e4.57c: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(API-MS-Win-Core-LocalRegistry-L1-1-0.dll) -> 0x0, fPresent=1
21016e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Core-LocalRegistry-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
21026e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd45160000 'API-MS-Win-Core-LocalRegistry-L1-1-0.dll'
21036e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd28cf0000 'C:\Windows\system32\wbem\wbemprox.dll'
21046e4.57c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000b74 pwszName=\Device\HarddiskVolume3\Windows\System32\wbem\wbemsvc.dll
21056e4.57c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000136ecf0
21066e4.57c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000136ecf0
21076e4.57c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2479751D59078C3499423233D67A94D93457E663
21086e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
21096e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
21106e4.57c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_347_for_KB4493509~31bf3856ad364e35~amd64~~10.0.1.6.cat'; file='\Device\HarddiskVolume3\Windows\System32\wbem\wbemsvc.dll'
21116e4.57c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
21126e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
21136e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'rpcrt4.dll'.
21146e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\wbem\wbemsvc.dll) WinVerifyTrust
21156e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\wbem\wbemsvc.dll
21166e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
21176e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
21186e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
21196e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
21206e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wbem\wbemsvc.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
21216e4.57c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wbem\wbemsvc.dll
21226e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd25390000 LB 0x00014000 C:\Windows\system32\wbem\wbemsvc.dll [fFlags=0x0]
21236e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wbem\wbemsvc.dll
21246e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd25390000 'C:\Windows\system32\wbem\wbemsvc.dll'
21256e4.57c: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-l1-2-0.dll) -> 0x0, fPresent=1
21266e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-l1-2-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
21276e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd45160000 'api-ms-win-core-localization-l1-2-0.dll'
21286e4.57c: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-obsolete-l1-1-0.dll) -> 0x0, fPresent=1
21296e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-obsolete-l1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
21306e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd45160000 'api-ms-win-core-localization-obsolete-l1-1-0.dll'
21316e4.57c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000b80 pwszName=\Device\HarddiskVolume3\Windows\System32\wbem\fastprox.dll
21326e4.57c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000136ecf0
21336e4.57c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000136ecf0
21346e4.57c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=5D738E4890595C8890290239456518F354997BFD
21356e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
21366e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
21376e4.57c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package02~31bf3856ad364e35~amd64~~10.0.17763.1.cat'; file='\Device\HarddiskVolume3\Windows\System32\wbem\fastprox.dll'
21386e4.57c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
21396e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
21406e4.57c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #19 'wbemcomn.dll'.
21416e4.57c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\wbem\fastprox.dll) WinVerifyTrust
21426e4.57c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\wbem\fastprox.dll
21436e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wbemcomn.dll'...
21446e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'wbemcomn.dll' -> '\Device\HarddiskVolume3\Windows\System32\wbemcomn.dll' [rcNtRedir=0xc0150008]
21456e4.57c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wbemcomn.dll
21466e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
21476e4.57c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
21486e4.57c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wbem\fastprox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
21496e4.57c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wbem\fastprox.dll
21506e4.57c: supR3HardenedDllNotificationCallback: load 00007ffd253d0000 LB 0x000f1000 C:\Windows\system32\wbem\fastprox.dll [fFlags=0x0]
21516e4.57c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wbem\fastprox.dll
21526e4.57c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd253d0000 'C:\Windows\system32\wbem\fastprox.dll'
21536e4.14d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
21546e4.14d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
21556e4.14d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrem.dll'.
21566e4.14d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
21576e4.14d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxVMM.dll) WinVerifyTrust
21586e4.14d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxVMM.dll
21596e4.14d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
21606e4.14d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
21616e4.14d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrem.dll'...
21626e4.14d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrem.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxrem.dll' [rcNtRedir=0xc0150008]
21636e4.14d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
21646e4.14d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'vboxrt.dll'.
21656e4.14d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
21666e4.14d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcrt.dll'.
21676e4.14d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxREM.dll) WinVerifyTrust
21686e4.14d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxREM.dll
21696e4.14d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
21706e4.14d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
21716e4.14d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
21726e4.14d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
21736e4.14d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
21746e4.14d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
21756e4.14d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxVMM.dll
21766e4.14d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
21776e4.14d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
21786e4.14d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
21796e4.14d4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxVMM.dll
21806e4.14d4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxREM.dll
21816e4.14d4: supR3HardenedDllNotificationCallback: load 0000000066b60000 LB 0x0010b000 C:\Program Files\Oracle\VirtualBox\VBoxREM.dll [fFlags=0x0]
21826e4.14d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxREM.dll
21836e4.14d4: supR3HardenedDllNotificationCallback: load 00007ffd058c0000 LB 0x00331000 C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL [fFlags=0x0]
21846e4.14d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxVMM.dll
21856e4.14d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd058c0000 'C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL'
21866e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
21876e4.3740: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
21886e4.3740: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
21896e4.3740: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
21906e4.3740: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
21916e4.3740: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
21926e4.3740: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll) WinVerifyTrust
21936e4.3740: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll
21946e4.3740: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
21956e4.3740: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
21966e4.3740: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
21976e4.3740: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
21986e4.3740: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
21996e4.3740: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
22006e4.3740: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxVMM.dll
22016e4.3740: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
22026e4.3740: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
22036e4.3740: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
22046e4.3740: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll
22056e4.3740: supR3HardenedDllNotificationCallback: load 00007ffd3a3d0000 LB 0x0000b000 C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL [fFlags=0x0]
22066e4.3740: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll
22076e4.3740: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd3a3d0000 'C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL'
22086e4.3740: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd48150000 'C:\Windows\system32\User32.dll'
22096e4.608: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
22106e4.608: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
22116e4.608: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
22126e4.608: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
22136e4.608: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll) WinVerifyTrust
22146e4.608: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll
22156e4.608: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
22166e4.608: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
22176e4.608: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
22186e4.608: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
22196e4.608: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
22206e4.608: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
22216e4.608: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll
22226e4.608: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
22236e4.608: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll
22246e4.608: supR3HardenedDllNotificationCallback: load 00007ffd39fa0000 LB 0x0000d000 C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL [fFlags=0x0]
22256e4.608: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll
22266e4.608: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd39fa0000 'C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL'
22276e4.1c34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shell32.dll
22286e4.1c34: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\Shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
22296e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd45aa0000 'C:\Windows\system32\Shell32.dll'
22306e4.1c34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxVMM.dll
22316e4.1c34: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
22326e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd058c0000 'C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL'
22336e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
22346e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
22356e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
22366e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
22376e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ole32.dll'.
22386e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
22396e4.1c34: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll) WinVerifyTrust
22406e4.1c34: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
22416e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
22426e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume3\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
22436e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
22446e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
22456e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
22466e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
22476e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
22486e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
22496e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
22506e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
22516e4.1c34: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
22526e4.1c34: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
22536e4.1c34: supR3HardenedDllNotificationCallback: load 00007ffd2e710000 LB 0x00041000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL [fFlags=0x0]
22546e4.1c34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
22556e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd2e710000 'C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL'
22566e4.1c34: supR3HardenedDllNotificationCallback: Unload 00007ffd2e710000 LB 0x00041000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL [flags=0x0]
22576e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
22586e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
22596e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
22606e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
22616e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
22626e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vboxddu.dll'.
22636e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'vboxdd2.dll'.
22646e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
22656e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'setupapi.dll'.
22666e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'ws2_32.dll'.
22676e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'ole32.dll'.
22686e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'iphlpapi.dll'.
22696e4.1c34: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxDD.dll) WinVerifyTrust
22706e4.1c34: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxDD.dll
22716e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'iphlpapi.dll'...
22726e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'iphlpapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\iphlpapi.dll' [rcNtRedir=0xc0150008]
22736e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
22746e4.1c34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll
22756e4.1c34: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
22766e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
22776e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #21 'rpcrt4.dll'.
22786e4.1c34: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\IPHLPAPI.DLL) WinVerifyTrust
22796e4.1c34: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\IPHLPAPI.DLL
22806e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
22816e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
22826e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
22836e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
22846e4.1c34: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ws2_32.dll
22856e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
22866e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
22876e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
22886e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
22896e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
22906e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
22916e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
22926e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #29 'rpcrt4.dll'.
22936e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #37 'cfgmgr32.dll'.
22946e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #41 'bcrypt.dll'.
22956e4.1c34: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\setupapi.dll) WinVerifyTrust
22966e4.1c34: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\setupapi.dll
22976e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
22986e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
22996e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxdd2.dll'...
23006e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxdd2.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxdd2.dll' [rcNtRedir=0xc0150008]
23016e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
23026e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume3\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
23036e4.1c34: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\bcrypt.dll
23046e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
23056e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume3\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
23066e4.1c34: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\cfgmgr32.dll [lacks WinVerifyTrust]
23076e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
23086e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
23096e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
23106e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
23116e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
23126e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
23136e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
23146e4.1c34: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxDD2.dll) WinVerifyTrust
23156e4.1c34: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxDD2.dll
23166e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxddu.dll'...
23176e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxddu.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxddu.dll' [rcNtRedir=0xc0150008]
23186e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
23196e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
23206e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
23216e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
23226e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
23236e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
23246e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
23256e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
23266e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'setupapi.dll'.
23276e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'advapi32.dll'.
23286e4.1c34: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxDDU.dll) WinVerifyTrust
23296e4.1c34: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxDDU.dll
23306e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
23316e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
23326e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
23336e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
23346e4.1c34: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxVMM.dll
23356e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
23366e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
23376e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
23386e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
23396e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
23406e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
23416e4.1c34: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\setupapi.dll
23426e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
23436e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
23446e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
23456e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
23466e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
23476e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
23486e4.1c34: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxDD.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
23496e4.1c34: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxDD.dll
23506e4.1c34: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxDDU.dll
23516e4.1c34: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxDD2.dll
23526e4.1c34: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\IPHLPAPI.DLL
23536e4.1c34: supR3HardenedDllNotificationCallback: load 00007ffd470c0000 LB 0x00476000 C:\Windows\System32\SETUPAPI.dll [fFlags=0x0]
23546e4.1c34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\setupapi.dll
23556e4.1c34: supR3HardenedDllNotificationCallback: load 00007ffd2f770000 LB 0x00064000 C:\Program Files\Oracle\VirtualBox\VBoxDDU.dll [fFlags=0x0]
23566e4.1c34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxDDU.dll
23576e4.1c34: supR3HardenedDllNotificationCallback: load 00007ffd18fd0000 LB 0x0005c000 C:\Program Files\Oracle\VirtualBox\VBoxDD2.dll [fFlags=0x0]
23586e4.1c34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxDD2.dll
23596e4.1c34: supR3HardenedDllNotificationCallback: load 00007ffd438a0000 LB 0x0003d000 C:\Windows\SYSTEM32\IPHLPAPI.DLL [fFlags=0x0]
23606e4.1c34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\IPHLPAPI.DLL
23616e4.1c34: supR3HardenedDllNotificationCallback: load 00007ffcdeff0000 LB 0x009d9000 C:\Program Files\Oracle\VirtualBox\VBoxDD.DLL [fFlags=0x0]
23626e4.1c34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxDD.dll
23636e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcdeff0000 'C:\Program Files\Oracle\VirtualBox\VBoxDD.DLL'
23646e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
23656e4.1c34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
23666e4.1c34: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
23676e4.1c34: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
23686e4.1c34: supR3HardenedDllNotificationCallback: load 00007ffd2e710000 LB 0x00041000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL [fFlags=0x0]
23696e4.1c34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
23706e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd2e710000 'C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL'
23716e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
23726e4.1c34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxC.dll
23736e4.1c34: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxC.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
23746e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcdb720000 'C:\Program Files\Oracle\VirtualBox\VBoxC.DLL'
23756e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
23766e4.1c34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxDD2.dll
23776e4.1c34: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxDD2.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
23786e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd18fd0000 'C:\Program Files\Oracle\VirtualBox\VBoxDD2.DLL'
23796e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
23806e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
23816e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
23826e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
23836e4.1c34: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.dll) WinVerifyTrust
23846e4.1c34: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.dll
23856e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
23866e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
23876e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
23886e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
23896e4.1c34: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
23906e4.1c34: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.dll
23916e4.1c34: supR3HardenedDllNotificationCallback: load 00007ffd38ce0000 LB 0x0001e000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.DLL [fFlags=0x0]
23926e4.1c34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.dll
23936e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd38ce0000 'C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.DLL'
23946e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
23956e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
23966e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
23976e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
23986e4.1c34: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.dll) WinVerifyTrust
23996e4.1c34: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.dll
24006e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
24016e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
24026e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
24036e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
24046e4.1c34: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
24056e4.1c34: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.dll
24066e4.1c34: supR3HardenedDllNotificationCallback: load 00007ffd38be0000 LB 0x00018000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.DLL [fFlags=0x0]
24076e4.1c34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.dll
24086e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd38be0000 'C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.DLL'
24096e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
24106e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
24116e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
24126e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
24136e4.1c34: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.dll) WinVerifyTrust
24146e4.1c34: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.dll
24156e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
24166e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
24176e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
24186e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
24196e4.1c34: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
24206e4.1c34: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.dll
24216e4.1c34: supR3HardenedDllNotificationCallback: load 00007ffd2f7e0000 LB 0x00018000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.DLL [fFlags=0x0]
24226e4.1c34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.dll
24236e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd2f7e0000 'C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.DLL'
24246e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
24256e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
24266e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
24276e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
24286e4.1c34: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.dll) WinVerifyTrust
24296e4.1c34: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.dll
24306e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
24316e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
24326e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
24336e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
24346e4.1c34: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
24356e4.1c34: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.dll
24366e4.1c34: supR3HardenedDllNotificationCallback: load 00007ffd2f720000 LB 0x00019000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.DLL [fFlags=0x0]
24376e4.1c34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.dll
24386e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd2f720000 'C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.DLL'
24396e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
24406e4.3488: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
24416e4.3488: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
24426e4.3488: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
24436e4.3488: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
24446e4.3488: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll) WinVerifyTrust
24456e4.3488: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll
24466e4.3488: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
24476e4.3488: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
24486e4.3488: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
24496e4.3488: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
24506e4.3488: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxVMM.dll
24516e4.3488: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
24526e4.3488: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
24536e4.3488: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
24546e4.3488: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll
24556e4.3488: supR3HardenedDllNotificationCallback: load 00007ffd2e9b0000 LB 0x00013000 C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL [fFlags=0x0]
24566e4.3488: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll
24576e4.3488: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd2e9b0000 'C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL'
24586e4.1774: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
24596e4.1774: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
24606e4.1774: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
24616e4.1774: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxvmm.dll'.
24626e4.1774: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vboxrt.dll'.
24636e4.1774: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll) WinVerifyTrust
24646e4.1774: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll
24656e4.1774: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
24666e4.1774: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
24676e4.1774: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
24686e4.1774: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
24696e4.1774: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxVMM.dll
24706e4.1774: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
24716e4.1774: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
24726e4.1774: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
24736e4.1774: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
24746e4.1774: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
24756e4.1774: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll
24766e4.1774: supR3HardenedDllNotificationCallback: load 00007ffd39b50000 LB 0x0000c000 C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL [fFlags=0x0]
24776e4.1774: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll
24786e4.1774: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd39b50000 'C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL'
24796e4.3a28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
24806e4.3a28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
24816e4.3a28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
24826e4.3a28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
24836e4.3a28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll) WinVerifyTrust
24846e4.3a28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll
24856e4.3a28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
24866e4.3a28: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
24876e4.3a28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
24886e4.3a28: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
24896e4.3a28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
24906e4.3a28: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
24916e4.3a28: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
24926e4.3a28: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll
24936e4.3a28: supR3HardenedDllNotificationCallback: load 00007ffd39b10000 LB 0x0000d000 C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL [fFlags=0x0]
24946e4.3a28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll
24956e4.3a28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd39b10000 'C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL'
24966e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
24976e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
24986e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
24996e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
25006e4.1c34: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.dll) WinVerifyTrust
25016e4.1c34: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.dll
25026e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
25036e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
25046e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
25056e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
25066e4.1c34: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
25076e4.1c34: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.dll
25086e4.1c34: supR3HardenedDllNotificationCallback: load 00007ffd403c0000 LB 0x0000a000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.DLL [fFlags=0x0]
25096e4.1c34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.dll
25106e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd403c0000 'C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.DLL'
25116e4.1c34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\IPHLPAPI.DLL
25126e4.1c34: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\Iphlpapi.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
25136e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd438a0000 'C:\Windows\system32\Iphlpapi.dll'
25146e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rpcrt4.dll'.
25156e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'nsi.dll'.
25166e4.1c34: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\winnsi.dll)
25176e4.1c34: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\winnsi.dll
25186e4.1c34: supR3HardenedDllNotificationCallback: load 00007ffd45750000 LB 0x00008000 C:\Windows\System32\NSI.dll [fFlags=0x0]
25196e4.1c34: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\nsi.dll)
25206e4.1c34: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\nsi.dll
25216e4.1c34: supR3HardenedDllNotificationCallback: load 00007ffd3c840000 LB 0x0000b000 C:\Windows\SYSTEM32\WINNSI.DLL [fFlags=0x0]
25226e4.1c34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winnsi.dll [avoiding WinVerifyTrust]
25236e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rpcrt4.dll'.
25246e4.1c34: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\dhcpcsvc6.dll)
25256e4.1c34: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\dhcpcsvc6.dll
25266e4.1c34: supR3HardenedDllNotificationCallback: load 00007ffd39ee0000 LB 0x00016000 C:\Windows\SYSTEM32\dhcpcsvc6.DLL [fFlags=0x0]
25276e4.1c34: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\dhcpcsvc6.dll [avoiding WinVerifyTrust]
25286e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rpcrt4.dll'.
25296e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ws2_32.dll'.
25306e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'nsi.dll'.
25316e4.1c34: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\dhcpcsvc.dll)
25326e4.1c34: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\dhcpcsvc.dll
25336e4.1c34: supR3HardenedDllNotificationCallback: load 00007ffd39980000 LB 0x0001c000 C:\Windows\SYSTEM32\dhcpcsvc.DLL [fFlags=0x0]
25346e4.1c34: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\dhcpcsvc.dll [avoiding WinVerifyTrust]
25356e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #21 'ws2_32.dll'.
25366e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'nsi.dll'.
25376e4.1c34: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\dnsapi.dll)
25386e4.1c34: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\dnsapi.dll
25396e4.1c34: supR3HardenedDllNotificationCallback: load 00007ffd438e0000 LB 0x000c6000 C:\Windows\SYSTEM32\DNSAPI.dll [fFlags=0x0]
25406e4.1c34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dnsapi.dll [avoiding WinVerifyTrust]
25416e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
25426e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume3\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
25436e4.1c34: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\nsi.dll [lacks WinVerifyTrust]
25446e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
25456e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
25466e4.1c34: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ws2_32.dll
25476e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
25486e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume3\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
25496e4.1c34: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\nsi.dll [lacks WinVerifyTrust]
25506e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
25516e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
25526e4.1c34: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ws2_32.dll
25536e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
25546e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
25556e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
25566e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
25576e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
25586e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume3\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
25596e4.1c34: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\nsi.dll [lacks WinVerifyTrust]
25606e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
25616e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
25626e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
25636e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
25646e4.1c34: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\dnsapi.dll'
25656e4.1c34: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000e5c pwszName=\Device\HarddiskVolume3\Windows\System32\dhcpcsvc.dll
25666e4.1c34: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000136ecf0
25676e4.1c34: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000136ecf0
25686e4.1c34: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=023C8DA2B39F9AA3A5B23F6B14BA6DD8E8288590
25696e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
25706e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
25716e4.1c34: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0316~31bf3856ad364e35~amd64~~10.0.17763.1.cat'; file='\Device\HarddiskVolume3\Windows\System32\dhcpcsvc.dll'
25726e4.1c34: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
25736e4.1c34: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\dhcpcsvc.dll'
25746e4.1c34: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000ef0 pwszName=\Device\HarddiskVolume3\Windows\System32\dhcpcsvc6.dll
25756e4.1c34: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000136ecf0
25766e4.1c34: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000136ecf0
25776e4.1c34: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=E0A1EEF9F9131F768A30314D53D98D8EC54A521D
25786e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
25796e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
25806e4.1c34: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0316~31bf3856ad364e35~amd64~~10.0.17763.1.cat'; file='\Device\HarddiskVolume3\Windows\System32\dhcpcsvc6.dll'
25816e4.1c34: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
25826e4.1c34: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\dhcpcsvc6.dll'
25836e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
25846e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
25856e4.1c34: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\nsi.dll'
25866e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
25876e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
25886e4.1c34: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\winnsi.dll'
25896e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
25906e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
25916e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'rpcrt4.dll'.
25926e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'devobj.dll'.
25936e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #37 'propsys.dll'.
25946e4.1c34: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\MMDevAPI.dll) WinVerifyTrust
25956e4.1c34: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\MMDevAPI.dll
25966e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'propsys.dll'...
25976e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'propsys.dll' -> '\Device\HarddiskVolume3\Windows\System32\propsys.dll' [rcNtRedir=0xc0150008]
25986e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
25996e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
26006e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
26016e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #15 'oleaut32.dll'.
26026e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #31 'rpcrt4.dll'.
26036e4.1c34: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\propsys.dll) WinVerifyTrust
26046e4.1c34: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\propsys.dll
26056e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'devobj.dll'...
26066e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'devobj.dll' -> '\Device\HarddiskVolume3\Windows\System32\devobj.dll' [rcNtRedir=0xc0150008]
26076e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
26086e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
26096e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
26106e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume3\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
26116e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
26126e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
26136e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
26146e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
26156e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'cfgmgr32.dll'.
26166e4.1c34: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\devobj.dll) WinVerifyTrust
26176e4.1c34: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\devobj.dll
26186e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
26196e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
26206e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
26216e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume3\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
26226e4.1c34: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\cfgmgr32.dll [redoing WinVerifyTrust]
26236e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
26246e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
26256e4.1c34: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\cfgmgr32.dll'
26266e4.1c34: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\MMDevApi.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
26276e4.1c34: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\MMDevAPI.dll
26286e4.1c34: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\devobj.dll
26296e4.1c34: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\propsys.dll
26306e4.1c34: supR3HardenedDllNotificationCallback: load 00007ffd44130000 LB 0x00029000 C:\Windows\System32\DEVOBJ.dll [fFlags=0x0]
26316e4.1c34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\devobj.dll
26326e4.1c34: supR3HardenedDllNotificationCallback: load 00007ffd40710000 LB 0x001a8000 C:\Windows\System32\PROPSYS.dll [fFlags=0x0]
26336e4.1c34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\propsys.dll
26346e4.1c34: supR3HardenedDllNotificationCallback: load 00007ffd38260000 LB 0x00070000 C:\Windows\System32\MMDevApi.dll [fFlags=0x0]
26356e4.1c34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\MMDevAPI.dll
26366e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd38260000 'C:\Windows\System32\MMDevApi.dll'
26376e4.1c34: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000001090 pwszName=\Device\HarddiskVolume3\Windows\System32\dsound.dll
26386e4.1c34: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000136ecf0
26396e4.1c34: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000136ecf0
26406e4.1c34: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=8AD365A940454786DE7BEC545039701B233FD977
26416e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
26426e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
26436e4.1c34: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_314_for_KB4493509~31bf3856ad364e35~amd64~~10.0.1.6.cat'; file='\Device\HarddiskVolume3\Windows\System32\dsound.dll'
26446e4.1c34: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
26456e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
26466e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #32 'winmm.dll'.
26476e4.1c34: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\dsound.dll) WinVerifyTrust
26486e4.1c34: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\dsound.dll
26496e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
26506e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume3\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
26516e4.1c34: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winmm.dll
26526e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
26536e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
26546e4.1c34: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
26556e4.1c34: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dsound.dll
26566e4.1c34: supR3HardenedDllNotificationCallback: load 00007ffd3d5d0000 LB 0x00096000 C:\Windows\System32\dsound.dll [fFlags=0x0]
26576e4.1c34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dsound.dll
26586e4.1c34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dsound.dll
26596e4.1c34: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
26606e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd3d5d0000 'C:\Windows\System32\dsound.dll'
26616e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd3d5d0000 'C:\Windows\System32\dsound.dll'
26626e4.1c34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dsound.dll
26636e4.1c34: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
26646e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd3d5d0000 'C:\Windows\system32\dsound.dll'
26656e4.1c34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\MMDevAPI.dll
26666e4.1c34: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\MMDEVAPI.DLL (Input=MMDEVAPI.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
26676e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd38260000 'C:\Windows\System32\MMDEVAPI.DLL'
26686e4.80c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
26696e4.80c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
26706e4.80c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
26716e4.80c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'rpcrt4.dll'.
26726e4.80c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'oleaut32.dll'.
26736e4.80c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #57 'mmdevapi.dll'.
26746e4.80c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #58 'avrt.dll'.
26756e4.80c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\AudioSes.dll) WinVerifyTrust
26766e4.80c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\AudioSes.dll
26776e4.80c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'avrt.dll'...
26786e4.80c: supR3HardenedWinVerifyCacheProcessImportTodos: 'avrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\avrt.dll' [rcNtRedir=0xc0150008]
26796e4.80c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
26806e4.80c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
26816e4.80c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\avrt.dll) WinVerifyTrust
26826e4.80c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\avrt.dll
26836e4.80c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mmdevapi.dll'...
26846e4.80c: supR3HardenedWinVerifyCacheProcessImportTodos: 'mmdevapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\mmdevapi.dll' [rcNtRedir=0xc0150008]
26856e4.80c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\MMDevAPI.dll
26866e4.80c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
26876e4.80c: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume3\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
26886e4.80c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
26896e4.80c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
26906e4.80c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll
26916e4.80c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
26926e4.80c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
26936e4.80c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcp_win.dll [redoing WinVerifyTrust]
26946e4.80c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
26956e4.80c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
26966e4.80c: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll'
26976e4.80c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\AUDIOSES.DLL (Input=AUDIOSES.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
26986e4.80c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\AudioSes.dll
26996e4.80c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\avrt.dll
27006e4.80c: supR3HardenedDllNotificationCallback: load 00007ffd400f0000 LB 0x0000a000 C:\Windows\SYSTEM32\AVRT.dll [fFlags=0x0]
27016e4.80c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\avrt.dll
27026e4.80c: supR3HardenedDllNotificationCallback: load 00007ffd37b70000 LB 0x00148000 C:\Windows\System32\AUDIOSES.DLL [fFlags=0x0]
27036e4.80c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\AudioSes.dll
27046e4.80c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd37b70000 'C:\Windows\System32\AUDIOSES.DLL'
27056e4.80c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
27066e4.80c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'rpcrt4.dll'.
27076e4.80c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\ResourcePolicyClient.dll)
27086e4.80c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\ResourcePolicyClient.dll
27096e4.80c: supR3HardenedDllNotificationCallback: load 00007ffd42650000 LB 0x00014000 C:\Windows\SYSTEM32\resourcepolicyclient.dll [fFlags=0x0]
27106e4.80c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ResourcePolicyClient.dll [avoiding WinVerifyTrust]
27116e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
27126e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
27136e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
27146e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
27156e4.1c34: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll
27166e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
27176e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
27186e4.1c34: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\ResourcePolicyClient.dll'
27196e4.1c34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winmm.dll
27206e4.1c34: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\winmm.dll (Input=winmm.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
27216e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd41f30000 'C:\Windows\System32\winmm.dll'
27226e4.1c34: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000001140 pwszName=\Device\HarddiskVolume3\Windows\System32\wdmaud.drv
27236e4.1c34: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000136ecf0
27246e4.1c34: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000136ecf0
27256e4.1c34: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=22E5B934FBB9B8EED168F5BD0121AD902CCB797A
27266e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
27276e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
27286e4.1c34: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package~31bf3856ad364e35~amd64~~10.0.17763.1.cat'; file='\Device\HarddiskVolume3\Windows\System32\wdmaud.drv'
27296e4.1c34: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
27306e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
27316e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'mmdevapi.dll'.
27326e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 'ksuser.dll'.
27336e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #28 'avrt.dll'.
27346e4.1c34: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\wdmaud.drv) WinVerifyTrust
27356e4.1c34: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\wdmaud.drv
27366e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'avrt.dll'...
27376e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'avrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\avrt.dll' [rcNtRedir=0xc0150008]
27386e4.1c34: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\avrt.dll
27396e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ksuser.dll'...
27406e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'ksuser.dll' -> '\Device\HarddiskVolume3\Windows\System32\ksuser.dll' [rcNtRedir=0xc0150008]
27416e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
27426e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
27436e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
27446e4.1c34: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\ksuser.dll) WinVerifyTrust
27456e4.1c34: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\ksuser.dll
27466e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mmdevapi.dll'...
27476e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'mmdevapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\mmdevapi.dll' [rcNtRedir=0xc0150008]
27486e4.1c34: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\MMDevAPI.dll
27496e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
27506e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
27516e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
27526e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
27536e4.1c34: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
27546e4.1c34: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wdmaud.drv
27556e4.1c34: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ksuser.dll
27566e4.1c34: supR3HardenedDllNotificationCallback: load 00007ffd38c90000 LB 0x00009000 C:\Windows\SYSTEM32\ksuser.dll [fFlags=0x0]
27576e4.1c34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ksuser.dll
27586e4.1c34: supR3HardenedDllNotificationCallback: load 00007ffd18340000 LB 0x00044000 C:\Windows\System32\wdmaud.drv [fFlags=0x0]
27596e4.1c34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wdmaud.drv
27606e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd18340000 'C:\Windows\System32\wdmaud.drv'
27616e4.1c34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wdmaud.drv
27626e4.1c34: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
27636e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd18340000 'C:\Windows\System32\wdmaud.drv'
27646e4.1c34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wdmaud.drv
27656e4.1c34: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
27666e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd18340000 'C:\Windows\System32\wdmaud.drv'
27676e4.1c34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wdmaud.drv
27686e4.1c34: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
27696e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd18340000 'C:\Windows\System32\wdmaud.drv'
27706e4.1c34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wdmaud.drv
27716e4.1c34: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
27726e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd18340000 'C:\Windows\System32\wdmaud.drv'
27736e4.1c34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wdmaud.drv
27746e4.1c34: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
27756e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd18340000 'C:\Windows\System32\wdmaud.drv'
27766e4.1c34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wdmaud.drv
27776e4.1c34: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
27786e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd18340000 'C:\Windows\System32\wdmaud.drv'
27796e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd18340000 'C:\Windows\System32\wdmaud.drv'
27806e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd18340000 'C:\Windows\System32\wdmaud.drv'
27816e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd18340000 'C:\Windows\System32\wdmaud.drv'
27826e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd18340000 'C:\Windows\System32\wdmaud.drv'
27836e4.1c34: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000001124 pwszName=\Device\HarddiskVolume3\Windows\System32\msacm32.drv
27846e4.1c34: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000136ecf0
27856e4.1c34: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000136ecf0
27866e4.1c34: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=DF9222E8F115E50DE05D7AD2D27BDC071ADD62AF
27876e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
27886e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
27896e4.1c34: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package~31bf3856ad364e35~amd64~~10.0.17763.1.cat'; file='\Device\HarddiskVolume3\Windows\System32\msacm32.drv'
27906e4.1c34: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
27916e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
27926e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'mmdevapi.dll'.
27936e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'msacm32.dll'.
27946e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'winmmbase.dll'.
27956e4.1c34: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\msacm32.drv) WinVerifyTrust
27966e4.1c34: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\msacm32.drv
27976e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmmbase.dll'...
27986e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmmbase.dll' -> '\Device\HarddiskVolume3\Windows\System32\winmmbase.dll' [rcNtRedir=0xc0150008]
27996e4.1c34: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winmmbase.dll [redoing WinVerifyTrust]
28006e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
28016e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
28026e4.1c34: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\winmmbase.dll'
28036e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msacm32.dll'...
28046e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'msacm32.dll' -> '\Device\HarddiskVolume3\Windows\System32\msacm32.dll' [rcNtRedir=0xc0150008]
28056e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
28066e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
28076e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
28086e4.1c34: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\msacm32.dll) WinVerifyTrust
28096e4.1c34: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\msacm32.dll
28106e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mmdevapi.dll'...
28116e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'mmdevapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\mmdevapi.dll' [rcNtRedir=0xc0150008]
28126e4.1c34: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\MMDevAPI.dll
28136e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
28146e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
28156e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
28166e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
28176e4.1c34: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
28186e4.1c34: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msacm32.drv
28196e4.1c34: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msacm32.dll
28206e4.1c34: supR3HardenedDllNotificationCallback: load 00007ffd122a0000 LB 0x0001c000 C:\Windows\SYSTEM32\MSACM32.dll [fFlags=0x0]
28216e4.1c34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msacm32.dll
28226e4.1c34: supR3HardenedDllNotificationCallback: load 00007ffd18330000 LB 0x0000d000 C:\Windows\System32\msacm32.drv [fFlags=0x0]
28236e4.1c34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msacm32.drv
28246e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd18330000 'C:\Windows\System32\msacm32.drv'
28256e4.1c34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msacm32.drv
28266e4.1c34: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
28276e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd18330000 'C:\Windows\System32\msacm32.drv'
28286e4.1c34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msacm32.drv
28296e4.1c34: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
28306e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd18330000 'C:\Windows\System32\msacm32.drv'
28316e4.1c34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msacm32.drv
28326e4.1c34: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
28336e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd18330000 'C:\Windows\System32\msacm32.drv'
28346e4.1c34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msacm32.drv
28356e4.1c34: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
28366e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd18330000 'C:\Windows\System32\msacm32.drv'
28376e4.1c34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msacm32.drv
28386e4.1c34: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
28396e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd18330000 'C:\Windows\System32\msacm32.drv'
28406e4.1c34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msacm32.drv
28416e4.1c34: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
28426e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd18330000 'C:\Windows\System32\msacm32.drv'
28436e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd18330000 'C:\Windows\System32\msacm32.drv'
28446e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd18330000 'C:\Windows\System32\msacm32.drv'
28456e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd18330000 'C:\Windows\System32\msacm32.drv'
28466e4.1c34: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000119c pwszName=\Device\HarddiskVolume3\Windows\System32\midimap.dll
28476e4.1c34: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000136ecf0
28486e4.1c34: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000136ecf0
28496e4.1c34: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=FE1B51D5EFA4634DA5F3478BB920BDCB24116539
28506e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
28516e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
28526e4.1c34: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package~31bf3856ad364e35~amd64~~10.0.17763.1.cat'; file='\Device\HarddiskVolume3\Windows\System32\midimap.dll'
28536e4.1c34: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
28546e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
28556e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'winmm.dll'.
28566e4.1c34: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\midimap.dll) WinVerifyTrust
28576e4.1c34: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\midimap.dll
28586e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
28596e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume3\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
28606e4.1c34: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winmm.dll
28616e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
28626e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
28636e4.1c34: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
28646e4.1c34: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\midimap.dll
28656e4.1c34: supR3HardenedDllNotificationCallback: load 00007ffd172e0000 LB 0x0000a000 C:\Windows\System32\midimap.dll [fFlags=0x0]
28666e4.1c34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\midimap.dll
28676e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd172e0000 'C:\Windows\System32\midimap.dll'
28686e4.1c34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\midimap.dll
28696e4.1c34: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
28706e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd172e0000 'C:\Windows\System32\midimap.dll'
28716e4.1c34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\midimap.dll
28726e4.1c34: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
28736e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd172e0000 'C:\Windows\System32\midimap.dll'
28746e4.1c34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\midimap.dll
28756e4.1c34: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
28766e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd172e0000 'C:\Windows\System32\midimap.dll'
28776e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd41f30000 'C:\Windows\System32\winmm.dll'
28786e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd41f30000 'C:\Windows\System32\winmm.dll'
28796e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd41f30000 'C:\Windows\System32\winmm.dll'
28806e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd41f30000 'C:\Windows\System32\winmm.dll'
28816e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd41f30000 'C:\Windows\System32\winmm.dll'
28826e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd41f30000 'C:\Windows\System32\winmm.dll'
28836e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd41f30000 'C:\Windows\System32\winmm.dll'
28846e4.1c34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winmm.dll
28856e4.1c34: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\winmm.dll (Input=winmm.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
28866e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd41f30000 'C:\Windows\System32\winmm.dll'
28876e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd41f30000 'C:\Windows\System32\winmm.dll'
28886e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd41f30000 'C:\Windows\System32\winmm.dll'
28896e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd41f30000 'C:\Windows\System32\winmm.dll'
28906e4.1c34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dsound.dll
28916e4.1c34: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
28926e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd3d5d0000 'C:\Windows\system32\dsound.dll'
28936e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd41f30000 'C:\Windows\System32\winmm.dll'
28946e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd41f30000 'C:\Windows\System32\winmm.dll'
28956e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd41f30000 'C:\Windows\System32\winmm.dll'
28966e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd41f30000 'C:\Windows\System32\winmm.dll'
28976e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd41f30000 'C:\Windows\System32\winmm.dll'
28986e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd41f30000 'C:\Windows\System32\winmm.dll'
28996e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd058c0000 'C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL'
29006e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
29016e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
29026e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
29036e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
29046e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'win32u.dll'.
29056e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'gdi32.dll'.
29066e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'dwmapi.dll'.
29076e4.1c34: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\d3d9.dll) WinVerifyTrust
29086e4.1c34: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\d3d9.dll
29096e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dwmapi.dll'...
29106e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'dwmapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\dwmapi.dll' [rcNtRedir=0xc0150008]
29116e4.1c34: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dwmapi.dll
29126e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
29136e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
29146e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
29156e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
29166e4.1c34: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\win32u.dll [redoing WinVerifyTrust]
29176e4.1c34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll
29186e4.1c34: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
29196e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
29206e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
29216e4.1c34: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\win32u.dll'
29226e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
29236e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
29246e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
29256e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
29266e4.1c34: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\d3d9.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
29276e4.1c34: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\d3d9.dll
29286e4.1c34: supR3HardenedDllNotificationCallback: load 00007ffd0b590000 LB 0x0019e000 C:\Windows\system32\d3d9.dll [fFlags=0x0]
29296e4.1c34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\d3d9.dll
29306e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd0b590000 'C:\Windows\system32\d3d9.dll'
29316e4.1c34: \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igdumdim64.dll: Owner is administrators group.
29326e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
29336e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
29346e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
29356e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
29366e4.1c34: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igdumdim64.dll) WinVerifyTrust
29376e4.1c34: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igdumdim64.dll
29386e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
29396e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
29406e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
29416e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
29426e4.1c34: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igdumdim64.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
29436e4.1c34: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igdumdim64.dll
29446e4.1c34: supR3HardenedDllNotificationCallback: load 00007ffd023f0000 LB 0x00275000 C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igdumdim64.dll [fFlags=0x0]
29456e4.1c34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igdumdim64.dll
29466e4.1c34: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
29476e4.1c34: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
29486e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd45160000 'api-ms-win-core-synch-l1-2-0'
29496e4.1c34: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
29506e4.1c34: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
29516e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd45160000 'api-ms-win-core-fibers-l1-1-1'
29526e4.1c34: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
29536e4.1c34: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
29546e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd45160000 'api-ms-win-core-synch-l1-2-0'
29556e4.1c34: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
29566e4.1c34: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
29576e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd45160000 'api-ms-win-core-fibers-l1-1-1'
29586e4.1c34: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-l1-2-1) -> 0x0, fPresent=1
29596e4.1c34: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-l1-2-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
29606e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd45160000 'api-ms-win-core-localization-l1-2-1'
29616e4.1c34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\kernel32.dll
29626e4.1c34: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\kernel32.dll (Input=kernel32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
29636e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd47ba0000 'C:\Windows\System32\kernel32.dll'
29646e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd023f0000 'C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igdumdim64.dll'
29656e4.1c34: \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igd9dxva64.dll: Owner is administrators group.
29666e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
29676e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
29686e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
29696e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
29706e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ole32.dll'.
29716e4.1c34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'oleaut32.dll'.
29726e4.1c34: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igd9dxva64.dll) WinVerifyTrust
29736e4.1c34: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igd9dxva64.dll
29746e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
29756e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume3\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
29766e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
29776e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
29786e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
29796e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
29806e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
29816e4.1c34: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
29826e4.1c34: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igd9dxva64.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
29836e4.1c34: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igd9dxva64.dll
29846e4.1c34: supR3HardenedDllNotificationCallback: load 00007ffcd2f20000 LB 0x038ec000 C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igd9dxva64.dll [fFlags=0x0]
29856e4.1c34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igd9dxva64.dll
29866e4.1c34: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
29876e4.1c34: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
29886e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd45160000 'api-ms-win-core-synch-l1-2-0'
29896e4.1c34: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
29906e4.1c34: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
29916e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd45160000 'api-ms-win-core-fibers-l1-1-1'
29926e4.1c34: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
29936e4.1c34: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
29946e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd45160000 'api-ms-win-core-synch-l1-2-0'
29956e4.1c34: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
29966e4.1c34: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
29976e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd45160000 'api-ms-win-core-fibers-l1-1-1'
29986e4.1c34: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-l1-2-1) -> 0x0, fPresent=1
29996e4.1c34: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-l1-2-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
30006e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd45160000 'api-ms-win-core-localization-l1-2-1'
30016e4.1c34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\kernel32.dll
30026e4.1c34: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\kernel32.dll (Input=kernel32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
30036e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd47ba0000 'C:\Windows\System32\kernel32.dll'
30046e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcd2f20000 'C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igd9dxva64.dll'
30056e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd45760000 'C:\Windows\System32\gdi32.dll'
30066e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
30076e4.31a8: '\Device\HarddiskVolume3\Windows\System32\tzres.dll' has no imports
30086e4.31a8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\tzres.dll)
30096e4.31a8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\tzres.dll
30106e4.31a8: supR3HardenedMonitor_NtCreateSection: NtMapViewOfSection failed on 00000000000013a8 (hFile=0000000000001118) with 0xc0000022 -> STATUS_TRUST_FAILURE
30116e4.31a8: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\tzres.dll [avoiding WinVerifyTrust]
30126e4.31a8: supR3HardenedMonitor_NtCreateSection: NtMapViewOfSection failed on 0000000000001118 (hFile=00000000000013a8) with 0xc0000022 -> STATUS_TRUST_FAILURE
30136e4.31a8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000bfc pwszName=\Device\HarddiskVolume3\Windows\System32\tzres.dll
30146e4.31a8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000136ecf0
30156e4.31a8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000136ecf0
30166e4.31a8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=11B44AC70070922FAD9F85E3435AFD4DDAE1C97E
30176e4.31a8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
30186e4.31a8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
30196e4.31a8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_193_for_KB4493509~31bf3856ad364e35~amd64~~10.0.1.6.cat'; file='\Device\HarddiskVolume3\Windows\System32\tzres.dll'
30206e4.31a8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
30216e4.31a8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\tzres.dll'
30226e4.31a8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
30236e4.31a8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
30246e4.31a8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'ws2_32.dll'.
30256e4.31a8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #22 'rpcrt4.dll'.
30266e4.31a8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\mswsock.dll) WinVerifyTrust
30276e4.31a8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\mswsock.dll
30286e4.31a8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
30296e4.31a8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
30306e4.31a8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
30316e4.31a8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
30326e4.31a8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ws2_32.dll
30336e4.31a8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\mswsock.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
30346e4.31a8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\mswsock.dll
30356e4.31a8: supR3HardenedDllNotificationCallback: load 00007ffd43b40000 LB 0x00067000 C:\Windows\system32\mswsock.dll [fFlags=0x0]
30366e4.31a8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\mswsock.dll
30376e4.31a8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43b40000 'C:\Windows\system32\mswsock.dll'
30386e4.f20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igdumdim64.dll
30396e4.f20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igdumdim64.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
30406e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd023f0000 'C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igdumdim64.dll'
30416e4.f20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igd9dxva64.dll
30426e4.f20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igd9dxva64.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
30436e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcd2f20000 'C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igd9dxva64.dll'
30446e4.f20: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(ext-ms-win-core-resourcepolicy-l1-1-0.dll) -> 0x0, fPresent=1
30456e4.f20: supR3HardenedMonitor_LdrLoadDll: pName=ext-ms-win-core-resourcepolicy-l1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
30466e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd42650000 'ext-ms-win-core-resourcepolicy-l1-1-0.dll'
30476e4.f20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igdumdim64.dll
30486e4.f20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igdumdim64.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
30496e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd023f0000 'C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igdumdim64.dll'
30506e4.f20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igd9dxva64.dll
30516e4.f20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igd9dxva64.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
30526e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcd2f20000 'C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igd9dxva64.dll'
30536e4.f20: \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igdinfo64.dll: Owner is administrators group.
30546e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
30556e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
30566e4.f20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'advapi32.dll'.
30576e4.f20: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igdinfo64.dll) WinVerifyTrust
30586e4.f20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igdinfo64.dll
30596e4.f20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
30606e4.f20: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
30616e4.f20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igdinfo64.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
30626e4.f20: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igdinfo64.dll
30636e4.f20: supR3HardenedDllNotificationCallback: load 00007ffd07cc0000 LB 0x00020000 C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igdinfo64.dll [fFlags=0x0]
30646e4.f20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igdinfo64.dll
30656e4.f20: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
30666e4.f20: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
30676e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd45160000 'api-ms-win-core-synch-l1-2-0'
30686e4.f20: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
30696e4.f20: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
30706e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd45160000 'api-ms-win-core-fibers-l1-1-1'
30716e4.f20: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-l1-2-1) -> 0x0, fPresent=1
30726e4.f20: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-l1-2-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
30736e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd45160000 'api-ms-win-core-localization-l1-2-1'
30746e4.f20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\kernel32.dll
30756e4.f20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\kernel32.dll (Input=kernel32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
30766e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd47ba0000 'C:\Windows\System32\kernel32.dll'
30776e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd07cc0000 'C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igdinfo64.dll'
30786e4.f20: \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igc64.dll: Owner is administrators group.
30796e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
30806e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
30816e4.f20: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igc64.dll) WinVerifyTrust
30826e4.f20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igc64.dll
30836e4.f20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igc64.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
30846e4.f20: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igc64.dll
30856e4.f20: supR3HardenedDllNotificationCallback: load 00007ffd3a720000 LB 0x01f7c000 C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igc64.dll [fFlags=0x0]
30866e4.f20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igc64.dll
30876e4.f20: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
30886e4.f20: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
30896e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd45160000 'api-ms-win-core-synch-l1-2-0'
30906e4.f20: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
30916e4.f20: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
30926e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd45160000 'api-ms-win-core-fibers-l1-1-1'
30936e4.f20: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-l1-2-1) -> 0x0, fPresent=1
30946e4.f20: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-l1-2-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
30956e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd45160000 'api-ms-win-core-localization-l1-2-1'
30966e4.f20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\kernel32.dll
30976e4.f20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\kernel32.dll (Input=kernel32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
30986e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd47ba0000 'C:\Windows\System32\kernel32.dll'
30996e4.f20: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-string-l1-1-0) -> 0x0, fPresent=1
31006e4.f20: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-string-l1-1-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
31016e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd45160000 'api-ms-win-core-string-l1-1-0'
31026e4.f20: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-datetime-l1-1-1) -> 0x0, fPresent=1
31036e4.f20: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-datetime-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
31046e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd45160000 'api-ms-win-core-datetime-l1-1-1'
31056e4.f20: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-obsolete-l1-2-0) -> 0x0, fPresent=1
31066e4.f20: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-obsolete-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
31076e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd45160000 'api-ms-win-core-localization-obsolete-l1-2-0'
31086e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd3a720000 'C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igc64.dll'
31096e4.f20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\d3d9.dll
31106e4.f20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\d3d9.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
31116e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd0b590000 'C:\Windows\system32\d3d9.dll'
31126e4.f20: supR3HardenedDllNotificationCallback: Unload 00007ffd07cc0000 LB 0x00020000 C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igdinfo64.dll [flags=0x0]
31136e4.f20: supR3HardenedDllNotificationCallback: Unload 00007ffd3a720000 LB 0x01f7c000 C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igc64.dll [flags=0x0]
31146e4.f20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igdumdim64.dll
31156e4.f20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igdumdim64.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
31166e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd023f0000 'C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igdumdim64.dll'
31176e4.f20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igd9dxva64.dll
31186e4.f20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igd9dxva64.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
31196e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcd2f20000 'C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igd9dxva64.dll'
31206e4.f20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igdumdim64.dll
31216e4.f20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igdumdim64.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
31226e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd023f0000 'C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igdumdim64.dll'
31236e4.f20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igd9dxva64.dll
31246e4.f20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igd9dxva64.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
31256e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcd2f20000 'C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igd9dxva64.dll'
31266e4.f20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igdinfo64.dll
31276e4.f20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igdinfo64.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
31286e4.f20: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igdinfo64.dll
31296e4.f20: supR3HardenedDllNotificationCallback: load 00007ffd07cc0000 LB 0x00020000 C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igdinfo64.dll [fFlags=0x0]
31306e4.f20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igdinfo64.dll
31316e4.f20: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
31326e4.f20: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
31336e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd45160000 'api-ms-win-core-synch-l1-2-0'
31346e4.f20: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
31356e4.f20: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
31366e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd45160000 'api-ms-win-core-fibers-l1-1-1'
31376e4.f20: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-l1-2-1) -> 0x0, fPresent=1
31386e4.f20: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-l1-2-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
31396e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd45160000 'api-ms-win-core-localization-l1-2-1'
31406e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd47ba0000 'C:\Windows\System32\kernel32.dll'
31416e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd07cc0000 'C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igdinfo64.dll'
31426e4.f20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igc64.dll
31436e4.f20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igc64.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
31446e4.f20: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igc64.dll
31456e4.f20: supR3HardenedDllNotificationCallback: load 00007ffd3a720000 LB 0x01f7c000 C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igc64.dll [fFlags=0x0]
31466e4.f20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igc64.dll
31476e4.f20: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
31486e4.f20: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
31496e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd45160000 'api-ms-win-core-synch-l1-2-0'
31506e4.f20: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
31516e4.f20: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
31526e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd45160000 'api-ms-win-core-fibers-l1-1-1'
31536e4.f20: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-l1-2-1) -> 0x0, fPresent=1
31546e4.f20: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-l1-2-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
31556e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd45160000 'api-ms-win-core-localization-l1-2-1'
31566e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd47ba0000 'C:\Windows\System32\kernel32.dll'
31576e4.f20: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-string-l1-1-0) -> 0x0, fPresent=1
31586e4.f20: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-string-l1-1-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
31596e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd45160000 'api-ms-win-core-string-l1-1-0'
31606e4.f20: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-datetime-l1-1-1) -> 0x0, fPresent=1
31616e4.f20: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-datetime-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
31626e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd45160000 'api-ms-win-core-datetime-l1-1-1'
31636e4.f20: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-obsolete-l1-2-0) -> 0x0, fPresent=1
31646e4.f20: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-obsolete-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
31656e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd45160000 'api-ms-win-core-localization-obsolete-l1-2-0'
31666e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd3a720000 'C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igc64.dll'
31676e4.f20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\d3d9.dll
31686e4.f20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\d3d9.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
31696e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd0b590000 'C:\Windows\system32\d3d9.dll'
31706e4.f20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igdumdim64.dll
31716e4.f20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igdumdim64.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
31726e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd023f0000 'C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igdumdim64.dll'
31736e4.f20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igd9dxva64.dll
31746e4.f20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igd9dxva64.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
31756e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcd2f20000 'C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igd9dxva64.dll'
31766e4.f20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igdumdim64.dll
31776e4.f20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igdumdim64.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
31786e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd023f0000 'C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igdumdim64.dll'
31796e4.f20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igd9dxva64.dll
31806e4.f20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igd9dxva64.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
31816e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcd2f20000 'C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igd9dxva64.dll'
31826e4.f20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igc64.dll
31836e4.f20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igc64.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
31846e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd3a720000 'C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igc64.dll'
31856e4.f20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\d3d9.dll
31866e4.f20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\d3d9.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
31876e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd0b590000 'C:\Windows\system32\d3d9.dll'
31886e4.1c34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dsound.dll
31896e4.1c34: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
31906e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd3d5d0000 'C:\Windows\system32\dsound.dll'
31916e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd41f30000 'C:\Windows\System32\winmm.dll'
31926e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd41f30000 'C:\Windows\System32\winmm.dll'
31936e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd41f30000 'C:\Windows\System32\winmm.dll'
31946e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd41f30000 'C:\Windows\System32\winmm.dll'
31956e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd41f30000 'C:\Windows\System32\winmm.dll'
31966e4.1c34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd41f30000 'C:\Windows\System32\winmm.dll'
31976e4.3720: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dsound.dll
31986e4.3720: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
31996e4.3720: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd3d5d0000 'C:\Windows\system32\dsound.dll'
32006e4.3720: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winmm.dll
32016e4.3720: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\winmm.dll (Input=winmm.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
32026e4.3720: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd41f30000 'C:\Windows\System32\winmm.dll'
32036e4.3720: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd41f30000 'C:\Windows\System32\winmm.dll'
32046e4.3720: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd41f30000 'C:\Windows\System32\winmm.dll'
32056e4.3720: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd41f30000 'C:\Windows\System32\winmm.dll'
32066e4.3720: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd41f30000 'C:\Windows\System32\winmm.dll'
32076e4.3720: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd41f30000 'C:\Windows\System32\winmm.dll'
32086e4.3720: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd41f30000 'C:\Windows\System32\winmm.dll'
32096e4.3720: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd41f30000 'C:\Windows\System32\winmm.dll'
32106e4.3720: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd41f30000 'C:\Windows\System32\winmm.dll'
32116e4.1724: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
32126e4.1724: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
32136e4.1724: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
32146e4.1724: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'rpcrt4.dll'.
32156e4.1724: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'combase.dll'.
32166e4.1724: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #20 'shcore.dll'.
32176e4.1724: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #21 'win32u.dll'.
32186e4.1724: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #22 'textinputframework.dll'.
32196e4.1724: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'inputhost.dll'.
32206e4.1724: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #43 'user32.dll'.
32216e4.1724: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\Windows.UI.dll) WinVerifyTrust
32226e4.1724: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\Windows.UI.dll
32236e4.1724: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
32246e4.1724: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
32256e4.1724: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'inputhost.dll'...
32266e4.1724: supR3HardenedWinVerifyCacheProcessImportTodos: 'inputhost.dll' -> '\Device\HarddiskVolume3\Windows\System32\inputhost.dll' [rcNtRedir=0xc0150008]
32276e4.1724: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
32286e4.1724: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
32296e4.1724: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
32306e4.1724: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'coremessaging.dll'.
32316e4.1724: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'twinapi.appcore.dll'.
32326e4.1724: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #41 'coreuicomponents.dll'.
32336e4.1724: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #46 'd2d1.dll'.
32346e4.1724: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #47 'd3d11.dll'.
32356e4.1724: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #48 'propsys.dll'.
32366e4.1724: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #50 'shcore.dll'.
32376e4.1724: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #51 'win32u.dll'.
32386e4.1724: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #54 'combase.dll'.
32396e4.1724: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\InputHost.dll) WinVerifyTrust
32406e4.1724: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\InputHost.dll
32416e4.1724: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'textinputframework.dll'...
32426e4.1724: supR3HardenedWinVerifyCacheProcessImportTodos: 'textinputframework.dll' -> '\Device\HarddiskVolume3\Windows\System32\textinputframework.dll' [rcNtRedir=0xc0150008]
32436e4.1724: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\TextInputFramework.dll
32446e4.1724: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
32456e4.1724: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
32466e4.1724: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shcore.dll'...
32476e4.1724: supR3HardenedWinVerifyCacheProcessImportTodos: 'shcore.dll' -> '\Device\HarddiskVolume3\Windows\System32\shcore.dll' [rcNtRedir=0xc0150008]
32486e4.1724: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\SHCore.dll
32496e4.1724: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
32506e4.1724: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
32516e4.1724: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\combase.dll
32526e4.1724: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
32536e4.1724: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
32546e4.1724: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
32556e4.1724: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
32566e4.1724: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
32576e4.1724: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
32586e4.1724: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
32596e4.1724: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
32606e4.1724: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shcore.dll'...
32616e4.1724: supR3HardenedWinVerifyCacheProcessImportTodos: 'shcore.dll' -> '\Device\HarddiskVolume3\Windows\System32\shcore.dll' [rcNtRedir=0xc0150008]
32626e4.1724: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\SHCore.dll
32636e4.1724: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'propsys.dll'...
32646e4.1724: supR3HardenedWinVerifyCacheProcessImportTodos: 'propsys.dll' -> '\Device\HarddiskVolume3\Windows\System32\propsys.dll' [rcNtRedir=0xc0150008]
32656e4.1724: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\propsys.dll
32666e4.1724: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'd3d11.dll'...
32676e4.1724: supR3HardenedWinVerifyCacheProcessImportTodos: 'd3d11.dll' -> '\Device\HarddiskVolume3\Windows\System32\d3d11.dll' [rcNtRedir=0xc0150008]
32686e4.1724: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\d3d11.dll
32696e4.1724: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'd2d1.dll'...
32706e4.1724: supR3HardenedWinVerifyCacheProcessImportTodos: 'd2d1.dll' -> '\Device\HarddiskVolume3\Windows\System32\d2d1.dll' [rcNtRedir=0xc0150008]
32716e4.1724: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd43700000 'C:\Windows\system32\rsaenh.dll'
32726e4.1724: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd44f00000 'C:\Windows\System32\crypt32.dll'
32736e4.1724: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
32746e4.1724: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\d2d1.dll) WinVerifyTrust
32756e4.1724: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\d2d1.dll
32766e4.1724: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'coreuicomponents.dll'...
32776e4.1724: supR3HardenedWinVerifyCacheProcessImportTodos: 'coreuicomponents.dll' -> '\Device\HarddiskVolume3\Windows\System32\coreuicomponents.dll' [rcNtRedir=0xc0150008]
32786e4.1724: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\CoreUIComponents.dll
32796e4.1724: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'twinapi.appcore.dll'...
32806e4.1724: supR3HardenedWinVerifyCacheProcessImportTodos: 'twinapi.appcore.dll' -> '\Device\HarddiskVolume3\Windows\System32\twinapi.appcore.dll' [rcNtRedir=0xc0150008]
32816e4.1724: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\twinapi.appcore.dll
32826e4.1724: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'coremessaging.dll'...
32836e4.1724: supR3HardenedWinVerifyCacheProcessImportTodos: 'coremessaging.dll' -> '\Device\HarddiskVolume3\Windows\System32\coremessaging.dll' [rcNtRedir=0xc0150008]
32846e4.1724: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\CoreMessaging.dll
32856e4.1724: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
32866e4.1724: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
32876e4.1724: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcp_win.dll
32886e4.1724: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
32896e4.1724: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
32906e4.1724: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\Windows.UI.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
32916e4.1724: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\Windows.UI.dll
32926e4.1724: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\InputHost.dll
32936e4.1724: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\d2d1.dll
32946e4.1724: supR3HardenedDllNotificationCallback: load 00007ffd411b0000 LB 0x005be000 C:\Windows\System32\d2d1.dll [fFlags=0x0]
32956e4.1724: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\d2d1.dll
32966e4.1724: supR3HardenedDllNotificationCallback: load 00007ffd2ea00000 LB 0x000cc000 C:\Windows\System32\InputHost.dll [fFlags=0x0]
32976e4.1724: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\InputHost.dll
32986e4.1724: supR3HardenedDllNotificationCallback: load 00007ffd2e430000 LB 0x0013a000 C:\Windows\System32\Windows.UI.dll [fFlags=0x0]
32996e4.1724: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\Windows.UI.dll
33006e4.1724: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd2e430000 'C:\Windows\System32\Windows.UI.dll'
33016e4.1e90: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\avrt.dll
33026e4.1e90: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\avrt.dll (Input=avrt.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
33036e4.1e90: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd400f0000 'C:\Windows\System32\avrt.dll'
33046e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd023f0000 'C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igdumdim64.dll'
33056e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcd2f20000 'C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igd9dxva64.dll'
33066e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd023f0000 'C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igdumdim64.dll'
33076e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcd2f20000 'C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igd9dxva64.dll'
33086e4.f20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igc64.dll
33096e4.f20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igc64.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
33106e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd3a720000 'C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igc64.dll'
33116e4.f20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\d3d9.dll
33126e4.f20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\d3d9.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
33136e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd0b590000 'C:\Windows\system32\d3d9.dll'
33146e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd023f0000 'C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igdumdim64.dll'
33156e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcd2f20000 'C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igd9dxva64.dll'
33166e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd023f0000 'C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igdumdim64.dll'
33176e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcd2f20000 'C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igd9dxva64.dll'
33186e4.f20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igc64.dll
33196e4.f20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igc64.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
33206e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd3a720000 'C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igc64.dll'
33216e4.f20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\d3d9.dll
33226e4.f20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\d3d9.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
33236e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd0b590000 'C:\Windows\system32\d3d9.dll'
33246e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd023f0000 'C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igdumdim64.dll'
33256e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcd2f20000 'C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igd9dxva64.dll'
33266e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd023f0000 'C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igdumdim64.dll'
33276e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcd2f20000 'C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igd9dxva64.dll'
33286e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd3a720000 'C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igc64.dll'
33296e4.f20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\d3d9.dll
33306e4.f20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\d3d9.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
33316e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd0b590000 'C:\Windows\system32\d3d9.dll'
33326e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd023f0000 'C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igdumdim64.dll'
33336e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcd2f20000 'C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igd9dxva64.dll'
33346e4.f20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igdumdim64.dll
33356e4.f20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igdumdim64.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
33366e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd023f0000 'C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igdumdim64.dll'
33376e4.f20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igd9dxva64.dll
33386e4.f20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igd9dxva64.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
33396e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcd2f20000 'C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igd9dxva64.dll'
33406e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd3a720000 'C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igc64.dll'
33416e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd0b590000 'C:\Windows\system32\d3d9.dll'
33426e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd023f0000 'C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igdumdim64.dll'
33436e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcd2f20000 'C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igd9dxva64.dll'
33446e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd023f0000 'C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igdumdim64.dll'
33456e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcd2f20000 'C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igd9dxva64.dll'
33466e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd3a720000 'C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igc64.dll'
33476e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd0b590000 'C:\Windows\system32\d3d9.dll'
33486e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd023f0000 'C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igdumdim64.dll'
33496e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcd2f20000 'C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igd9dxva64.dll'
33506e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd023f0000 'C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igdumdim64.dll'
33516e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcd2f20000 'C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igd9dxva64.dll'
33526e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd3a720000 'C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_16ed7d82b93e4f68\igc64.dll'
33536e4.f20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd0b590000 'C:\Windows\system32\d3d9.dll'
33541030.2c68: supR3HardNtChildWaitFor[2]: Quitting: ExitCode=0xcfffffff (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 178355 ms, the end);
335512c4.39c0: supR3HardNtChildWaitFor[1]: Quitting: ExitCode=0xcfffffff (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 178778 ms, the end);

© 2024 Oracle Support Privacy / Do Not Sell My Info Terms of Use Trademark Policy Automated Access Etiquette