VirtualBox

Ticket #19358: Windows 10 1809-2020-02-28-08-47-19.log

File Windows 10 1809-2020-02-28-08-47-19.log, 406.1 KB (added by VeHav2GoVeeper, 5 years ago)
Line 
123a64.23560: Log file opened: 6.1.4r136177 g_hStartupLog=0000000000000014 g_uNtVerCombined=0x611db110
223a64.23560: \SystemRoot\System32\ntdll.dll:
323a64.23560: CreationTime: 2020-01-14T21:20:24.992404300Z
423a64.23560: LastWriteTime: 2020-01-03T03:35:05.302579400Z
523a64.23560: ChangeTime: 2020-01-14T22:54:45.661976200Z
623a64.23560: FileAttributes: 0x20
723a64.23560: Size: 0x198080
823a64.23560: NT Headers: 0xe0
923a64.23560: Timestamp: 0x5e0eb67f
1023a64.23560: Machine: 0x8664 - amd64
1123a64.23560: Timestamp: 0x5e0eb67f
1223a64.23560: Image Version: 6.1
1323a64.23560: SizeOfImage: 0x19f000 (1699840)
1423a64.23560: Resource Dir: 0x142000 LB 0x5a038
1523a64.23560: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
1623a64.23560: [Raw version resource data: 0x1420f0 LB 0x38c, codepage 0x0 (reserved 0x0)]
1723a64.23560: ProductName: Microsoft® Windows® Operating System
1823a64.23560: ProductVersion: 6.1.7601.24545
1923a64.23560: FileVersion: 6.1.7601.24545 (win7sp1_ldr_escrow.200102-1707)
2023a64.23560: FileDescription: NT Layer DLL
2123a64.23560: \SystemRoot\System32\kernel32.dll:
2223a64.23560: CreationTime: 2020-01-14T21:20:21.987377500Z
2323a64.23560: LastWriteTime: 2020-01-03T03:33:39.604000000Z
2423a64.23560: ChangeTime: 2020-01-14T22:54:46.285977300Z
2523a64.23560: FileAttributes: 0x20
2623a64.23560: Size: 0x11be00
2723a64.23560: NT Headers: 0xe0
2823a64.23560: Timestamp: 0x5e0eb6bc
2923a64.23560: Machine: 0x8664 - amd64
3023a64.23560: Timestamp: 0x5e0eb6bc
3123a64.23560: Image Version: 6.1
3223a64.23560: SizeOfImage: 0x11f000 (1175552)
3323a64.23560: Resource Dir: 0x116000 LB 0x530
3423a64.23560: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
3523a64.23560: [Raw version resource data: 0x1160b0 LB 0x3b0, codepage 0x0 (reserved 0x0)]
3623a64.23560: ProductName: Microsoft® Windows® Operating System
3723a64.23560: ProductVersion: 6.1.7601.24545
3823a64.23560: FileVersion: 6.1.7601.24545 (win7sp1_ldr_escrow.200102-1707)
3923a64.23560: FileDescription: Windows NT BASE API Client DLL
4023a64.23560: \SystemRoot\System32\KernelBase.dll:
4123a64.23560: CreationTime: 2020-01-14T21:20:21.737377200Z
4223a64.23560: LastWriteTime: 2020-01-03T03:33:39.604000000Z
4323a64.23560: ChangeTime: 2020-01-14T22:54:46.285977300Z
4423a64.23560: FileAttributes: 0x20
4523a64.23560: Size: 0x63c00
4623a64.23560: NT Headers: 0xe8
4723a64.23560: Timestamp: 0x5e0eb6bd
4823a64.23560: Machine: 0x8664 - amd64
4923a64.23560: Timestamp: 0x5e0eb6bd
5023a64.23560: Image Version: 6.1
5123a64.23560: SizeOfImage: 0x67000 (421888)
5223a64.23560: Resource Dir: 0x65000 LB 0x538
5323a64.23560: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
5423a64.23560: [Raw version resource data: 0x650b0 LB 0x3b8, codepage 0x0 (reserved 0x0)]
5523a64.23560: ProductName: Microsoft® Windows® Operating System
5623a64.23560: ProductVersion: 6.1.7601.24545
5723a64.23560: FileVersion: 6.1.7601.24545 (win7sp1_ldr_escrow.200102-1707)
5823a64.23560: FileDescription: Windows NT BASE API Client DLL
5923a64.23560: \SystemRoot\System32\apisetschema.dll:
6023a64.23560: CreationTime: 2020-01-14T21:20:21.327376600Z
6123a64.23560: LastWriteTime: 2020-01-03T03:33:11.406000000Z
6223a64.23560: ChangeTime: 2020-01-14T22:54:45.318775600Z
6323a64.23560: FileAttributes: 0x20
6423a64.23560: Size: 0x1c00
6523a64.23560: NT Headers: 0xc0
6623a64.23560: Timestamp: 0x5e0eb63f
6723a64.23560: Machine: 0x8664 - amd64
6823a64.23560: Timestamp: 0x5e0eb63f
6923a64.23560: Image Version: 6.1
7023a64.23560: SizeOfImage: 0x50000 (327680)
7123a64.23560: Resource Dir: 0x30000 LB 0x408
7223a64.23560: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
7323a64.23560: [Raw version resource data: 0x30060 LB 0x3a4, codepage 0x0 (reserved 0x0)]
7423a64.23560: ProductName: Microsoft® Windows® Operating System
7523a64.23560: ProductVersion: 6.1.7601.24545
7623a64.23560: FileVersion: 6.1.7601.24545 (win7sp1_ldr_escrow.200102-1707)
7723a64.23560: FileDescription: ApiSet Schema DLL
7823a64.23560: supR3HardenedWinFindAdversaries: 0x0
7923a64.23560: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox'
8023a64.23560: Calling main()
8123a64.23560: SUPR3HardenedMain: pszProgName=VirtualBoxVM fFlags=0x2
8223a64.23560: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox'
8323a64.23560: SUPR3HardenedMain: Respawn #1
8423a64.23560: System32: \Device\HarddiskVolume1\Windows\System32
8523a64.23560: WinSxS: \Device\HarddiskVolume1\Windows\winsxs
8623a64.23560: KnownDllPath: C:\Windows\system32
8723a64.23560: supR3HardenedWinInit: Performing a limited self purification...
8823a64.23560: supHardNtVpScanVirtualMemory: enmKind=SELF_PURIFICATION
8923a64.23560: *0000000000000000-000000000000ffff 0x0001/0x0000 0x0000000
9023a64.23560: *0000000000010000-000000000001ffff 0x0004/0x0004 0x0040000
9123a64.23560: 0000000000020000-000000000002ffff 0x0001/0x0000 0x0000000
9223a64.23560: *0000000000030000-0000000000033fff 0x0002/0x0002 0x0040000
9323a64.23560: 0000000000034000-000000000003ffff 0x0001/0x0000 0x0000000
9423a64.23560: *0000000000040000-0000000000040fff 0x0004/0x0004 0x0020000
9523a64.23560: 0000000000041000-000000000006ffff 0x0001/0x0000 0x0000000
9623a64.23560: *0000000000070000-0000000000075fff 0x0004/0x0004 0x0020000
9723a64.23560: 0000000000076000-000000000016ffff 0x0000/0x0004 0x0020000
9823a64.23560: *0000000000170000-00000000001d6fff 0x0002/0x0002 0x0040000
9923a64.23560: 00000000001d7000-00000000001dffff 0x0001/0x0000 0x0000000
10023a64.23560: *00000000001e0000-0000000000299fff 0x0000/0x0004 0x0020000
10123a64.23560: 000000000029a000-000000000029bfff 0x0104/0x0004 0x0020000
10223a64.23560: 000000000029c000-00000000002dffff 0x0004/0x0004 0x0020000
10323a64.23560: *00000000002e0000-000000000047ffff 0x0004/0x0004 0x0020000
10423a64.23560: 0000000000480000-00000000004bffff 0x0001/0x0000 0x0000000
10523a64.23560: *00000000004c0000-000000000053ffff 0x0004/0x0004 0x0020000
10623a64.23560: *0000000000540000-0000000000553fff 0x0004/0x0004 0x0020000
10723a64.23560: 0000000000554000-000000000063ffff 0x0000/0x0004 0x0020000
10823a64.23560: 0000000000640000-00000000771fffff 0x0001/0x0000 0x0000000
10923a64.23560: *0000000077200000-0000000077200fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\kernel32.dll
11023a64.23560: 0000000077201000-000000007729bfff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\kernel32.dll
11123a64.23560: 000000007729c000-0000000077309fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\kernel32.dll
11223a64.23560: 000000007730a000-000000007730bfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\kernel32.dll
11323a64.23560: 000000007730c000-000000007731efff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\kernel32.dll
11423a64.23560: 000000007731f000-000000007741ffff 0x0001/0x0000 0x0000000
11523a64.23560: *0000000077420000-0000000077420fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
11623a64.23560: 0000000077421000-0000000077544fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
11723a64.23560: 0000000077545000-0000000077546fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
11823a64.23560: 0000000077547000-0000000077548fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
11923a64.23560: 0000000077549000-000000007754afff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
12023a64.23560: 000000007754b000-000000007754dfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
12123a64.23560: 000000007754e000-0000000077550fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
12223a64.23560: 0000000077551000-0000000077553fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
12323a64.23560: 0000000077554000-00000000775befff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
12423a64.23560: 00000000775bf000-000000007efdffff 0x0001/0x0000 0x0000000
12523a64.23560: *000000007efe0000-000000007efe4fff 0x0002/0x0002 0x0040000
12623a64.23560: 000000007efe5000-000000007f0dffff 0x0000/0x0002 0x0040000
12723a64.23560: *000000007f0e0000-000000007ffdffff 0x0000/0x0002 0x0020000
12823a64.23560: *000000007ffe0000-000000007ffe0fff 0x0002/0x0002 0x0020000
12923a64.23560: 000000007ffe1000-000000007ffeffff 0x0000/0x0002 0x0020000
13023a64.23560: 000000007fff0000-000000013f2cffff 0x0001/0x0000 0x0000000
13123a64.23560: *000000013f2d0000-000000013f2d0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
13223a64.23560: 000000013f2d1000-000000013f346fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
13323a64.23560: 000000013f347000-000000013f347fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
13423a64.23560: 000000013f348000-000000013f38ffff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
13523a64.23560: 000000013f390000-000000013f392fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
13623a64.23560: 000000013f393000-000000013f395fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
13723a64.23560: 000000013f396000-000000013f398fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
13823a64.23560: 000000013f399000-000000013f399fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
13923a64.23560: 000000013f39a000-000000013f39bfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
14023a64.23560: 000000013f39c000-000000013f39cfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
14123a64.23560: 000000013f39d000-000000013f3e5fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
14223a64.23560: 000000013f3e6000-000007fefd03ffff 0x0001/0x0000 0x0000000
14323a64.23560: *000007fefd040000-000007fefd040fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\KernelBase.dll
14423a64.23560: 000007fefd041000-000007fefd087fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\KernelBase.dll
14523a64.23560: 000007fefd088000-000007fefd09cfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\KernelBase.dll
14623a64.23560: 000007fefd09d000-000007fefd09efff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\KernelBase.dll
14723a64.23560: 000007fefd09f000-000007fefd0a6fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\KernelBase.dll
14823a64.23560: 000007fefd0a7000-000007feff71ffff 0x0001/0x0000 0x0000000
14923a64.23560: *000007feff720000-000007feff720fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\apisetschema.dll
15023a64.23560: 000007feff721000-000007fffffaffff 0x0001/0x0000 0x0000000
15123a64.23560: *000007fffffb0000-000007fffffd2fff 0x0002/0x0002 0x0040000
15223a64.23560: 000007fffffd3000-000007fffffdcfff 0x0001/0x0000 0x0000000
15323a64.23560: *000007fffffdd000-000007fffffdefff 0x0004/0x0004 0x0020000
15423a64.23560: *000007fffffdf000-000007fffffdffff 0x0004/0x0004 0x0020000
15523a64.23560: *000007fffffe0000-000007fffffeffff 0x0001/0x0002 0x0020000
15623a64.23560: apisetschema.dll: timestamp 0x5e0eb63f (rc=VINF_SUCCESS)
15723a64.23560: kernelbase.dll: timestamp 0x5e0eb6bd (rc=VINF_SUCCESS)
15823a64.23560: VirtualBoxVM.exe: timestamp 0x5e4c1d19 (rc=VINF_SUCCESS)
15923a64.23560: kernel32.dll: timestamp 0x5e0eb6bc (rc=VINF_SUCCESS)
16023a64.23560: '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
16123a64.23560: '\Device\HarddiskVolume1\Windows\System32\apisetschema.dll' has no imports
16223a64.23560: '\Device\HarddiskVolume1\Windows\System32\ntdll.dll' has no imports
16323a64.23560: supR3HardenedWinInit: SUPHARDNTVPKIND_SELF_PURIFICATION_LIMITED -> VINF_SUCCESS, cFixes=0
16423a64.23560: '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
16523a64.23560: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe)
16623a64.23560: supR3HardNtEnableThreadCreationEx:
16723a64.23560: supR3HardNtDisableThreadCreation: pvLdrInitThunk=0000000077463730 pvNtTerminateThread=0000000077489cd0
16823a64.23560: supR3HardenedWinDoReSpawn(1): New child 1f168.125e8 [kernel32].
16923a64.23560: supR3HardNtChildGatherData: PebBaseAddress=000007fffffdd000 cbPeb=0x380
17023a64.23560: supR3HardNtPuChFindNtdll: uNtDllParentAddr=0000000077420000 uNtDllChildAddr=0000000077420000
17123a64.23560: supR3HardenedWinSetupChildInit: uLdrInitThunk=0000000077463730
17223a64.23560: supR3HardenedWinSetupChildInit: Initial context:
173 rax=0000000000000000 rbx=0000000000000000 rcx=000000013f2d7900 rdx=000007fffffdd000
174 rsi=0000000000000000 rdi=0000000000000000 r8 =0000000000000000 r9 =0000000000000000
175 r10=0000000000000000 r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
176 r14=0000000000000000 r15=0000000000000000 P1=0000000000000000 P2=0000000000000000
177 rip=0000000077473710 rsp=00000000002efc48 rbp=0000000000000000 ctxflags=0010001b
178 cs=0033 ss=002b ds=0000 es=0000 fs=0000 gs=0000 eflags=00000200 mxcrx=00001f80
179 P3=0000000000000000 P4=0000000000000000 P5=0000000000000000 P6=0000000000000000
180 dr0=0000000000000000 dr1=0000000000000000 dr2=0000000000000000 dr3=0000000000000000
181 dr6=0000000000000000 dr7=0000000000000000 vcr=0000000000000000 dcr=0000000000000000
182 lbt=0000000000000000 lbf=0000000000000000 lxt=0000000000000000 lxf=0000000000000000
18323a64.23560: supR3HardenedWinSetupChildInit: Start child.
18423a64.23560: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 1 ms.
18523a64.23560: supR3HardNtChildPurify: Startup delay kludge #1/0: 264 ms, 33 sleeps
18623a64.23560: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
18723a64.23560: *0000000000000000-000000000000ffff 0x0001/0x0000 0x0000000
18823a64.23560: *0000000000010000-000000000002ffff 0x0004/0x0004 0x0020000
18923a64.23560: *0000000000030000-0000000000033fff 0x0002/0x0002 0x0040000
19023a64.23560: 0000000000034000-000000000003ffff 0x0001/0x0000 0x0000000
19123a64.23560: *0000000000040000-0000000000040fff 0x0004/0x0004 0x0020000
19223a64.23560: 0000000000041000-00000000001effff 0x0001/0x0000 0x0000000
19323a64.23560: *00000000001f0000-00000000002ebfff 0x0000/0x0004 0x0020000
19423a64.23560: 00000000002ec000-00000000002edfff 0x0104/0x0004 0x0020000
19523a64.23560: 00000000002ee000-00000000002effff 0x0004/0x0004 0x0020000
19623a64.23560: 00000000002f0000-000000007741ffff 0x0001/0x0000 0x0000000
19723a64.23560: *0000000077420000-0000000077420fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
19823a64.23560: 0000000077421000-0000000077544fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
19923a64.23560: 0000000077545000-000000007754afff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
20023a64.23560: 000000007754b000-000000007754bfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
20123a64.23560: 000000007754c000-0000000077553fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
20223a64.23560: 0000000077554000-00000000775befff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
20323a64.23560: 00000000775bf000-000000007efdffff 0x0001/0x0000 0x0000000
20423a64.23560: *000000007efe0000-000000007ffdffff 0x0000/0x0002 0x0020000
20523a64.23560: *000000007ffe0000-000000007ffe0fff 0x0002/0x0002 0x0020000
20623a64.23560: 000000007ffe1000-000000007ffeffff 0x0000/0x0002 0x0020000
20723a64.23560: 000000007fff0000-000000013f2cffff 0x0001/0x0000 0x0000000
20823a64.23560: *000000013f2d0000-000000013f2d0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
20923a64.23560: 000000013f2d1000-000000013f346fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
21023a64.23560: 000000013f347000-000000013f347fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
21123a64.23560: 000000013f348000-000000013f38ffff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
21223a64.23560: 000000013f390000-000000013f390fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
21323a64.23560: 000000013f391000-000000013f391fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
21423a64.23560: 000000013f392000-000000013f396fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
21523a64.23560: 000000013f397000-000000013f397fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
21623a64.23560: 000000013f398000-000000013f398fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
21723a64.23560: 000000013f399000-000000013f39cfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
21823a64.23560: 000000013f39d000-000000013f3e5fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
21923a64.23560: 000000013f3e6000-000007feff71ffff 0x0001/0x0000 0x0000000
22023a64.23560: *000007feff720000-000007feff720fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\apisetschema.dll
22123a64.23560: 000007feff721000-000007fffffaffff 0x0001/0x0000 0x0000000
22223a64.23560: *000007fffffb0000-000007fffffd2fff 0x0002/0x0002 0x0040000
22323a64.23560: 000007fffffd3000-000007fffffdcfff 0x0001/0x0000 0x0000000
22423a64.23560: *000007fffffdd000-000007fffffddfff 0x0004/0x0004 0x0020000
22523a64.23560: *000007fffffde000-000007fffffdffff 0x0004/0x0004 0x0020000
22623a64.23560: *000007fffffe0000-000007fffffeffff 0x0001/0x0002 0x0020000
22723a64.23560: supR3HardNtChildPurify: Done after 268 ms and 0 fixes (loop #0).
2281f168.125e8: Log file opened: 6.1.4r136177 g_hStartupLog=0000000000000004 g_uNtVerCombined=0x611db100
2291f168.125e8: supR3HardenedVmProcessInit: uNtDllAddr=0000000077420000 g_uNtVerCombined=0x611db100 (stack ~00000000002ef6f8)
2301f168.125e8: ntdll.dll: timestamp 0x5e0eb67f (rc=VINF_SUCCESS)
2311f168.125e8: New simple heap: #1 00000000002f0000 LB 0x400000 (for 1699840 allocation)
23223a64.23560: supR3HardNtEnableThreadCreationEx:
2331f168.125e8: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox'
2341f168.125e8: System32: \Device\HarddiskVolume1\Windows\System32
2351f168.125e8: WinSxS: \Device\HarddiskVolume1\Windows\winsxs
2361f168.125e8: KnownDllPath: C:\Windows\system32
2371f168.125e8: supR3HardenedVmProcessInit: Opening vboxdrv stub...
2381f168.125e8: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
2391f168.125e8: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
2401f168.125e8: Registered Dll notification callback with NTDLL.
2411f168.125e8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\kernel32.dll)
2421f168.125e8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\kernel32.dll
2431f168.125e8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
2441f168.125e8: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
2451f168.125e8: supR3HardenedDllNotificationCallback: load 0000000077200000 LB 0x0011f000 C:\Windows\system32\kernel32.dll [fFlags=0x0]
2461f168.125e8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
2471f168.125e8: supR3HardenedDllNotificationCallback: load 000007fefd040000 LB 0x00067000 C:\Windows\system32\KERNELBASE.dll [fFlags=0x0]
2481f168.125e8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\KernelBase.dll)
2491f168.125e8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\KernelBase.dll
2501f168.125e8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077200000 'C:\Windows\system32\kernel32.dll'
2511f168.125e8: supR3HardNtDisableThreadCreation: pvLdrInitThunk=0000000077463730 pvNtTerminateThread=0000000077489cd0
25223a64.23560: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 53 ms.
2531f168.125e8: \SystemRoot\System32\ntdll.dll:
2541f168.125e8: CreationTime: 2020-01-14T21:20:24.992404300Z
2551f168.125e8: LastWriteTime: 2020-01-03T03:35:05.302579400Z
2561f168.125e8: ChangeTime: 2020-01-14T22:54:45.661976200Z
2571f168.125e8: FileAttributes: 0x20
2581f168.125e8: Size: 0x198080
2591f168.125e8: NT Headers: 0xe0
2601f168.125e8: Timestamp: 0x5e0eb67f
2611f168.125e8: Machine: 0x8664 - amd64
2621f168.125e8: Timestamp: 0x5e0eb67f
2631f168.125e8: Image Version: 6.1
2641f168.125e8: SizeOfImage: 0x19f000 (1699840)
2651f168.125e8: Resource Dir: 0x142000 LB 0x5a038
2661f168.125e8: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
2671f168.125e8: [Raw version resource data: 0x1420f0 LB 0x38c, codepage 0x0 (reserved 0x0)]
2681f168.125e8: ProductName: Microsoft® Windows® Operating System
2691f168.125e8: ProductVersion: 6.1.7601.24545
2701f168.125e8: FileVersion: 6.1.7601.24545 (win7sp1_ldr_escrow.200102-1707)
2711f168.125e8: FileDescription: NT Layer DLL
2721f168.125e8: \SystemRoot\System32\kernel32.dll:
2731f168.125e8: CreationTime: 2020-01-14T21:20:21.987377500Z
2741f168.125e8: LastWriteTime: 2020-01-03T03:33:39.604000000Z
2751f168.125e8: ChangeTime: 2020-01-14T22:54:46.285977300Z
2761f168.125e8: FileAttributes: 0x20
2771f168.125e8: Size: 0x11be00
2781f168.125e8: NT Headers: 0xe0
2791f168.125e8: Timestamp: 0x5e0eb6bc
2801f168.125e8: Machine: 0x8664 - amd64
2811f168.125e8: Timestamp: 0x5e0eb6bc
2821f168.125e8: Image Version: 6.1
2831f168.125e8: SizeOfImage: 0x11f000 (1175552)
2841f168.125e8: Resource Dir: 0x116000 LB 0x530
2851f168.125e8: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
2861f168.125e8: [Raw version resource data: 0x1160b0 LB 0x3b0, codepage 0x0 (reserved 0x0)]
2871f168.125e8: ProductName: Microsoft® Windows® Operating System
2881f168.125e8: ProductVersion: 6.1.7601.24545
2891f168.125e8: FileVersion: 6.1.7601.24545 (win7sp1_ldr_escrow.200102-1707)
2901f168.125e8: FileDescription: Windows NT BASE API Client DLL
2911f168.125e8: \SystemRoot\System32\KernelBase.dll:
2921f168.125e8: CreationTime: 2020-01-14T21:20:21.737377200Z
2931f168.125e8: LastWriteTime: 2020-01-03T03:33:39.604000000Z
2941f168.125e8: ChangeTime: 2020-01-14T22:54:46.285977300Z
2951f168.125e8: FileAttributes: 0x20
2961f168.125e8: Size: 0x63c00
2971f168.125e8: NT Headers: 0xe8
2981f168.125e8: Timestamp: 0x5e0eb6bd
2991f168.125e8: Machine: 0x8664 - amd64
3001f168.125e8: Timestamp: 0x5e0eb6bd
3011f168.125e8: Image Version: 6.1
3021f168.125e8: SizeOfImage: 0x67000 (421888)
3031f168.125e8: Resource Dir: 0x65000 LB 0x538
3041f168.125e8: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
3051f168.125e8: [Raw version resource data: 0x650b0 LB 0x3b8, codepage 0x0 (reserved 0x0)]
3061f168.125e8: ProductName: Microsoft® Windows® Operating System
3071f168.125e8: ProductVersion: 6.1.7601.24545
3081f168.125e8: FileVersion: 6.1.7601.24545 (win7sp1_ldr_escrow.200102-1707)
3091f168.125e8: FileDescription: Windows NT BASE API Client DLL
3101f168.125e8: \SystemRoot\System32\apisetschema.dll:
3111f168.125e8: CreationTime: 2020-01-14T21:20:21.327376600Z
3121f168.125e8: LastWriteTime: 2020-01-03T03:33:11.406000000Z
3131f168.125e8: ChangeTime: 2020-01-14T22:54:45.318775600Z
3141f168.125e8: FileAttributes: 0x20
3151f168.125e8: Size: 0x1c00
3161f168.125e8: NT Headers: 0xc0
3171f168.125e8: Timestamp: 0x5e0eb63f
3181f168.125e8: Machine: 0x8664 - amd64
3191f168.125e8: Timestamp: 0x5e0eb63f
3201f168.125e8: Image Version: 6.1
3211f168.125e8: SizeOfImage: 0x50000 (327680)
3221f168.125e8: Resource Dir: 0x30000 LB 0x408
3231f168.125e8: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
3241f168.125e8: [Raw version resource data: 0x30060 LB 0x3a4, codepage 0x0 (reserved 0x0)]
3251f168.125e8: ProductName: Microsoft® Windows® Operating System
3261f168.125e8: ProductVersion: 6.1.7601.24545
3271f168.125e8: FileVersion: 6.1.7601.24545 (win7sp1_ldr_escrow.200102-1707)
3281f168.125e8: FileDescription: ApiSet Schema DLL
3291f168.125e8: supR3HardenedWinFindAdversaries: 0x0
3301f168.125e8: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox'
3311f168.125e8: Calling main()
3321f168.125e8: SUPR3HardenedMain: pszProgName=VirtualBoxVM fFlags=0x2
3331f168.125e8: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox'
3341f168.125e8: '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
3351f168.125e8: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe)
3361f168.125e8: SUPR3HardenedMain: Respawn #2
3371f168.125e8: supR3HardNtEnableThreadCreationEx:
3381f168.125e8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\apphelp.dll)
3391f168.125e8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\apphelp.dll
3401f168.125e8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\apphelp.dll (rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
3411f168.125e8: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\apphelp.dll [lacks WinVerifyTrust]
3421f168.125e8: supR3HardenedDllNotificationCallback: load 000007fefcd70000 LB 0x00057000 C:\Windows\system32\apphelp.dll [fFlags=0x0]
3431f168.125e8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\apphelp.dll [lacks WinVerifyTrust]
3441f168.125e8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcd70000 'C:\Windows\system32\apphelp.dll'
3451f168.125e8: supR3HardNtDisableThreadCreation: pvLdrInitThunk=0000000077463730 pvNtTerminateThread=0000000077489cd0
3461f168.125e8: supR3HardenedWinDoReSpawn(2): New child 23338.1f228 [kernel32].
3471f168.125e8: supR3HardNtChildGatherData: PebBaseAddress=000007fffffd3000 cbPeb=0x380
3481f168.125e8: supR3HardNtPuChFindNtdll: uNtDllParentAddr=0000000077420000 uNtDllChildAddr=0000000077420000
3491f168.125e8: supR3HardenedWinSetupChildInit: uLdrInitThunk=0000000077463730
3501f168.125e8: supR3HardenedWinSetupChildInit: Initial context:
351 rax=0000000000000000 rbx=0000000000000000 rcx=000000013f2d7900 rdx=000007fffffd3000
352 rsi=0000000000000000 rdi=0000000000000000 r8 =0000000000000000 r9 =0000000000000000
353 r10=0000000000000000 r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
354 r14=0000000000000000 r15=0000000000000000 P1=0000000000000000 P2=0000000000000000
355 rip=0000000077473710 rsp=00000000001ef948 rbp=0000000000000000 ctxflags=0010001b
356 cs=0033 ss=002b ds=0000 es=0000 fs=0000 gs=0000 eflags=00000200 mxcrx=00001f80
357 P3=0000000000000000 P4=0000000000000000 P5=0000000000000000 P6=0000000000000000
358 dr0=0000000000000000 dr1=0000000000000000 dr2=0000000000000000 dr3=0000000000000000
359 dr6=0000000000000000 dr7=0000000000000000 vcr=0000000000000000 dcr=0000000000000000
360 lbt=0000000000000000 lbf=0000000000000000 lxt=0000000000000000 lxf=0000000000000000
3611f168.125e8: kernel32.dll: timestamp 0x5e0eb6bc (rc=VINF_SUCCESS)
3621f168.125e8: supR3HardenedWinSetupChildInit: Start child.
3631f168.125e8: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 1 ms.
3641f168.125e8: supR3HardNtChildPurify: Startup delay kludge #1/0: 264 ms, 33 sleeps
3651f168.125e8: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
3661f168.125e8: *0000000000000000-000000000000ffff 0x0001/0x0000 0x0000000
3671f168.125e8: *0000000000010000-000000000002ffff 0x0004/0x0004 0x0020000
3681f168.125e8: *0000000000030000-0000000000033fff 0x0002/0x0002 0x0040000
3691f168.125e8: 0000000000034000-000000000003ffff 0x0001/0x0000 0x0000000
3701f168.125e8: *0000000000040000-0000000000040fff 0x0004/0x0004 0x0020000
3711f168.125e8: 0000000000041000-00000000000effff 0x0001/0x0000 0x0000000
3721f168.125e8: *00000000000f0000-00000000001ebfff 0x0000/0x0004 0x0020000
3731f168.125e8: 00000000001ec000-00000000001edfff 0x0104/0x0004 0x0020000
3741f168.125e8: 00000000001ee000-00000000001effff 0x0004/0x0004 0x0020000
3751f168.125e8: 00000000001f0000-000000007741ffff 0x0001/0x0000 0x0000000
3761f168.125e8: *0000000077420000-0000000077420fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
3771f168.125e8: 0000000077421000-0000000077544fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
3781f168.125e8: 0000000077545000-000000007754afff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
3791f168.125e8: 000000007754b000-000000007754bfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
3801f168.125e8: 000000007754c000-0000000077553fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
3811f168.125e8: 0000000077554000-00000000775befff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
3821f168.125e8: 00000000775bf000-000000007efdffff 0x0001/0x0000 0x0000000
3831f168.125e8: *000000007efe0000-000000007ffdffff 0x0000/0x0002 0x0020000
3841f168.125e8: *000000007ffe0000-000000007ffe0fff 0x0002/0x0002 0x0020000
3851f168.125e8: 000000007ffe1000-000000007ffeffff 0x0000/0x0002 0x0020000
3861f168.125e8: 000000007fff0000-000000013f2cffff 0x0001/0x0000 0x0000000
3871f168.125e8: *000000013f2d0000-000000013f2d0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
3881f168.125e8: 000000013f2d1000-000000013f346fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
3891f168.125e8: 000000013f347000-000000013f347fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
3901f168.125e8: 000000013f348000-000000013f38ffff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
3911f168.125e8: 000000013f390000-000000013f390fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
3921f168.125e8: 000000013f391000-000000013f391fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
3931f168.125e8: 000000013f392000-000000013f396fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
3941f168.125e8: 000000013f397000-000000013f397fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
3951f168.125e8: 000000013f398000-000000013f398fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
3961f168.125e8: 000000013f399000-000000013f39cfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
3971f168.125e8: 000000013f39d000-000000013f3e5fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
3981f168.125e8: 000000013f3e6000-000007feff71ffff 0x0001/0x0000 0x0000000
3991f168.125e8: *000007feff720000-000007feff720fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\apisetschema.dll
4001f168.125e8: 000007feff721000-000007fffffaffff 0x0001/0x0000 0x0000000
4011f168.125e8: *000007fffffb0000-000007fffffd2fff 0x0002/0x0002 0x0040000
4021f168.125e8: *000007fffffd3000-000007fffffd3fff 0x0004/0x0004 0x0020000
4031f168.125e8: 000007fffffd4000-000007fffffddfff 0x0001/0x0000 0x0000000
4041f168.125e8: *000007fffffde000-000007fffffdffff 0x0004/0x0004 0x0020000
4051f168.125e8: *000007fffffe0000-000007fffffeffff 0x0001/0x0002 0x0020000
4061f168.125e8: apisetschema.dll: timestamp 0x5e0eb63f (rc=VINF_SUCCESS)
4071f168.125e8: VirtualBoxVM.exe: timestamp 0x5e4c1d19 (rc=VINF_SUCCESS)
4081f168.125e8: '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
4091f168.125e8: '\Device\HarddiskVolume1\Windows\System32\apisetschema.dll' has no imports
4101f168.125e8: '\Device\HarddiskVolume1\Windows\System32\ntdll.dll' has no imports
4111f168.125e8: supR3HardNtChildPurify: Done after 301 ms and 0 fixes (loop #0).
41223338.1f228: Log file opened: 6.1.4r136177 g_hStartupLog=0000000000000004 g_uNtVerCombined=0x611db100
41323338.1f228: supR3HardenedVmProcessInit: uNtDllAddr=0000000077420000 g_uNtVerCombined=0x611db100 (stack ~00000000001ef3f8)
4141f168.125e8: supR3HardenedEarlyCompact: Removed heap 1 (0x000000002f0000 LB 0x400000)
41523338.1f228: ntdll.dll: timestamp 0x5e0eb67f (rc=VINF_SUCCESS)
41623338.1f228: New simple heap: #1 00000000002f0000 LB 0x400000 (for 1699840 allocation)
4171f168.125e8: supR3HardNtEnableThreadCreationEx:
41823338.1f228: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox'
41923338.1f228: System32: \Device\HarddiskVolume1\Windows\System32
42023338.1f228: WinSxS: \Device\HarddiskVolume1\Windows\winsxs
42123338.1f228: KnownDllPath: C:\Windows\system32
42223338.1f228: supR3HardenedVmProcessInit: Opening vboxdrv...
42323338.1f228: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
42423338.1f228: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
42523338.1f228: Registered Dll notification callback with NTDLL.
42623338.1f228: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\kernel32.dll)
42723338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\kernel32.dll
42823338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
42923338.1f228: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
43023338.1f228: supR3HardenedDllNotificationCallback: load 0000000077200000 LB 0x0011f000 C:\Windows\system32\kernel32.dll [fFlags=0x0]
43123338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
43223338.1f228: supR3HardenedDllNotificationCallback: load 000007fefd040000 LB 0x00067000 C:\Windows\system32\KERNELBASE.dll [fFlags=0x0]
43323338.1f228: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\KernelBase.dll)
43423338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\KernelBase.dll
43523338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077200000 'C:\Windows\system32\kernel32.dll'
43623338.1f228: supR3HardNtDisableThreadCreation: pvLdrInitThunk=0000000077463730 pvNtTerminateThread=0000000077489cd0
4371f168.125e8: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 73 ms.
43823338.1f228: \SystemRoot\System32\ntdll.dll:
43923338.1f228: CreationTime: 2020-01-14T21:20:24.992404300Z
44023338.1f228: LastWriteTime: 2020-01-03T03:35:05.302579400Z
44123338.1f228: ChangeTime: 2020-01-14T22:54:45.661976200Z
44223338.1f228: FileAttributes: 0x20
44323338.1f228: Size: 0x198080
44423338.1f228: NT Headers: 0xe0
44523338.1f228: Timestamp: 0x5e0eb67f
44623338.1f228: Machine: 0x8664 - amd64
44723338.1f228: Timestamp: 0x5e0eb67f
44823338.1f228: Image Version: 6.1
44923338.1f228: SizeOfImage: 0x19f000 (1699840)
45023338.1f228: Resource Dir: 0x142000 LB 0x5a038
45123338.1f228: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
45223338.1f228: [Raw version resource data: 0x1420f0 LB 0x38c, codepage 0x0 (reserved 0x0)]
45323338.1f228: ProductName: Microsoft® Windows® Operating System
45423338.1f228: ProductVersion: 6.1.7601.24545
45523338.1f228: FileVersion: 6.1.7601.24545 (win7sp1_ldr_escrow.200102-1707)
45623338.1f228: FileDescription: NT Layer DLL
45723338.1f228: \SystemRoot\System32\kernel32.dll:
45823338.1f228: CreationTime: 2020-01-14T21:20:21.987377500Z
45923338.1f228: LastWriteTime: 2020-01-03T03:33:39.604000000Z
46023338.1f228: ChangeTime: 2020-01-14T22:54:46.285977300Z
46123338.1f228: FileAttributes: 0x20
46223338.1f228: Size: 0x11be00
46323338.1f228: NT Headers: 0xe0
46423338.1f228: Timestamp: 0x5e0eb6bc
46523338.1f228: Machine: 0x8664 - amd64
46623338.1f228: Timestamp: 0x5e0eb6bc
46723338.1f228: Image Version: 6.1
46823338.1f228: SizeOfImage: 0x11f000 (1175552)
46923338.1f228: Resource Dir: 0x116000 LB 0x530
47023338.1f228: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
47123338.1f228: [Raw version resource data: 0x1160b0 LB 0x3b0, codepage 0x0 (reserved 0x0)]
47223338.1f228: ProductName: Microsoft® Windows® Operating System
47323338.1f228: ProductVersion: 6.1.7601.24545
47423338.1f228: FileVersion: 6.1.7601.24545 (win7sp1_ldr_escrow.200102-1707)
47523338.1f228: FileDescription: Windows NT BASE API Client DLL
47623338.1f228: \SystemRoot\System32\KernelBase.dll:
47723338.1f228: CreationTime: 2020-01-14T21:20:21.737377200Z
47823338.1f228: LastWriteTime: 2020-01-03T03:33:39.604000000Z
47923338.1f228: ChangeTime: 2020-01-14T22:54:46.285977300Z
48023338.1f228: FileAttributes: 0x20
48123338.1f228: Size: 0x63c00
48223338.1f228: NT Headers: 0xe8
48323338.1f228: Timestamp: 0x5e0eb6bd
48423338.1f228: Machine: 0x8664 - amd64
48523338.1f228: Timestamp: 0x5e0eb6bd
48623338.1f228: Image Version: 6.1
48723338.1f228: SizeOfImage: 0x67000 (421888)
48823338.1f228: Resource Dir: 0x65000 LB 0x538
48923338.1f228: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
49023338.1f228: [Raw version resource data: 0x650b0 LB 0x3b8, codepage 0x0 (reserved 0x0)]
49123338.1f228: ProductName: Microsoft® Windows® Operating System
49223338.1f228: ProductVersion: 6.1.7601.24545
49323338.1f228: FileVersion: 6.1.7601.24545 (win7sp1_ldr_escrow.200102-1707)
49423338.1f228: FileDescription: Windows NT BASE API Client DLL
49523338.1f228: \SystemRoot\System32\apisetschema.dll:
49623338.1f228: CreationTime: 2020-01-14T21:20:21.327376600Z
49723338.1f228: LastWriteTime: 2020-01-03T03:33:11.406000000Z
49823338.1f228: ChangeTime: 2020-01-14T22:54:45.318775600Z
49923338.1f228: FileAttributes: 0x20
50023338.1f228: Size: 0x1c00
50123338.1f228: NT Headers: 0xc0
50223338.1f228: Timestamp: 0x5e0eb63f
50323338.1f228: Machine: 0x8664 - amd64
50423338.1f228: Timestamp: 0x5e0eb63f
50523338.1f228: Image Version: 6.1
50623338.1f228: SizeOfImage: 0x50000 (327680)
50723338.1f228: Resource Dir: 0x30000 LB 0x408
50823338.1f228: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
50923338.1f228: [Raw version resource data: 0x30060 LB 0x3a4, codepage 0x0 (reserved 0x0)]
51023338.1f228: ProductName: Microsoft® Windows® Operating System
51123338.1f228: ProductVersion: 6.1.7601.24545
51223338.1f228: FileVersion: 6.1.7601.24545 (win7sp1_ldr_escrow.200102-1707)
51323338.1f228: FileDescription: ApiSet Schema DLL
51423338.1f228: supR3HardenedWinFindAdversaries: 0x0
51523338.1f228: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox'
51623338.1f228: Calling main()
51723338.1f228: SUPR3HardenedMain: pszProgName=VirtualBoxVM fFlags=0x2
51823338.1f228: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox'
51923338.1f228: '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
52023338.1f228: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe)
52123338.1f228: SUPR3HardenedMain: Final process, opening VBoxDrv...
52223338.1f228: supR3HardenedEarlyCompact: Removed heap 1 (0x000000002f0000 LB 0x400000)
52323338.1f228: supR3HardNtEnableThreadCreationEx:
52423338.1f228: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxSupLib.dll)
52523338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxSupLib.dll
52623338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001eb281:<flags> [calling]
52723338.1f228: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
52823338.1f228: supR3HardenedDllNotificationCallback: load 000007fef61c0000 LB 0x00005000 C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL [fFlags=0x0]
52923338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
53023338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
53123338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001e8a01:<flags> [calling]
53223338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef61c0000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
53323338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
53423338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001e8a01:<flags> [calling]
53523338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef61c0000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
53623338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef61c0000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
53723338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
53823338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'crypt32.dll'.
53923338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msasn1.dll'.
54023338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
54123338.1f228: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\wintrust.dll)
54223338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\wintrust.dll
54323338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
54423338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
54523338.1f228: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll)
54623338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\rpcrt4.dll
54723338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
54823338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume1\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
54923338.1f228: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\msasn1.dll)
55023338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\msasn1.dll
55123338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
55223338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume1\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
55323338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
55423338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msasn1.dll'.
55523338.1f228: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\crypt32.dll)
55623338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\crypt32.dll
55723338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
55823338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
55923338.1f228: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\msvcrt.dll)
56023338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\msvcrt.dll
56123338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
56223338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume1\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
56323338.1f228: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
56423338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
56523338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
56623338.1f228: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
56723338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ed091:<flags> [calling]
56823338.1f228: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
56923338.1f228: supR3HardenedDllNotificationCallback: load 000007fefd240000 LB 0x0003b000 C:\Windows\system32\Wintrust.dll [fFlags=0x0]
57023338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
57123338.1f228: supR3HardenedDllNotificationCallback: load 000007feff080000 LB 0x0009f000 C:\Windows\system32\msvcrt.dll [fFlags=0x0]
57223338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
57323338.1f228: supR3HardenedDllNotificationCallback: load 000007fefd0b0000 LB 0x0016d000 C:\Windows\system32\CRYPT32.dll [fFlags=0x0]
57423338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
57523338.1f228: supR3HardenedDllNotificationCallback: load 000007fefcf80000 LB 0x0000f000 C:\Windows\system32\MSASN1.dll [fFlags=0x0]
57623338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
57723338.1f228: supR3HardenedDllNotificationCallback: load 000007fefe180000 LB 0x0012c000 C:\Windows\system32\RPCRT4.dll [fFlags=0x0]
57823338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
57923338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd240000 'C:\Windows\system32\Wintrust.dll'
58023338.1f228: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\bcrypt.dll)
58123338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\bcrypt.dll
58223338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcrypt.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ed091:<flags> [calling]
58323338.1f228: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
58423338.1f228: supR3HardenedDllNotificationCallback: load 000007fefc5d0000 LB 0x00022000 C:\Windows\system32\bcrypt.dll [fFlags=0x0]
58523338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
58623338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc5d0000 'C:\Windows\system32\bcrypt.dll'
58723338.1f228: bcrypt.dll loaded at 000007fefc5d0000, BCryptOpenAlgorithmProvider at 000007fefc5d2460, preloading providers:
58823338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
58923338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'bcrypt.dll'.
59023338.1f228: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\bcryptprimitives.dll)
59123338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\bcryptprimitives.dll
59223338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
59323338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume1\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
59423338.1f228: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
59523338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
59623338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
59723338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
59823338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'rpcrt4.dll'.
59923338.1f228: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\advapi32.dll)
60023338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\advapi32.dll
60123338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
60223338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
60323338.1f228: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
60423338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
60523338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
60623338.1f228: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
60723338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcryptprimitives.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ed071:<flags> [calling]
60823338.1f228: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
60923338.1f228: supR3HardenedDllNotificationCallback: load 000007fefc520000 LB 0x0004c000 C:\Windows\system32\bcryptprimitives.dll [fFlags=0x0]
61023338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
61123338.1f228: supR3HardenedDllNotificationCallback: load 000007fefe660000 LB 0x000db000 C:\Windows\system32\ADVAPI32.dll [fFlags=0x0]
61223338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
61323338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msvcrt.dll'.
61423338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'rpcrt4.dll'.
61523338.1f228: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\sechost.dll)
61623338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\sechost.dll
61723338.1f228: supR3HardenedDllNotificationCallback: load 000007fefd350000 LB 0x0001f000 C:\Windows\SYSTEM32\sechost.dll [fFlags=0x0]
61823338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\sechost.dll [lacks WinVerifyTrust]
61923338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc520000 'C:\Windows\system32\bcryptprimitives.dll'
62023338.1f228: BCryptOpenAlgorithmProvider(,'MD2',0,0) -> 0x0 (hAlgo=00000000008de580)
62123338.1f228: BCryptOpenAlgorithmProvider(,'MD4',0,0) -> 0x0 (hAlgo=00000000008df440)
62223338.1f228: BCryptOpenAlgorithmProvider(,'MD5',0,0) -> 0x0 (hAlgo=00000000008df570)
62323338.1f228: BCryptOpenAlgorithmProvider(,'SHA1',0,0) -> 0x0 (hAlgo=00000000008df790)
62423338.1f228: BCryptOpenAlgorithmProvider(,'SHA256',0,0) -> 0x0 (hAlgo=00000000008df8c0)
62523338.1f228: BCryptOpenAlgorithmProvider(,'SHA512',0,0) -> 0x0 (hAlgo=00000000008df9f0)
62623338.1f228: BCryptOpenAlgorithmProvider(,'RSA',0,0) -> 0x0 (hAlgo=00000000008dfc40)
62723338.1f228: BCryptOpenAlgorithmProvider(,'DSA',0,0) -> 0x0 (hAlgo=00000000008dfd70)
62823338.1f228: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\cryptsp.dll)
62923338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\cryptsp.dll
63023338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
63123338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
63223338.1f228: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
63323338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
63423338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
63523338.1f228: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
63623338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTSP.dll (Input=CRYPTSP.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ecbe1:<flags> [calling]
63723338.1f228: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
63823338.1f228: supR3HardenedDllNotificationCallback: load 000007fefc410000 LB 0x00018000 C:\Windows\system32\CRYPTSP.dll [fFlags=0x0]
63923338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
64023338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc410000 'C:\Windows\system32\CRYPTSP.dll'
64123338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
64223338.1f228: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\rsaenh.dll)
64323338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\rsaenh.dll
64423338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
64523338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
64623338.1f228: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
64723338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ecb71:<flags> [calling]
64823338.1f228: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
64923338.1f228: supR3HardenedDllNotificationCallback: load 000007fefc110000 LB 0x00047000 C:\Windows\system32\rsaenh.dll [fFlags=0x0]
65023338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
65123338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc110000 'C:\Windows\system32\rsaenh.dll'
65223338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
65323338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ADVAPI32.dll (Input=ADVAPI32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ec401:<flags> [calling]
65423338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe660000 'C:\Windows\system32\ADVAPI32.dll'
65523338.1f228: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\cryptbase.dll)
65623338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\cryptbase.dll
65723338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTBASE.dll (Input=CRYPTBASE.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ec781:<flags> [calling]
65823338.1f228: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptbase.dll [lacks WinVerifyTrust]
65923338.1f228: supR3HardenedDllNotificationCallback: load 000007fefcdd0000 LB 0x0000f000 C:\Windows\system32\CRYPTBASE.dll [fFlags=0x0]
66023338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptbase.dll [lacks WinVerifyTrust]
66123338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcdd0000 'C:\Windows\system32\CRYPTBASE.dll'
66223338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
66323338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ec1b1:<flags> [calling]
66423338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077200000 'C:\Windows\system32\kernel32.dll'
66523338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
66623338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\WINTRUST.DLL (Input=WINTRUST.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ecb41:<flags> [calling]
66723338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd240000 'C:\Windows\system32\WINTRUST.DLL'
66823338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
66923338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPT32.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=00000000001ec971:<flags> [calling]
67023338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd0b0000 'C:\Windows\system32\CRYPT32.dll'
67123338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
67223338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'advapi32.dll'.
67323338.1f228: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\imagehlp.dll)
67423338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\imagehlp.dll
67523338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
67623338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
67723338.1f228: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
67823338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
67923338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
68023338.1f228: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
68123338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\imagehlp.dll (Input=imagehlp.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ec9c1:<flags> [calling]
68223338.1f228: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\imagehlp.dll [lacks WinVerifyTrust]
68323338.1f228: supR3HardenedDllNotificationCallback: load 000007fefd330000 LB 0x00019000 C:\Windows\system32\imagehlp.dll [fFlags=0x0]
68423338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\imagehlp.dll [lacks WinVerifyTrust]
68523338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd330000 'C:\Windows\system32\imagehlp.dll'
68623338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
68723338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTSP.dll (Input=CRYPTSP.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ecb11:<flags> [calling]
68823338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc410000 'C:\Windows\system32\CRYPTSP.dll'
68923338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
69023338.1f228: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\user32.dll)
69123338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\user32.dll
69223338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
69323338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
69423338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
69523338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'lpk.dll'.
69623338.1f228: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\gdi32.dll)
69723338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\gdi32.dll
69823338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'lpk.dll'...
69923338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'lpk.dll' -> '\Device\HarddiskVolume1\Windows\System32\lpk.dll' [rcNtRedir=0xc0150008]
70023338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'gdi32.dll'.
70123338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'user32.dll'.
70223338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'usp10.dll'.
70323338.1f228: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\lpk.dll)
70423338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\lpk.dll
70523338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
70623338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
70723338.1f228: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\user32.dll [lacks WinVerifyTrust]
70823338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'usp10.dll'...
70923338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'usp10.dll' -> '\Device\HarddiskVolume1\Windows\System32\usp10.dll' [rcNtRedir=0xc0150008]
71023338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
71123338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
71223338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'gdi32.dll'.
71323338.1f228: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\usp10.dll)
71423338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\usp10.dll
71523338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
71623338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
71723338.1f228: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\user32.dll [lacks WinVerifyTrust]
71823338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
71923338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
72023338.1f228: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
72123338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
72223338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
72323338.1f228: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
72423338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
72523338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
72623338.1f228: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\user32.dll [lacks WinVerifyTrust]
72723338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
72823338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
72923338.1f228: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
73023338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\USER32.dll (Input=USER32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ec641:<flags> [calling]
73123338.1f228: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\user32.dll [lacks WinVerifyTrust]
73223338.1f228: supR3HardenedDllNotificationCallback: load 0000000077320000 LB 0x000fb000 C:\Windows\system32\USER32.dll [fFlags=0x0]
73323338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\user32.dll [lacks WinVerifyTrust]
73423338.1f228: supR3HardenedDllNotificationCallback: load 000007fefed50000 LB 0x00067000 C:\Windows\system32\GDI32.dll [fFlags=0x0]
73523338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
73623338.1f228: supR3HardenedDllNotificationCallback: load 000007fefefa0000 LB 0x0000e000 C:\Windows\system32\LPK.dll [fFlags=0x0]
73723338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\lpk.dll [lacks WinVerifyTrust]
73823338.1f228: supR3HardenedDllNotificationCallback: load 000007feff190000 LB 0x000cb000 C:\Windows\system32\USP10.dll [fFlags=0x0]
73923338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\usp10.dll [lacks WinVerifyTrust]
74023338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
74123338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\gdi32.dll (Input=gdi32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ebb41:<flags> [calling]
74223338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefed50000 'C:\Windows\system32\gdi32.dll'
74323338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'user32.dll'.
74423338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
74523338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msctf.dll'.
74623338.1f228: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\imm32.dll)
74723338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\imm32.dll
74823338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msctf.dll'...
74923338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'msctf.dll' -> '\Device\HarddiskVolume1\Windows\System32\msctf.dll' [rcNtRedir=0xc0150008]
75023338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
75123338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
75223338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'gdi32.dll'.
75323338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'imm32.dll'.
75423338.1f228: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\msctf.dll)
75523338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\msctf.dll
75623338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
75723338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
75823338.1f228: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
75923338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
76023338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
76123338.1f228: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\user32.dll [lacks WinVerifyTrust]
76223338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
76323338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume1\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
76423338.1f228: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\imm32.dll [lacks WinVerifyTrust]
76523338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
76623338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
76723338.1f228: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
76823338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
76923338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
77023338.1f228: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\user32.dll [lacks WinVerifyTrust]
77123338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
77223338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
77323338.1f228: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
77423338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\IMM32.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001eb481:<flags> [calling]
77523338.1f228: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\imm32.dll [lacks WinVerifyTrust]
77623338.1f228: supR3HardenedDllNotificationCallback: load 000007fefefb0000 LB 0x0002e000 C:\Windows\system32\IMM32.DLL [fFlags=0x0]
77723338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\imm32.dll [lacks WinVerifyTrust]
77823338.1f228: supR3HardenedDllNotificationCallback: load 000007fefe550000 LB 0x0010b000 C:\Windows\system32\MSCTF.dll [fFlags=0x0]
77923338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msctf.dll [lacks WinVerifyTrust]
78023338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefefb0000 'C:\Windows\system32\IMM32.DLL'
78123338.1f228: \Device\HarddiskVolume1\Windows\System32\nvinitx.dll: Owner is administrators group.
78223338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'user32.dll'.
78323338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
78423338.1f228: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume1\Windows\System32\nvinitx.dll)
78523338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\nvinitx.dll
78623338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
78723338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
78823338.1f228: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
78923338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
79023338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
79123338.1f228: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\user32.dll [lacks WinVerifyTrust]
79223338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\nvinitx.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001eb091:<flags> [calling]
79323338.1f228: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume1\Windows\System32\nvinitx.dll [lacks WinVerifyTrust]
79423338.1f228: supR3HardenedDllNotificationCallback: load 000007fefcea0000 LB 0x00040000 C:\Windows\system32\nvinitx.dll [fFlags=0x0]
79523338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume1\Windows\System32\nvinitx.dll [lacks WinVerifyTrust]
79623338.1f228: \Device\HarddiskVolume1\Program Files\NVIDIA Corporation\coprocmanager\detoured.dll: Owner is administrators group.
79723338.1f228: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Program Files\NVIDIA Corporation\coprocmanager\detoured.dll)
79823338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\NVIDIA Corporation\coprocmanager\detoured.dll
79923338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\NVIDIA Corporation\CoProcManager\detoured.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ea591:<flags> [calling]
80023338.1f228: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Program Files\NVIDIA Corporation\coprocmanager\detoured.dll [lacks WinVerifyTrust]
80123338.1f228: supR3HardenedDllNotificationCallback: load 000000000f000000 LB 0x00006000 C:\Program Files\NVIDIA Corporation\CoProcManager\detoured.dll [fFlags=0x0]
80223338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Program Files\NVIDIA Corporation\coprocmanager\detoured.dll [lacks WinVerifyTrust]
80323338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000000000f000000 'C:\Program Files\NVIDIA Corporation\CoProcManager\detoured.dll'
80423338.1f228: \Device\HarddiskVolume1\Program Files\NVIDIA Corporation\coprocmanager\Nvd3d9wrapx.dll: Owner is administrators group.
80523338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'user32.dll'.
80623338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'detoured.dll'.
80723338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'gdi32.dll'.
80823338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'setupapi.dll'.
80923338.1f228: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume1\Program Files\NVIDIA Corporation\coprocmanager\Nvd3d9wrapx.dll)
81023338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\NVIDIA Corporation\coprocmanager\Nvd3d9wrapx.dll
81123338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
81223338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume1\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
81323338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'cfgmgr32.dll'.
81423338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcrt.dll'.
81523338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'gdi32.dll'.
81623338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
81723338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'user32.dll'.
81823338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'oleaut32.dll'.
81923338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'devobj.dll'.
82023338.1f228: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\setupapi.dll)
82123338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\setupapi.dll
82223338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
82323338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
82423338.1f228: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
82523338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'detoured.dll'...
82623338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'detoured.dll' -> '\Device\HarddiskVolume1\Program Files\NVIDIA Corporation\coprocmanager\detoured.dll' [rcNtRedir=0xc0150008]
82723338.1f228: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Program Files\NVIDIA Corporation\coprocmanager\detoured.dll [lacks WinVerifyTrust]
82823338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
82923338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
83023338.1f228: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\user32.dll [lacks WinVerifyTrust]
83123338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'devobj.dll'...
83223338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'devobj.dll' -> '\Device\HarddiskVolume1\Windows\System32\devobj.dll' [rcNtRedir=0xc0150008]
83323338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
83423338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'cfgmgr32.dll'.
83523338.1f228: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\devobj.dll)
83623338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\devobj.dll
83723338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
83823338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume1\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
83923338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ole32.dll'.
84023338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
84123338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
84223338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'user32.dll'.
84323338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'gdi32.dll'.
84423338.1f228: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\oleaut32.dll)
84523338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\oleaut32.dll
84623338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
84723338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
84823338.1f228: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\user32.dll [lacks WinVerifyTrust]
84923338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
85023338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
85123338.1f228: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
85223338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
85323338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
85423338.1f228: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
85523338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
85623338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
85723338.1f228: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
85823338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
85923338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume1\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
86023338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
86123338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'rpcrt4.dll'.
86223338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
86323338.1f228: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\cfgmgr32.dll)
86423338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\cfgmgr32.dll
86523338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
86623338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
86723338.1f228: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
86823338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
86923338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
87023338.1f228: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
87123338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
87223338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
87323338.1f228: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
87423338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
87523338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
87623338.1f228: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
87723338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
87823338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
87923338.1f228: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\user32.dll [lacks WinVerifyTrust]
88023338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
88123338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
88223338.1f228: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
88323338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
88423338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
88523338.1f228: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
88623338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
88723338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
88823338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
88923338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
89023338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'user32.dll'.
89123338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'rpcrt4.dll'.
89223338.1f228: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\ole32.dll)
89323338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\ole32.dll
89423338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
89523338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume1\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
89623338.1f228: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cfgmgr32.dll [lacks WinVerifyTrust]
89723338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
89823338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
89923338.1f228: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
90023338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
90123338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
90223338.1f228: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
90323338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
90423338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
90523338.1f228: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\user32.dll [lacks WinVerifyTrust]
90623338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
90723338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
90823338.1f228: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
90923338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
91023338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
91123338.1f228: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
91223338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\NVIDIA Corporation\CoProcManager\nvd3d9wrapx.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ea591:<flags> [calling]
91323338.1f228: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume1\Program Files\NVIDIA Corporation\coprocmanager\Nvd3d9wrapx.dll [lacks WinVerifyTrust]
91423338.1f228: supR3HardenedDllNotificationCallback: load 000007fefa470000 LB 0x00056000 C:\Program Files\NVIDIA Corporation\CoProcManager\nvd3d9wrapx.dll [fFlags=0x0]
91523338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume1\Program Files\NVIDIA Corporation\coprocmanager\Nvd3d9wrapx.dll [lacks WinVerifyTrust]
91623338.1f228: supR3HardenedDllNotificationCallback: load 000007fefe8a0000 LB 0x001d7000 C:\Windows\system32\SETUPAPI.dll [fFlags=0x0]
91723338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\setupapi.dll [lacks WinVerifyTrust]
91823338.1f228: supR3HardenedDllNotificationCallback: load 000007fefcff0000 LB 0x00036000 C:\Windows\system32\CFGMGR32.dll [fFlags=0x0]
91923338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cfgmgr32.dll [lacks WinVerifyTrust]
92023338.1f228: supR3HardenedDllNotificationCallback: load 000007fefe7c0000 LB 0x000db000 C:\Windows\system32\OLEAUT32.dll [fFlags=0x0]
92123338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\oleaut32.dll [lacks WinVerifyTrust]
92223338.1f228: supR3HardenedDllNotificationCallback: load 000007fefe2b0000 LB 0x001ff000 C:\Windows\system32\ole32.dll [fFlags=0x0]
92323338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\ole32.dll [lacks WinVerifyTrust]
92423338.1f228: supR3HardenedDllNotificationCallback: load 000007fefcfc0000 LB 0x0001a000 C:\Windows\system32\DEVOBJ.dll [fFlags=0x0]
92523338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\devobj.dll [lacks WinVerifyTrust]
92623338.1f228: supR3HardenedIsApiSetDll: '<NULL>' -> true
92723338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Core-LocalRegistry-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000001e96d1:<flags> [calling]
92823338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077200000 'API-MS-Win-Core-LocalRegistry-L1-1-0.dll'
92923338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa470000 'C:\Program Files\NVIDIA Corporation\CoProcManager\nvd3d9wrapx.dll'
93023338.1f228: \Device\HarddiskVolume1\Program Files\NVIDIA Corporation\coprocmanager\nvdxgiwrapx.dll: Owner is administrators group.
93123338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'detoured.dll'.
93223338.1f228: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume1\Program Files\NVIDIA Corporation\coprocmanager\nvdxgiwrapx.dll)
93323338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\NVIDIA Corporation\coprocmanager\nvdxgiwrapx.dll
93423338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'detoured.dll'...
93523338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'detoured.dll' -> '\Device\HarddiskVolume1\Program Files\NVIDIA Corporation\coprocmanager\detoured.dll' [rcNtRedir=0xc0150008]
93623338.1f228: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Program Files\NVIDIA Corporation\coprocmanager\detoured.dll [lacks WinVerifyTrust]
93723338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\NVIDIA Corporation\CoProcManager\nvdxgiwrapx.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ea561:<flags> [calling]
93823338.1f228: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume1\Program Files\NVIDIA Corporation\coprocmanager\nvdxgiwrapx.dll [lacks WinVerifyTrust]
93923338.1f228: supR3HardenedDllNotificationCallback: load 000007fefa430000 LB 0x0003d000 C:\Program Files\NVIDIA Corporation\CoProcManager\nvdxgiwrapx.dll [fFlags=0x0]
94023338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume1\Program Files\NVIDIA Corporation\coprocmanager\nvdxgiwrapx.dll [lacks WinVerifyTrust]
94123338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa430000 'C:\Program Files\NVIDIA Corporation\CoProcManager\nvdxgiwrapx.dll'
94223338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcea0000 'C:\Windows\system32\nvinitx.dll'
94323338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077320000 'C:\Windows\system32\USER32.dll'
94423338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'bcrypt.dll'.
94523338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
94623338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msasn1.dll'.
94723338.1f228: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\ncrypt.dll)
94823338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\ncrypt.dll
94923338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
95023338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume1\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
95123338.1f228: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
95223338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
95323338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
95423338.1f228: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
95523338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
95623338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume1\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
95723338.1f228: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
95823338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ncrypt.dll (Input=ncrypt.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ec911:<flags> [calling]
95923338.1f228: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\ncrypt.dll [lacks WinVerifyTrust]
96023338.1f228: supR3HardenedDllNotificationCallback: load 000007fefc600000 LB 0x00050000 C:\Windows\system32\ncrypt.dll [fFlags=0x0]
96123338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\ncrypt.dll [lacks WinVerifyTrust]
96223338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc600000 'C:\Windows\system32\ncrypt.dll'
96323338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
96423338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcrypt.dll (Input=bcrypt.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ec701:<flags> [calling]
96523338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc5d0000 'C:\Windows\system32\bcrypt.dll'
96623338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
96723338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'rpcrt4.dll'.
96823338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'profapi.dll'.
96923338.1f228: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\userenv.dll)
97023338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\userenv.dll
97123338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'profapi.dll'...
97223338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'profapi.dll' -> '\Device\HarddiskVolume1\Windows\System32\profapi.dll' [rcNtRedir=0xc0150008]
97323338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
97423338.1f228: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\profapi.dll)
97523338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\profapi.dll
97623338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
97723338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
97823338.1f228: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
97923338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
98023338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
98123338.1f228: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
98223338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
98323338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
98423338.1f228: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
98523338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\USERENV.dll (Input=USERENV.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ec091:<flags> [calling]
98623338.1f228: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\userenv.dll [lacks WinVerifyTrust]
98723338.1f228: supR3HardenedDllNotificationCallback: load 000007fefd220000 LB 0x0001f000 C:\Windows\system32\USERENV.dll [fFlags=0x0]
98823338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\userenv.dll [lacks WinVerifyTrust]
98923338.1f228: supR3HardenedDllNotificationCallback: load 000007fefcf70000 LB 0x0000f000 C:\Windows\system32\profapi.dll [fFlags=0x0]
99023338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\profapi.dll [lacks WinVerifyTrust]
99123338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd220000 'C:\Windows\system32\USERENV.dll'
99223338.1f228: supR3HardenedIsApiSetDll: '<NULL>' -> true
99323338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000001ebdf1:<flags> [calling]
99423338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd350000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
99523338.1f228: supR3HardenedIsApiSetDll: '<NULL>' -> true
99623338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000001ec181:<flags> [calling]
99723338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd350000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
99823338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
99923338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'rpcrt4.dll'.
100023338.1f228: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\gpapi.dll)
100123338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\gpapi.dll
100223338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
100323338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
100423338.1f228: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
100523338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
100623338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
100723338.1f228: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
100823338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\GPAPI.dll (Input=GPAPI.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ec3b1:<flags> [calling]
100923338.1f228: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\gpapi.dll [lacks WinVerifyTrust]
101023338.1f228: supR3HardenedDllNotificationCallback: load 000007fefb6c0000 LB 0x0001b000 C:\Windows\system32\GPAPI.dll [fFlags=0x0]
101123338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\gpapi.dll [lacks WinVerifyTrust]
101223338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefb6c0000 'C:\Windows\system32\GPAPI.dll'
101323338.1f228: supR3HardenedIsApiSetDll: '<NULL>' -> true
101423338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-Management-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000001ec301:<flags> [calling]
101523338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd350000 'API-MS-WIN-Service-Management-L1-1-0.dll'
101623338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
101723338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe180000 'C:\Windows\system32\rpcrt4.dll'
101823338.1f228: supR3HardenedIsApiSetDll: '<NULL>' -> true
101923338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-Management-L2-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000001ec2e1:<flags> [calling]
102023338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd350000 'API-MS-WIN-Service-Management-L2-1-0.dll'
102123338.1f228: supR3HardenedIsApiSetDll: '<NULL>' -> true
102223338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000001ec2f1:<flags> [calling]
102323338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd350000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
102423338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
102523338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'advapi32.dll'.
102623338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'crypt32.dll'.
102723338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'wldap32.dll'.
102823338.1f228: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\cryptnet.dll)
102923338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\cryptnet.dll
103023338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wldap32.dll'...
103123338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'wldap32.dll' -> '\Device\HarddiskVolume1\Windows\System32\wldap32.dll' [rcNtRedir=0xc0150008]
103223338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
103323338.1f228: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\Wldap32.dll)
103423338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\Wldap32.dll
103523338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
103623338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume1\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
103723338.1f228: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
103823338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
103923338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
104023338.1f228: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
104123338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
104223338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
104323338.1f228: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
104423338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
104523338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
104623338.1f228: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
104723338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (Input=cryptnet.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ebdf1:<flags> [calling]
104823338.1f228: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
104923338.1f228: supR3HardenedDllNotificationCallback: load 000007fef95f0000 LB 0x00027000 C:\Windows\system32\cryptnet.dll [fFlags=0x0]
105023338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
105123338.1f228: supR3HardenedDllNotificationCallback: load 000007feff120000 LB 0x00052000 C:\Windows\system32\WLDAP32.dll [fFlags=0x0]
105223338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\Wldap32.dll [lacks WinVerifyTrust]
105323338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
105423338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=00000000001eaff1:<flags> [calling]
105523338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef95f0000 'C:\Windows\system32\cryptnet.dll'
105623338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
105723338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=00000000001eaff1:<flags> [calling]
105823338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef95f0000 'C:\Windows\system32\cryptnet.dll'
105923338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
106023338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=00000000001eaff1:<flags> [calling]
106123338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef95f0000 'C:\Windows\system32\cryptnet.dll'
106223338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
106323338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=00000000001eaff1:<flags> [calling]
106423338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef95f0000 'C:\Windows\system32\cryptnet.dll'
106523338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
106623338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=00000000001eaff1:<flags> [calling]
106723338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef95f0000 'C:\Windows\system32\cryptnet.dll'
106823338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
106923338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=00000000001eaff1:<flags> [calling]
107023338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef95f0000 'C:\Windows\system32\cryptnet.dll'
107123338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
107223338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef95f0000 'C:\Windows\system32\cryptnet.dll'
107323338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
107423338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef95f0000 'C:\Windows\system32\cryptnet.dll'
107523338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
107623338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef95f0000 'C:\Windows\system32\cryptnet.dll'
107723338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
107823338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef95f0000 'C:\Windows\system32\cryptnet.dll'
107923338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
108023338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef95f0000 'C:\Windows\system32\cryptnet.dll'
108123338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef95f0000 'C:\Windows\system32\cryptnet.dll'
108223338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
108323338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef95f0000 'C:\Windows\system32\cryptnet.dll'
108423338.1f228: supR3HardenedIsApiSetDll: '<NULL>' -> true
108523338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000001eb711:<flags> [calling]
108623338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd350000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
108723338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\profapi.dll [lacks WinVerifyTrust]
108823338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\profapi.dll (Input=profapi.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001eb711:<flags> [calling]
108923338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcf70000 'C:\Windows\system32\profapi.dll'
109023338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
109123338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
109223338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msvcrt.dll'.
109323338.1f228: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\shlwapi.dll)
109423338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\shlwapi.dll
109523338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
109623338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
109723338.1f228: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
109823338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
109923338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
110023338.1f228: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\user32.dll [lacks WinVerifyTrust]
110123338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
110223338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
110323338.1f228: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
110423338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\SHLWAPI.dll (Input=SHLWAPI.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001eb1a1:<flags> [calling]
110523338.1f228: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\shlwapi.dll [lacks WinVerifyTrust]
110623338.1f228: supR3HardenedDllNotificationCallback: load 000007fefe740000 LB 0x00071000 C:\Windows\system32\SHLWAPI.dll [fFlags=0x0]
110723338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\shlwapi.dll [lacks WinVerifyTrust]
110823338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe740000 'C:\Windows\system32\SHLWAPI.dll'
110923338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
111023338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ecb21:<flags> [calling]
111123338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd0b0000 'C:\Windows\system32\crypt32.dll'
111223338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000000 pwszName=\SystemRoot\System32\ntdll.dll
111323338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: New context 0000000000957000
111423338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
111523338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F8CD815F0CD05638A6894535B0372BF0C0378D10
111623338.1f228: supR3HardenedIsApiSetDll: '<NULL>' -> true
111723338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000001ec0d1:<flags> [calling]
111823338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd350000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
111923338.1f228: supR3HardenedIsApiSetDll: '<NULL>' -> true
112023338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-Management-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000001ebc31:<flags> [calling]
112123338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd350000 'API-MS-WIN-Service-Management-L1-1-0.dll'
112223338.1f228: supR3HardenedIsApiSetDll: '<NULL>' -> true
112323338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-winsvc-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000001ebc31:<flags> [calling]
112423338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd350000 'API-MS-WIN-Service-winsvc-L1-1-0.dll'
112523338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
112623338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ADVAPI32.dll (Input=ADVAPI32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ec0d1:<flags> [calling]
112723338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe660000 'C:\Windows\system32\ADVAPI32.dll'
112823338.1f228: supR3HardenedIsApiSetDll: '<NULL>' -> true
112923338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-LSALookup-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000001ec081:<flags> [calling]
113023338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd350000 'API-MS-Win-Security-LSALookup-L1-1-0.dll'
113123338.1f228: supR3HardenedIsApiSetDll: '<NULL>' -> true
113223338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-LSALookup-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000001ebd71:<flags> [calling]
113323338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd350000 'API-MS-Win-Security-LSALookup-L1-1-0.dll'
113423338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
113523338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ec5a1:<flags> [calling]
113623338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd0b0000 'C:\Windows\system32\crypt32.dll'
113723338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_822_for_KB4534310~31bf3856ad364e35~amd64~~6.1.1.9.cat'; file='\SystemRoot\System32\ntdll.dll'
113823338.1f228: g_pfnWinVerifyTrust=000007fefd241010
113923338.1f228: supR3HardenedScreenImage/preload: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\crypt32.dll [redoing WinVerifyTrust]
114023338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000c4 pwszName=\Device\HarddiskVolume1\Windows\System32\crypt32.dll
114123338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
114223338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
114323338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=EB46C4F6B834DB9328784D5BE3326BD80E3042DA
114423338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
114523338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001eb311:<flags> [calling]
114623338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd0b0000 'C:\Windows\system32\crypt32.dll'
114723338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_822_for_KB4534310~31bf3856ad364e35~amd64~~6.1.1.9.cat'; file='\Device\HarddiskVolume1\Windows\System32\crypt32.dll'
114823338.1f228: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
114923338.1f228: supR3HardenedScreenImage/preload: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\crypt32.dll'
115023338.1f228: supR3HardenedScreenImage/preload: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\wintrust.dll [redoing WinVerifyTrust]
115123338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000b8 pwszName=\Device\HarddiskVolume1\Windows\System32\wintrust.dll
115223338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
115323338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
115423338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=C1F7258EF71AF066FD00F9B71F0DE2B52FBACE45
115523338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\crypt32.dll
115623338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001eb311:<flags> [calling]
115723338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd0b0000 'C:\Windows\system32\crypt32.dll'
115823338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_822_for_KB4534310~31bf3856ad364e35~amd64~~6.1.1.9.cat'; file='\Device\HarddiskVolume1\Windows\System32\wintrust.dll'
115923338.1f228: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
116023338.1f228: supR3HardenedScreenImage/preload: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\wintrust.dll'
116123338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000404 pwszName=\Device\HarddiskVolume1\Windows\System32\shlwapi.dll
116223338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
116323338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
116423338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=0AB8D9C9D3E1FC95D01F9A984B16ED031BB40CD8
116523338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\shlwapi.dll'
116623338.1f228: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
116723338.1f228: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\shlwapi.dll'
116823338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000003f8 pwszName=\Device\HarddiskVolume1\Windows\System32\Wldap32.dll
116923338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
117023338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
117123338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=086A94704E162AB5C6F0ED4BA6DE6C8B4524BA56
117223338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd0b0000 'C:\Windows\system32\crypt32.dll'
117323338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_822_for_KB4534310~31bf3856ad364e35~amd64~~6.1.1.9.cat'; file='\Device\HarddiskVolume1\Windows\System32\Wldap32.dll'
117423338.1f228: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
117523338.1f228: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\Wldap32.dll'
117623338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000003f4 pwszName=\Device\HarddiskVolume1\Windows\System32\cryptnet.dll
117723338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
117823338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
117923338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=E4160C19B4AE8E9DA7E4CF6F902F681967E258DC
118023338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd0b0000 'C:\Windows\system32\crypt32.dll'
118123338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_822_for_KB4534310~31bf3856ad364e35~amd64~~6.1.1.9.cat'; file='\Device\HarddiskVolume1\Windows\System32\cryptnet.dll'
118223338.1f228: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
118323338.1f228: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\cryptnet.dll'
118423338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000002b4 pwszName=\Device\HarddiskVolume1\Windows\System32\gpapi.dll
118523338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
118623338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
118723338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=EBDAA16C3FD93DFF9C20BA3B2689DFF4C8D31061
118823338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_115_for_KB3159398~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume1\Windows\System32\gpapi.dll'
118923338.1f228: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
119023338.1f228: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\gpapi.dll'
119123338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000220 pwszName=\Device\HarddiskVolume1\Windows\System32\profapi.dll
119223338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
119323338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
119423338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2449672745D9BA339420451D13FA0380AA768231
119523338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume1\Windows\System32\profapi.dll'
119623338.1f228: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
119723338.1f228: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\profapi.dll'
119823338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000021c pwszName=\Device\HarddiskVolume1\Windows\System32\userenv.dll
119923338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
120023338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
120123338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=8128043E2DB517CE21AC6C645E17AA014BE6A2CB
120223338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd0b0000 'C:\Windows\system32\crypt32.dll'
120323338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_822_for_KB4534310~31bf3856ad364e35~amd64~~6.1.1.9.cat'; file='\Device\HarddiskVolume1\Windows\System32\userenv.dll'
120423338.1f228: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
120523338.1f228: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\userenv.dll'
120623338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000208 pwszName=\Device\HarddiskVolume1\Windows\System32\ncrypt.dll
120723338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
120823338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
120923338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=E9B60D8E91DE4B6BD8680A8EA9952E873AF643EE
121023338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd0b0000 'C:\Windows\system32\crypt32.dll'
121123338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_822_for_KB4534310~31bf3856ad364e35~amd64~~6.1.1.9.cat'; file='\Device\HarddiskVolume1\Windows\System32\ncrypt.dll'
121223338.1f228: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
121323338.1f228: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\ncrypt.dll'
121423338.1f228: supR3HardNtViCallWinVerifyTrust: WinVerifyTrust failed with 0x800b010a (CERT_E_CHAINING) on '\Device\HarddiskVolume1\Program Files\NVIDIA Corporation\coprocmanager\nvdxgiwrapx.dll'
121523338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000204 pwszName=\Device\HarddiskVolume1\Program Files\NVIDIA Corporation\coprocmanager\nvdxgiwrapx.dll
121623338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
121723338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
121823338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=4AFCEDBD0386D5B6429C0FDF7498C1608DE17EC2
121923338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem27.CAT'; file='\Device\HarddiskVolume1\Program Files\NVIDIA Corporation\coprocmanager\nvdxgiwrapx.dll'
122023338.1f228: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (was CERT_E_CHAINING)
122123338.1f228: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 24202) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Program Files\NVIDIA Corporation\coprocmanager\nvdxgiwrapx.dll'
122223338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000001c8 pwszName=\Device\HarddiskVolume1\Windows\System32\ole32.dll
122323338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
122423338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
122523338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=41C849408ED6D9A5379745F72C06BA402FAFD6B4
122623338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd0b0000 'C:\Windows\system32\crypt32.dll'
122723338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_822_for_KB4534310~31bf3856ad364e35~amd64~~6.1.1.9.cat'; file='\Device\HarddiskVolume1\Windows\System32\ole32.dll'
122823338.1f228: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
122923338.1f228: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\ole32.dll'
123023338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000001c4 pwszName=\Device\HarddiskVolume1\Windows\System32\cfgmgr32.dll
123123338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
123223338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
123323338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=8F731777EFC4BC982C1E1467FBF29A74CC14D93A
123423338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\cfgmgr32.dll'
123523338.1f228: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
123623338.1f228: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\cfgmgr32.dll'
123723338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000001c0 pwszName=\Device\HarddiskVolume1\Windows\System32\oleaut32.dll
123823338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
123923338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
124023338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=DF3169AB12A33146DE2E4D9C648CB8C041F20136
124123338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd0b0000 'C:\Windows\system32\crypt32.dll'
124223338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_822_for_KB4534310~31bf3856ad364e35~amd64~~6.1.1.9.cat'; file='\Device\HarddiskVolume1\Windows\System32\oleaut32.dll'
124323338.1f228: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
124423338.1f228: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\oleaut32.dll'
124523338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000001bc pwszName=\Device\HarddiskVolume1\Windows\System32\devobj.dll
124623338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
124723338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
124823338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B410A095222E69F0ECE7D66E4AC27A7125D2EB5A
124923338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\devobj.dll'
125023338.1f228: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
125123338.1f228: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\devobj.dll'
125223338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000001b8 pwszName=\Device\HarddiskVolume1\Windows\System32\setupapi.dll
125323338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
125423338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
125523338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=1499C4FEA6E143F9BEC35B4FFA098917D3A6EBF2
125623338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\setupapi.dll'
125723338.1f228: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
125823338.1f228: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\setupapi.dll'
125923338.1f228: supR3HardNtViCallWinVerifyTrust: WinVerifyTrust failed with 0x800b010a (CERT_E_CHAINING) on '\Device\HarddiskVolume1\Program Files\NVIDIA Corporation\coprocmanager\Nvd3d9wrapx.dll'
126023338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000001b4 pwszName=\Device\HarddiskVolume1\Program Files\NVIDIA Corporation\coprocmanager\Nvd3d9wrapx.dll
126123338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
126223338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
126323338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=695ACD125CEFF9F81B4477D40E4F48230DA7575A
126423338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem27.CAT'; file='\Device\HarddiskVolume1\Program Files\NVIDIA Corporation\coprocmanager\Nvd3d9wrapx.dll'
126523338.1f228: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (was CERT_E_CHAINING)
126623338.1f228: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 24202) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Program Files\NVIDIA Corporation\coprocmanager\Nvd3d9wrapx.dll'
126723338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000001b0 pwszName=\Device\HarddiskVolume1\Program Files\NVIDIA Corporation\coprocmanager\detoured.dll
126823338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
126923338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
127023338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=0F8698A026E11A08C881A657EBEF003ACEB45DEC
127123338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem27.CAT'; file='\Device\HarddiskVolume1\Program Files\NVIDIA Corporation\coprocmanager\detoured.dll'
127223338.1f228: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
127323338.1f228: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Program Files\NVIDIA Corporation\coprocmanager\detoured.dll'
127423338.1f228: supR3HardNtViCallWinVerifyTrust: WinVerifyTrust failed with 0x800b010a (CERT_E_CHAINING) on '\Device\HarddiskVolume1\Windows\System32\nvinitx.dll'
127523338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000001a8 pwszName=\Device\HarddiskVolume1\Windows\System32\nvinitx.dll
127623338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
127723338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
127823338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=C0D2EF1199F6922E255762832EFCD158CB488C63
127923338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem27.CAT'; file='\Device\HarddiskVolume1\Windows\System32\nvinitx.dll'
128023338.1f228: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (was CERT_E_CHAINING)
128123338.1f228: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 24202) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\nvinitx.dll'
128223338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000018c pwszName=\Device\HarddiskVolume1\Windows\System32\msctf.dll
128323338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
128423338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
128523338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=5B282A2631D47B459D3BFB9E19817422A5BDA7C7
128623338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd0b0000 'C:\Windows\system32\crypt32.dll'
128723338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_822_for_KB4534310~31bf3856ad364e35~amd64~~6.1.1.9.cat'; file='\Device\HarddiskVolume1\Windows\System32\msctf.dll'
128823338.1f228: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
128923338.1f228: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\msctf.dll'
129023338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000188 pwszName=\Device\HarddiskVolume1\Windows\System32\imm32.dll
129123338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
129223338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
129323338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=6EEE1AB3B6D79AFF857940FF5F51ED27698153EC
129423338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume1\Windows\System32\imm32.dll'
129523338.1f228: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
129623338.1f228: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\imm32.dll'
129723338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000184 pwszName=\Device\HarddiskVolume1\Windows\System32\usp10.dll
129823338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
129923338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
130023338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=CCB7F806B584BC833CCB45233D3BC2338D720DD4
130123338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\crypt32.dll
130223338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ea981:<flags> [calling]
130323338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd0b0000 'C:\Windows\system32\crypt32.dll'
130423338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_822_for_KB4534310~31bf3856ad364e35~amd64~~6.1.1.9.cat'; file='\Device\HarddiskVolume1\Windows\System32\usp10.dll'
130523338.1f228: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
130623338.1f228: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\usp10.dll'
130723338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000180 pwszName=\Device\HarddiskVolume1\Windows\System32\lpk.dll
130823338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
130923338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
131023338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=E2E1B84E3D9D8988B641F2EA9E2FAEF8CEEACAF0
131123338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd0b0000 'C:\Windows\system32\crypt32.dll'
131223338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_822_for_KB4534310~31bf3856ad364e35~amd64~~6.1.1.9.cat'; file='\Device\HarddiskVolume1\Windows\System32\lpk.dll'
131323338.1f228: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
131423338.1f228: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\lpk.dll'
131523338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000017c pwszName=\Device\HarddiskVolume1\Windows\System32\gdi32.dll
131623338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
131723338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
131823338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=46C6553832B642058240BB0EC294D9684053FA28
131923338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd0b0000 'C:\Windows\system32\crypt32.dll'
132023338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_822_for_KB4534310~31bf3856ad364e35~amd64~~6.1.1.9.cat'; file='\Device\HarddiskVolume1\Windows\System32\gdi32.dll'
132123338.1f228: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
132223338.1f228: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\gdi32.dll'
132323338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000178 pwszName=\Device\HarddiskVolume1\Windows\System32\user32.dll
132423338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
132523338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
132623338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=D7A5A1283302E26EA13000CD81ADE080BA465337
132723338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd0b0000 'C:\Windows\system32\crypt32.dll'
132823338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_822_for_KB4534310~31bf3856ad364e35~amd64~~6.1.1.9.cat'; file='\Device\HarddiskVolume1\Windows\System32\user32.dll'
132923338.1f228: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
133023338.1f228: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\user32.dll'
133123338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000174 pwszName=\Device\HarddiskVolume1\Windows\System32\imagehlp.dll
133223338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
133323338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
133423338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2702EE05F1B717B0F2CE0FBE32784A47B8419DCA
133523338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_2_for_KB2893294~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume1\Windows\System32\imagehlp.dll'
133623338.1f228: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
133723338.1f228: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\imagehlp.dll'
133823338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000118 pwszName=\Device\HarddiskVolume1\Windows\System32\cryptbase.dll
133923338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
134023338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
134123338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=4B00C47C46ED3B51BBFC3F8FE80751A96F25C3EA
134223338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd0b0000 'C:\Windows\system32\crypt32.dll'
134323338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_822_for_KB4534310~31bf3856ad364e35~amd64~~6.1.1.9.cat'; file='\Device\HarddiskVolume1\Windows\System32\cryptbase.dll'
134423338.1f228: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
134523338.1f228: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\cryptbase.dll'
134623338.1f228: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\rsaenh.dll'
134723338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000114 pwszName=\Device\HarddiskVolume1\Windows\System32\cryptsp.dll
134823338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
134923338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
135023338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=4D212E5620D5CC7084245971F59495972AE15D84
135123338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd0b0000 'C:\Windows\system32\crypt32.dll'
135223338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_822_for_KB4534310~31bf3856ad364e35~amd64~~6.1.1.9.cat'; file='\Device\HarddiskVolume1\Windows\System32\cryptsp.dll'
135323338.1f228: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
135423338.1f228: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\cryptsp.dll'
135523338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000104 pwszName=\Device\HarddiskVolume1\Windows\System32\sechost.dll
135623338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
135723338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
135823338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=CB669FA8DB80F8E50A29D055BB8D558E10E5E6B4
135923338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_85_for_KB3068708~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume1\Windows\System32\sechost.dll'
136023338.1f228: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
136123338.1f228: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\sechost.dll'
136223338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000100 pwszName=\Device\HarddiskVolume1\Windows\System32\advapi32.dll
136323338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
136423338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
136523338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=DD8EB2AA54C831F3AF5671C72D3359678F561895
136623338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd0b0000 'C:\Windows\system32\crypt32.dll'
136723338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_822_for_KB4534310~31bf3856ad364e35~amd64~~6.1.1.9.cat'; file='\Device\HarddiskVolume1\Windows\System32\advapi32.dll'
136823338.1f228: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
136923338.1f228: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\advapi32.dll'
137023338.1f228: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\bcryptprimitives.dll'
137123338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000e8 pwszName=\Device\HarddiskVolume1\Windows\System32\bcrypt.dll
137223338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
137323338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
137423338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=392B33B84600AC5ED0D2F6C5EC6F1E2AB7C64234
137523338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd0b0000 'C:\Windows\system32\crypt32.dll'
137623338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_822_for_KB4534310~31bf3856ad364e35~amd64~~6.1.1.9.cat'; file='\Device\HarddiskVolume1\Windows\System32\bcrypt.dll'
137723338.1f228: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
137823338.1f228: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\bcrypt.dll'
137923338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000c8 pwszName=\Device\HarddiskVolume1\Windows\System32\msvcrt.dll
138023338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
138123338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
138223338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2CA2FD632B264C063162F71474266E3615B6420C
138323338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB2654428~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume1\Windows\System32\msvcrt.dll'
138423338.1f228: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
138523338.1f228: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll'
138623338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000c0 pwszName=\Device\HarddiskVolume1\Windows\System32\msasn1.dll
138723338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
138823338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
138923338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F2FF57DC30D774F93061607060DAA0DD15E39CCE
139023338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\msasn1.dll'
139123338.1f228: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
139223338.1f228: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\msasn1.dll'
139323338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000bc pwszName=\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll
139423338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
139523338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
139623338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=487CAE399C22924A675FED14D1CB8898D92C81B9
139723338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd0b0000 'C:\Windows\system32\crypt32.dll'
139823338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_822_for_KB4534310~31bf3856ad364e35~amd64~~6.1.1.9.cat'; file='\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll'
139923338.1f228: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
140023338.1f228: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll'
140123338.1f228: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 24202) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxSupLib.dll'
140223338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000028 pwszName=\Device\HarddiskVolume1\Windows\System32\KernelBase.dll
140323338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
140423338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
140523338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=D8459AE7ED3F113B897E375D67EA01B027C8E524
140623338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd0b0000 'C:\Windows\system32\crypt32.dll'
140723338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_822_for_KB4534310~31bf3856ad364e35~amd64~~6.1.1.9.cat'; file='\Device\HarddiskVolume1\Windows\System32\KernelBase.dll'
140823338.1f228: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
140923338.1f228: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\KernelBase.dll'
141023338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000020 pwszName=\Device\HarddiskVolume1\Windows\System32\kernel32.dll
141123338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
141223338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
141323338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F72682744C68FE06FC8B7C2643183184F472F3A1
141423338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd0b0000 'C:\Windows\system32\crypt32.dll'
141523338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_822_for_KB4534310~31bf3856ad364e35~amd64~~6.1.1.9.cat'; file='\Device\HarddiskVolume1\Windows\System32\kernel32.dll'
141623338.1f228: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
141723338.1f228: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\kernel32.dll'
141823338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd0b0000 'C:\Windows\system32\crypt32.dll'
141923338.1f228: supR3HardenedWinIsDesiredRootCA: Adding 0x5ad46780fa5df300 DC=com, DC=microsoft, CN=Microsoft Root Certificate Authority
142023338.1f228: supR3HardenedWinIsDesiredRootCA: Adding 0xea5386456178582b C=ZA, ST=Western Cape, L=Durbanville, O=Thawte, OU=Thawte Certification, CN=Thawte Timestamping CA
142123338.1f228: supR3HardenedWinIsDesiredRootCA: Adding 0x3be670c1bd02a900 OU=Copyright (c) 1997 Microsoft Corp., OU=Microsoft Corporation, CN=Microsoft Root Authority
142223338.1f228: supR3HardenedWinIsDesiredRootCA: Adding 0x4d3835aa4180b200 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2011
142323338.1f228: supR3HardenedWinIsDesiredRootCA: Adding 0x646e3fe3ba08df00 C=US, O=MSFT, CN=Microsoft Authenticode(tm) Root Authority
142423338.1f228: supR3HardenedWinIsDesiredRootCA: Adding 0xece4e4289e08b900 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010
142523338.1f228: supR3HardenedWinIsDesiredRootCA: Adding 0x43a9cc371ff5385a O=Microsoft Trust Network, OU=Microsoft Corporation, OU=Microsoft Time Stamping Service Root, OU=Copyright (c) 1997 Microsoft Corp.
142623338.1f228: supR3HardenedWinIsDesiredRootCA: Adding 0x2e2d2c7c68f0202e O=VeriSign Trust Network, OU=VeriSign, Inc., OU=VeriSign Time Stamping Service Root, OU=NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.
142723338.1f228: supR3HardenedWinIsDesiredRootCA: Adding 0x61a3a33f81aace00 C=US, ST=UT, L=Salt Lake City, O=The USERTRUST Network, OU=http://www.usertrust.com, CN=UTN-USERFirst-Object
142823338.1f228: supR3HardenedWinIsDesiredRootCA: Adding 0x6b7bdc34cd37bb00 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root G2
142923338.1f228: supR3HardenedWinIsDesiredRootCA: Adding 0x57ba5395b561bf00 C=BM, O=QuoVadis Limited, OU=Root Certification Authority, CN=QuoVadis Root Certification Authority
143023338.1f228: supR3HardenedWinIsDesiredRootCA: Adding 0xf4fd306318ccda00 C=US, O=GeoTrust Inc., CN=GeoTrust Global CA
143123338.1f228: supR3HardenedWinIsDesiredRootCA: Adding 0x83085097e9afdf00 O=Digital Signature Trust Co., CN=DST Root CA X3
143223338.1f228: supR3HardenedWinIsDesiredRootCA: Adding 0x780679907625cc00 OU=GlobalSign Root CA - R3, O=GlobalSign, CN=GlobalSign
143323338.1f228: supR3HardenedWinIsDesiredRootCA: Adding 0x3d98ab22bb04a300 C=IE, O=Baltimore, OU=CyberTrust, CN=Baltimore CyberTrust Root
143423338.1f228: supR3HardenedWinIsDesiredRootCA: Adding 0xa0ee62086758b15d C=US, O=Equifax, OU=Equifax Secure Certificate Authority
143523338.1f228: supR3HardenedWinIsDesiredRootCA: Adding 0xd944bca189a00 C=BM, O=QuoVadis Limited, CN=QuoVadis Root CA 2
143623338.1f228: supR3HardenedWinIsDesiredRootCA: Adding 0x8ff6fc03c1edbd00 C=US, ST=Arizona, L=Scottsdale, O=Starfield Technologies, Inc., CN=Starfield Root Certificate Authority - G2
143723338.1f228: supR3HardenedWinIsDesiredRootCA: Adding 0xc6fa4243b695b600 C=US, O=Entrust, Inc., OU=www.entrust.net/CPS is incorporated by reference, OU=(c) 2006 Entrust, Inc., CN=Entrust Root Certification Authority
143823338.1f228: supR3HardenedWinIsDesiredRootCA: Adding 0xa3ce8d99e60eda00 C=BE, O=GlobalSign nv-sa, OU=Root CA, CN=GlobalSign Root CA
143923338.1f228: supR3HardenedWinIsDesiredRootCA: Adding 0x560ad29254e89100 C=GB, ST=Greater Manchester, L=Salford, O=COMODO CA Limited, CN=COMODO RSA Certification Authority
144023338.1f228: supR3HardenedWinIsDesiredRootCA: Adding 0xa671e9fec832b700 C=US, O=Starfield Technologies, Inc., OU=Starfield Class 2 Certification Authority
144123338.1f228: supR3HardenedWinIsDesiredRootCA: Adding 0xa8de7211e13be200 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root CA
144223338.1f228: supR3HardenedWinIsDesiredRootCA: Adding 0x7ae89c50f0b6a00f C=US, O=GTE Corporation, OU=GTE CyberTrust Solutions, Inc., CN=GTE CyberTrust Global Root
144323338.1f228: supR3HardenedWinIsDesiredRootCA: Adding 0xd45980fbf0a0ac00 C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2006 thawte, Inc. - For authorized use only, CN=thawte Primary Root CA
144423338.1f228: supR3HardenedWinIsDesiredRootCA: Adding 0xc9edb72b684ba00 C=US, O=Entrust, Inc., OU=See www.entrust.net/legal-terms, OU=(c) 2009 Entrust, Inc. - for authorized use only, CN=Entrust Root Certification Authority - G2
144523338.1f228: supR3HardenedWinIsDesiredRootCA: Adding 0xf5cd95e581a4ab00 C=US, O=SecureTrust Corporation, CN=SecureTrust CA
144623338.1f228: supR3HardenedWinIsDesiredRootCA: Adding 0x6f2ebe0e24cfa600 OU=GlobalSign Root CA - R2, O=GlobalSign, CN=GlobalSign
144723338.1f228: supR3HardenedWinIsDesiredRootCA: Adding 0x14018a1bf29e595c C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority
144823338.1f228: supR3HardenedWinIsDesiredRootCA: Adding 0x9e5bc2d78b6a3636 C=ZA, ST=Western Cape, L=Cape Town, O=Thawte Consulting cc, OU=Certification Services Division, CN=Thawte Premium Server CA, [email protected]
144923338.1f228: supR3HardenedWinIsDesiredRootCA: Adding 0xd4fbe673e5ccc600 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA
145023338.1f228: supR3HardenedWinIsDesiredRootCA: Adding 0xf8dae202a2dfca00 C=CH, O=SwissSign AG, CN=SwissSign Platinum CA - G2
145123338.1f228: supR3HardenedWinIsDesiredRootCA: Adding 0x357a29080824af00 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2006 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G5
145223338.1f228: supR3HardenedWinIsDesiredRootCA: Adding 0x59faf1086271bf00 C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com, Inc., CN=Go Daddy Root Certificate Authority - G2
145323338.1f228: supR3HardenedWinIsDesiredRootCA: Adding 0x30669a4e82fa800 C=US, O=America Online Inc., CN=America Online Root Certification Authority 1
145423338.1f228: supR3HardenedWinIsDesiredRootCA: Adding 0x3401b15e3761c700 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2008 VeriSign, Inc. - For authorized use only, CN=VeriSign Universal Root Certification Authority
145523338.1f228: supR3HardenedWinIsDesiredRootCA: Adding 0xc30e361765128000 C=US, ST=New Jersey, L=Jersey City, O=The USERTRUST Network, CN=USERTrust RSA Certification Authority
145623338.1f228: supR3HardenedWinIsDesiredRootCA: Adding 0x491857ead79dde00 C=US, O=The Go Daddy Group, Inc., OU=Go Daddy Class 2 Certification Authority
145723338.1f228: supR3HardenedWinIsDesiredRootCA: Adding 0xc2ba72a37dfbe300 C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Trusted Network CA
145823338.1f228: supR3HardenedWinIsDesiredRootCA: Adding 0x8043e4ce150ead00 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID Root CA
145923338.1f228: supR3HardenedWinIsDesiredRootCA: Adding 0x331d58625ee2dc00 C=US, O=GeoTrust Inc., OU=(c) 2008 GeoTrust Inc. - For authorized use only, CN=GeoTrust Primary Certification Authority - G3
146023338.1f228: supR3HardenedWinIsDesiredRootCA: Adding 0xf2e6331af7b700 C=SE, O=AddTrust AB, OU=AddTrust External TTP Network, CN=AddTrust External CA Root
146123338.1f228: supR3HardenedWinRetrieveTrustedRootCAs: cAdded=42
146223338.1f228: SUPR3HardenedMain: Load Runtime...
146323338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
146423338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
146523338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rpcrt4.dll'.
146623338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ws2_32.dll'.
146723338.1f228: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxRT.dll) WinVerifyTrust
146823338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxRT.dll
146923338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
147023338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
147123338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000047c pwszName=\Device\HarddiskVolume1\Windows\System32\ws2_32.dll
147223338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
147323338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
147423338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=901DCB8172024F14E25295BF5692180F12FC8C18
147523338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3161949~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume1\Windows\System32\ws2_32.dll'
147623338.1f228: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
147723338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
147823338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'rpcrt4.dll'.
147923338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'nsi.dll'.
148023338.1f228: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\ws2_32.dll) WinVerifyTrust
148123338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\ws2_32.dll
148223338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
148323338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
148423338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
148523338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
148623338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
148723338.1f228: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcp100.dll) WinVerifyTrust
148823338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcp100.dll
148923338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
149023338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
149123338.1f228: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcr100.dll) WinVerifyTrust
149223338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcr100.dll
149323338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
149423338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
149523338.1f228: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcr100.dll
149623338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
149723338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume1\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
149823338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000460 pwszName=\Device\HarddiskVolume1\Windows\System32\nsi.dll
149923338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
150023338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
150123338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=5C61E0233B4D23762E0FE158DE0FDC6C24988F13
150223338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd0b0000 'C:\Windows\system32\crypt32.dll'
150323338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_822_for_KB4534310~31bf3856ad364e35~amd64~~6.1.1.9.cat'; file='\Device\HarddiskVolume1\Windows\System32\nsi.dll'
150423338.1f228: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
150523338.1f228: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\nsi.dll) WinVerifyTrust
150623338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\nsi.dll
150723338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
150823338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
150923338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
151023338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
151123338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ebea1:<flags> [calling]
151223338.1f228: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxRT.dll
151323338.1f228: supR3HardenedDllNotificationCallback: load 000007fee1460000 LB 0x005ed000 C:\Program Files\Oracle\VirtualBox\VBoxRT.dll [fFlags=0x0]
151423338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxRT.dll
151523338.1f228: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcr100.dll
151623338.1f228: supR3HardenedDllNotificationCallback: load 0000000056330000 LB 0x000d2000 C:\Program Files\Oracle\VirtualBox\MSVCR100.dll [fFlags=0x0]
151723338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcr100.dll
151823338.1f228: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcp100.dll
151923338.1f228: supR3HardenedDllNotificationCallback: load 0000000056290000 LB 0x00098000 C:\Program Files\Oracle\VirtualBox\MSVCP100.dll [fFlags=0x0]
152023338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcp100.dll
152123338.1f228: supR3HardenedDllNotificationCallback: load 000007fefef50000 LB 0x0004d000 C:\Windows\system32\WS2_32.dll [fFlags=0x0]
152223338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ws2_32.dll
152323338.1f228: supR3HardenedDllNotificationCallback: load 000007feff180000 LB 0x00008000 C:\Windows\system32\NSI.dll [fFlags=0x0]
152423338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\nsi.dll
152523338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxRT.dll
152623338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001e9581:<flags> [calling]
152723338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee1460000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
152823338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxRT.dll
152923338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001e9581:<flags> [calling]
153023338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee1460000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
153123338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxRT.dll
153223338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001e9581:<flags> [calling]
153323338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee1460000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
153423338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxRT.dll
153523338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001e9581:<flags> [calling]
153623338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee1460000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
153723338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxRT.dll
153823338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001e9581:<flags> [calling]
153923338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee1460000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
154023338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxRT.dll
154123338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001e9581:<flags> [calling]
154223338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee1460000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
154323338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee1460000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
154423338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee1460000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
154523338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee1460000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
154623338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee1460000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
154723338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee1460000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
154823338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee1460000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
154923338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee1460000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
155023338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxRT.dll
155123338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001e9581:<flags> [calling]
155223338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee1460000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
155323338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee1460000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
155423338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee1460000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
155523338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee1460000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
155623338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee1460000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
155723338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee1460000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
155823338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee1460000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
155923338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee1460000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
156023338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee1460000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
156123338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee1460000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
156223338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee1460000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
156323338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee1460000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
156423338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee1460000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
156523338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee1460000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
156623338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee1460000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
156723338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee1460000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
156823338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxRT.dll
156923338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001e9581:<flags> [calling]
157023338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee1460000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
157123338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee1460000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
157223338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee1460000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
157323338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee1460000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
157423338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\wintrust.dll
157523338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001eda01:<flags> [calling]
157623338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd240000 'C:\Windows\system32\Wintrust.dll'
157723338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd0b0000 'C:\Windows\system32\crypt32.dll'
157823338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd0b0000 'C:\Windows\system32\crypt32.dll'
157923338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd0b0000 'C:\Windows\system32\crypt32.dll'
158023338.1f228: SUPR3HardenedMain: Load TrustedMain...
158123338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'opengl32.dll'.
158223338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'uicommon.dll'.
158323338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
158423338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcp100.dll'.
158523338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msvcr100.dll'.
158623338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'qt5corevbox.dll'.
158723338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'qt5guivbox.dll'.
158823338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'qt5widgetsvbox.dll'.
158923338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'qt5openglvbox.dll'.
159023338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'user32.dll'.
159123338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'ole32.dll'.
159223338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'oleaut32.dll'.
159323338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'winmm.dll'.
159423338.1f228: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll) WinVerifyTrust
159523338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll
159623338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
159723338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume1\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
159823338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004e0 pwszName=\Device\HarddiskVolume1\Windows\System32\winmm.dll
159923338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
160023338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
160123338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=82E2B2A7826F88BEB98FFF0540C9BDB0A12F001A
160223338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume1\Windows\System32\winmm.dll'
160323338.1f228: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
160423338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
160523338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
160623338.1f228: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\winmm.dll) WinVerifyTrust
160723338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\winmm.dll
160823338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
160923338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume1\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
161023338.1f228: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\oleaut32.dll
161123338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
161223338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
161323338.1f228: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ole32.dll
161423338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
161523338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
161623338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5openglvbox.dll'...
161723338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5openglvbox.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\qt5openglvbox.dll' [rcNtRedir=0xc0150008]
161823338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'qt5widgetsvbox.dll'.
161923338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'qt5guivbox.dll'.
162023338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5corevbox.dll'.
162123338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcr100.dll'.
162223338.1f228: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll) WinVerifyTrust
162323338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll
162423338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
162523338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
162623338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
162723338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
162823338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5guivbox.dll'.
162923338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qt5corevbox.dll'.
163023338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'shell32.dll'.
163123338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcp100.dll'.
163223338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcr100.dll'.
163323338.1f228: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll) WinVerifyTrust
163423338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll
163523338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
163623338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
163723338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ole32.dll'.
163823338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'opengl32.dll'.
163923338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
164023338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
164123338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qt5corevbox.dll'.
164223338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcp100.dll'.
164323338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcr100.dll'.
164423338.1f228: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll) WinVerifyTrust
164523338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
164623338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
164723338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
164823338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
164923338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'shell32.dll'.
165023338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ole32.dll'.
165123338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
165223338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ws2_32.dll'.
165323338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'mpr.dll'.
165423338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'msvcp100.dll'.
165523338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'msvcr100.dll'.
165623338.1f228: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll) WinVerifyTrust
165723338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
165823338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
165923338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
166023338.1f228: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcr100.dll
166123338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
166223338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
166323338.1f228: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcp100.dll
166423338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
166523338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
166623338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'uicommon.dll'...
166723338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'uicommon.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\uicommon.dll' [rcNtRedir=0xc0150008]
166823338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'vboxrt.dll'.
166923338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcr100.dll'.
167023338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5corevbox.dll'.
167123338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qt5guivbox.dll'.
167223338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qt5widgetsvbox.dll'.
167323338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
167423338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'advapi32.dll'.
167523338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'ole32.dll'.
167623338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'oleaut32.dll'.
167723338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'rpcrt4.dll'.
167823338.1f228: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\UICommon.dll) WinVerifyTrust
167923338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\UICommon.dll
168023338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
168123338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume1\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
168223338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004fc pwszName=\Device\HarddiskVolume1\Windows\System32\opengl32.dll
168323338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
168423338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
168523338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=608AC397FCC42B9FBAE25CB8C25EAF4C19AA384D
168623338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume1\Windows\System32\opengl32.dll'
168723338.1f228: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
168823338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
168923338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
169023338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'gdi32.dll'.
169123338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'glu32.dll'.
169223338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ddraw.dll'.
169323338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'user32.dll'.
169423338.1f228: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\opengl32.dll) WinVerifyTrust
169523338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\opengl32.dll
169623338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
169723338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
169823338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ddraw.dll'...
169923338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'ddraw.dll' -> '\Device\HarddiskVolume1\Windows\System32\ddraw.dll' [rcNtRedir=0xc0150008]
170023338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004ec pwszName=\Device\HarddiskVolume1\Windows\System32\ddraw.dll
170123338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
170223338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
170323338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=24C763EA54CD792A0F1618411061DC356EE31FF6
170423338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume1\Windows\System32\ddraw.dll'
170523338.1f228: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
170623338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
170723338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
170823338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'dciman32.dll'.
170923338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
171023338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'setupapi.dll'.
171123338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'dwmapi.dll'.
171223338.1f228: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\ddraw.dll) WinVerifyTrust
171323338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\ddraw.dll
171423338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'glu32.dll'...
171523338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'glu32.dll' -> '\Device\HarddiskVolume1\Windows\System32\glu32.dll' [rcNtRedir=0xc0150008]
171623338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004c8 pwszName=\Device\HarddiskVolume1\Windows\System32\glu32.dll
171723338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
171823338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
171923338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=60E45AB914E06A11F44EA76C6EF750AF892F9EA2
172023338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume1\Windows\System32\glu32.dll'
172123338.1f228: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
172223338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
172323338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'opengl32.dll'.
172423338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
172523338.1f228: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\glu32.dll) WinVerifyTrust
172623338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\glu32.dll
172723338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
172823338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
172923338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
173023338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
173123338.1f228: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\advapi32.dll
173223338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
173323338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
173423338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
173523338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
173623338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
173723338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume1\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
173823338.1f228: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\oleaut32.dll
173923338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
174023338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
174123338.1f228: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ole32.dll
174223338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
174323338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
174423338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
174523338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
174623338.1f228: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\user32.dll
174723338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
174823338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
174923338.1f228: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll
175023338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
175123338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
175223338.1f228: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
175323338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
175423338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
175523338.1f228: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
175623338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
175723338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
175823338.1f228: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcr100.dll
175923338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
176023338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
176123338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
176223338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
176323338.1f228: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcr100.dll
176423338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
176523338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
176623338.1f228: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcp100.dll
176723338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mpr.dll'...
176823338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'mpr.dll' -> '\Device\HarddiskVolume1\Windows\System32\mpr.dll' [rcNtRedir=0xc0150008]
176923338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000050c pwszName=\Device\HarddiskVolume1\Windows\System32\mpr.dll
177023338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
177123338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
177223338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F84FE9BA047B24E7694C9E0C349B48B9FD5F925B
177323338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume1\Windows\System32\mpr.dll'
177423338.1f228: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
177523338.1f228: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\mpr.dll) WinVerifyTrust
177623338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\mpr.dll
177723338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
177823338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
177923338.1f228: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ws2_32.dll
178023338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
178123338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
178223338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
178323338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
178423338.1f228: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ole32.dll
178523338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
178623338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume1\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
178723338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000518 pwszName=\Device\HarddiskVolume1\Windows\System32\shell32.dll
178823338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
178923338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
179023338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=6F0FD5A01ADEE7CE965956E4165CC96F02202139
179123338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\crypt32.dll
179223338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
179323338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
179423338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
179523338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume1\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
179623338.1f228: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\opengl32.dll
179723338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
179823338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
179923338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dwmapi.dll'...
180023338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'dwmapi.dll' -> '\Device\HarddiskVolume1\Windows\System32\dwmapi.dll' [rcNtRedir=0xc0150008]
180123338.1f228: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume1\Windows\System32\dwmapi.dll'.
180223338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
180323338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
180423338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
180523338.1f228: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\dwmapi.dll)
180623338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\dwmapi.dll
180723338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
180823338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume1\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
180923338.1f228: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\setupapi.dll
181023338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
181123338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
181223338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dciman32.dll'...
181323338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'dciman32.dll' -> '\Device\HarddiskVolume1\Windows\System32\dciman32.dll' [rcNtRedir=0xc0150008]
181423338.1f228: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume1\Windows\System32\dciman32.dll'.
181523338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
181623338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'gdi32.dll'.
181723338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
181823338.1f228: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\dciman32.dll)
181923338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\dciman32.dll
182023338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
182123338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
182223338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
182323338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
182423338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
182523338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
182623338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
182723338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
182823338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
182923338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
183023338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
183123338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
183223338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
183323338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
183423338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
183523338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
183623338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001e94e1:<flags> [calling]
183723338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd0b0000 'C:\Windows\system32\crypt32.dll'
183823338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_822_for_KB4534310~31bf3856ad364e35~amd64~~6.1.1.9.cat'; file='\Device\HarddiskVolume1\Windows\System32\shell32.dll'
183923338.1f228: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
184023338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
184123338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #21 'shlwapi.dll'.
184223338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'user32.dll'.
184323338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #24 'gdi32.dll'.
184423338.1f228: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\shell32.dll) WinVerifyTrust
184523338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\shell32.dll
184623338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
184723338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
184823338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
184923338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
185023338.1f228: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcr100.dll
185123338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
185223338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
185323338.1f228: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcp100.dll
185423338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
185523338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
185623338.1f228: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
185723338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
185823338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
185923338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
186023338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
186123338.1f228: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\gdi32.dll
186223338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
186323338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume1\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
186423338.1f228: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\opengl32.dll
186523338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
186623338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
186723338.1f228: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ole32.dll
186823338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
186923338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
187023338.1f228: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcr100.dll
187123338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
187223338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
187323338.1f228: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcp100.dll
187423338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
187523338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume1\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
187623338.1f228: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\shell32.dll
187723338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
187823338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
187923338.1f228: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
188023338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
188123338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
188223338.1f228: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
188323338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
188423338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
188523338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
188623338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
188723338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
188823338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
188923338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
189023338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
189123338.1f228: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
189223338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
189323338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
189423338.1f228: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
189523338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
189623338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
189723338.1f228: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll
189823338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
189923338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
190023338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
190123338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
190223338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
190323338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
190423338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
190523338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
190623338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
190723338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume1\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
190823338.1f228: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\shlwapi.dll
190923338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
191023338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
191123338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ebeb1:<flags> [calling]
191223338.1f228: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll
191323338.1f228: supR3HardenedDllNotificationCallback: load 000007fee1110000 LB 0x001c8000 C:\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll [fFlags=0x0]
191423338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll
191523338.1f228: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\opengl32.dll
191623338.1f228: supR3HardenedDllNotificationCallback: load 000007fee2700000 LB 0x0011d000 C:\Windows\system32\OPENGL32.dll [fFlags=0x0]
191723338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\opengl32.dll
191823338.1f228: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\glu32.dll
191923338.1f228: supR3HardenedDllNotificationCallback: load 000007fef0330000 LB 0x0002d000 C:\Windows\system32\GLU32.dll [fFlags=0x0]
192023338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\glu32.dll
192123338.1f228: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ddraw.dll
192223338.1f228: supR3HardenedDllNotificationCallback: load 000007feee420000 LB 0x000f1000 C:\Windows\system32\DDRAW.dll [fFlags=0x0]
192323338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ddraw.dll
192423338.1f228: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\dciman32.dll [avoiding WinVerifyTrust]
192523338.1f228: supR3HardenedDllNotificationCallback: load 000007feee410000 LB 0x00008000 C:\Windows\system32\DCIMAN32.dll [fFlags=0x0]
192623338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\dciman32.dll [avoiding WinVerifyTrust]
192723338.1f228: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\dwmapi.dll [avoiding WinVerifyTrust]
192823338.1f228: supR3HardenedDllNotificationCallback: load 000007fefca60000 LB 0x00018000 C:\Windows\system32\dwmapi.dll [fFlags=0x0]
192923338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\dwmapi.dll [avoiding WinVerifyTrust]
193023338.1f228: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\UICommon.dll
193123338.1f228: supR3HardenedDllNotificationCallback: load 000007feb3090000 LB 0x02614000 C:\Program Files\Oracle\VirtualBox\UICommon.dll [fFlags=0x0]
193223338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\UICommon.dll
193323338.1f228: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
193423338.1f228: supR3HardenedDllNotificationCallback: load 00000000543c0000 LB 0x00565000 C:\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [fFlags=0x0]
193523338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
193623338.1f228: supR3HardenedDllNotificationCallback: load 000007fefd370000 LB 0x00d8b000 C:\Windows\system32\SHELL32.dll [fFlags=0x0]
193723338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\shell32.dll
193823338.1f228: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\mpr.dll
193923338.1f228: supR3HardenedDllNotificationCallback: load 000007fef9660000 LB 0x00018000 C:\Windows\system32\MPR.dll [fFlags=0x0]
194023338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\mpr.dll
194123338.1f228: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
194223338.1f228: supR3HardenedDllNotificationCallback: load 000007fee0830000 LB 0x005f7000 C:\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll [fFlags=0x0]
194323338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
194423338.1f228: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll
194523338.1f228: supR3HardenedDllNotificationCallback: load 00000000645a0000 LB 0x00561000 C:\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll [fFlags=0x0]
194623338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll
194723338.1f228: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll
194823338.1f228: supR3HardenedDllNotificationCallback: load 0000000056fa0000 LB 0x00054000 C:\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll [fFlags=0x0]
194923338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll
195023338.1f228: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\winmm.dll
195123338.1f228: supR3HardenedDllNotificationCallback: load 000007fefa3f0000 LB 0x0003b000 C:\Windows\system32\WINMM.dll [fFlags=0x0]
195223338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\winmm.dll
195323338.1f228: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume1\Windows\System32\dciman32.dll'.
195423338.1f228: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume1\Windows\System32\dciman32.dll' [rescheduled]
195523338.1f228: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume1\Windows\System32\dwmapi.dll'.
195623338.1f228: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume1\Windows\System32\dwmapi.dll' [rescheduled]
195723338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe660000 'C:\Windows\system32\ADVAPI32.DLL'
195823338.1f228: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume1\Windows\System32\dciman32.dll'.
195923338.1f228: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume1\Windows\System32\dciman32.dll' [rescheduled]
196023338.1f228: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume1\Windows\System32\dwmapi.dll'.
196123338.1f228: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume1\Windows\System32\dwmapi.dll' [rescheduled]
196223338.1f228: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume1\Windows\System32\dciman32.dll'.
196323338.1f228: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume1\Windows\System32\dciman32.dll' [rescheduled]
196423338.1f228: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume1\Windows\System32\dwmapi.dll'.
196523338.1f228: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume1\Windows\System32\dwmapi.dll' [rescheduled]
196623338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\cryptbase.dll
196723338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptbase.dll (Input=cryptbase.dll, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
196823338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcdd0000 'C:\Windows\system32\cryptbase.dll'
196923338.1f228: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume1\Windows\System32\dciman32.dll'.
197023338.1f228: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume1\Windows\System32\dciman32.dll' [rescheduled]
197123338.1f228: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume1\Windows\System32\dwmapi.dll'.
197223338.1f228: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume1\Windows\System32\dwmapi.dll' [rescheduled]
197323338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee1110000 'C:\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll'
197423338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004e4 pwszName=\Device\HarddiskVolume1\Windows\System32\dciman32.dll
197523338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
197623338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
197723338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=06E87E8BC22B9124778A2BDA6472CAFE3F12B2CA
197823338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd0b0000 'C:\Windows\system32\crypt32.dll'
197923338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_822_for_KB4534310~31bf3856ad364e35~amd64~~6.1.1.9.cat'; file='\Device\HarddiskVolume1\Windows\System32\dciman32.dll'
198023338.1f228: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
198123338.1f228: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\dciman32.dll'
198223338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004f4 pwszName=\Device\HarddiskVolume1\Windows\System32\dwmapi.dll
198323338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
198423338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
198523338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F3F3D4867E9140896E0742D7EE8AE1D01FE85ECE
198623338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3078667~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume1\Windows\System32\dwmapi.dll'
198723338.1f228: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
198823338.1f228: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\dwmapi.dll'
198923338.1f228: SUPR3HardenedMain: Calling TrustedMain (000007fee11116c0)...
199023338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ole32.dll
199123338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ole32.dll (Input=ole32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ed761:<flags> [calling]
199223338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe2b0000 'C:\Windows\system32\ole32.dll'
199323338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe660000 'C:\Windows\system32\ADVAPI32.dll'
199423338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\profapi.dll
199523338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\profapi.dll (Input=profapi.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ebe41:<flags> [calling]
199623338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcf70000 'C:\Windows\system32\profapi.dll'
199723338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
199823338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'ole32.dll'.
199923338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
200023338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'imm32.dll'.
200123338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'winmm.dll'.
200223338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
200323338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'shell32.dll'.
200423338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'advapi32.dll'.
200523338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'qt5guivbox.dll'.
200623338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'qt5corevbox.dll'.
200723338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'msvcr100.dll'.
200823338.1f228: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\platforms\qwindows.dll) WinVerifyTrust
200923338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\platforms\qwindows.dll
201023338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
201123338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
201223338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
201323338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
201423338.1f228: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
201523338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
201623338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
201723338.1f228: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
201823338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
201923338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
202023338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
202123338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume1\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
202223338.1f228: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\shell32.dll
202323338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
202423338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume1\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
202523338.1f228: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\oleaut32.dll
202623338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
202723338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume1\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
202823338.1f228: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\winmm.dll
202923338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
203023338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume1\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
203123338.1f228: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\imm32.dll
203223338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
203323338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
203423338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
203523338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
203623338.1f228: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ole32.dll
203723338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
203823338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
203923338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\platforms\qwindows.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ee131:<flags> [calling]
204023338.1f228: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\platforms\qwindows.dll
204123338.1f228: supR3HardenedDllNotificationCallback: load 000007fee21d0000 LB 0x0012e000 C:\Program Files\Oracle\VirtualBox\platforms\qwindows.dll [fFlags=0x0]
204223338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\platforms\qwindows.dll
204323338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee21d0000 'C:\Program Files\Oracle\VirtualBox\platforms\qwindows.dll'
204423338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\cryptbase.dll
204523338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTBASE.dll (Input=CRYPTBASE.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ee061:<flags> [calling]
204623338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcdd0000 'C:\Windows\system32\CRYPTBASE.dll'
204723338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000548 pwszName=\Device\HarddiskVolume1\Windows\System32\uxtheme.dll
204823338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
204923338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
205023338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=936D45CC7026757A151F62882B557DD75D5FCB21
205123338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume1\Windows\System32\uxtheme.dll'
205223338.1f228: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
205323338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
205423338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
205523338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'gdi32.dll'.
205623338.1f228: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\uxtheme.dll) WinVerifyTrust
205723338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\uxtheme.dll
205823338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
205923338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
206023338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
206123338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
206223338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
206323338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
206423338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001edac1:<flags> [calling]
206523338.1f228: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\uxtheme.dll
206623338.1f228: supR3HardenedDllNotificationCallback: load 000007fefc700000 LB 0x00056000 C:\Windows\system32\uxtheme.dll [fFlags=0x0]
206723338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\uxtheme.dll
206823338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc700000 'C:\Windows\system32\uxtheme.dll'
206923338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\uxtheme.dll
207023338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ed501:<flags> [calling]
207123338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc700000 'C:\Windows\system32\uxtheme.dll'
207223338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\uxtheme.dll
207323338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ed271:<flags> [calling]
207423338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc700000 'C:\Windows\system32\uxtheme.dll'
207523338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\uxtheme.dll
207623338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ed271:<flags> [calling]
207723338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc700000 'C:\Windows\system32\uxtheme.dll'
207823338.1f228: \Device\HarddiskVolume1\Program Files (x86)\Dexpot\hooxpot64.dll: Owner is administrators group.
207923338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd0b0000 'C:\Windows\system32\crypt32.dll'
208023338.1f228: supHardenedWinVerifyImageByHandle: -> -23021 (\Device\HarddiskVolume1\Program Files (x86)\Dexpot\hooxpot64.dll) WinVerifyTrust
208123338.1f228: Error (rc=0):
208223338.1f228: supR3HardenedScreenImage/LdrLoadDll: rc=Unknown Status -23021 (0xffffa613) fImage=1 fProtect=0x0 fAccess=0x0 \Device\HarddiskVolume1\Program Files (x86)\Dexpot\hooxpot64.dll: None of the 1 path(s) have a trust anchor.: \Device\HarddiskVolume1\Program Files (x86)\Dexpot\hooxpot64.dll
208323338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files (x86)\Dexpot\hooxpot64.dll
208423338.1f228: Error (rc=0):
208523338.1f228: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\Program Files (x86)\Dexpot\hooxpot64.dll' (C:\Program Files (x86)\Dexpot\hooxpot64.dll): rcNt=0xc0000190
208623338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Program Files (x86)\Dexpot\hooxpot64.dll'
208723338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077320000 'C:\Windows\system32\user32.dll'
208823338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\shell32.dll
208923338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ee371:<flags> [calling]
209023338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd370000 'C:\Windows\system32\shell32.dll'
209123338.1f228: supR3HardenedMonitor_LdrLoadDll: error opening 'C:\Windows\system32\wintab32.dll': 0 (NtPath=\??\C:\Windows\system32\wintab32.dll; Input=C:\Windows\system32\wintab32.dll; rcNtGetDll=0x0
209223338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000034 'C:\Windows\system32\wintab32.dll'
209323338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status -23021 (0xffffa613)) on \Device\HarddiskVolume1\Program Files (x86)\Dexpot\hooxpot64.dll
209423338.1f228: Error (rc=0):
209523338.1f228: supR3HardenedScreenImage/LdrLoadDll: cached rc=Unknown Status -23021 (0xffffa613) fImage=1 fProtect=0x0 fAccess=0x0 cHits=1 \Device\HarddiskVolume1\Program Files (x86)\Dexpot\hooxpot64.dll
209623338.1f228: Error (rc=0):
209723338.1f228: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\Program Files (x86)\Dexpot\hooxpot64.dll' (C:\Program Files (x86)\Dexpot\hooxpot64.dll): rcNt=0xc0000190
209823338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Program Files (x86)\Dexpot\hooxpot64.dll'
209923338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\dwmapi.dll
210023338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\dwmapi.dll (Input=dwmapi.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ed9a1:<flags> [calling]
210123338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefca60000 'C:\Windows\system32\dwmapi.dll'
210223338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\winmm.dll
210323338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\winmm.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ee791:<flags> [calling]
210423338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa3f0000 'C:\Windows\system32\winmm.dll'
210523338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\winmm.dll
210623338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\winmm.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ee791:<flags> [calling]
210723338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa3f0000 'C:\Windows\system32\winmm.dll'
210823338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status -23021 (0xffffa613)) on \Device\HarddiskVolume1\Program Files (x86)\Dexpot\hooxpot64.dll
210923338.1f228: Error (rc=0):
211023338.1f228: supR3HardenedScreenImage/LdrLoadDll: cached rc=Unknown Status -23021 (0xffffa613) fImage=1 fProtect=0x0 fAccess=0x0 cHits=2 \Device\HarddiskVolume1\Program Files (x86)\Dexpot\hooxpot64.dll
211123338.1f228: Error (rc=0):
211223338.1f228: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\Program Files (x86)\Dexpot\hooxpot64.dll' (C:\Program Files (x86)\Dexpot\hooxpot64.dll): rcNt=0xc0000190
211323338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Program Files (x86)\Dexpot\hooxpot64.dll'
211423338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\shell32.dll
211523338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001eea71:<flags> [calling]
211623338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd370000 'C:\Windows\system32\shell32.dll'
211723338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\uxtheme.dll
211823338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001eea41:<flags> [calling]
211923338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc700000 'C:\Windows\system32\uxtheme.dll'
212023338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe660000 'C:\Windows\system32\advapi32.dll'
212123338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\userenv.dll
212223338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\userenv.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ee9a1:<flags> [calling]
212323338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd220000 'C:\Windows\system32\userenv.dll'
212423338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\kernel32.dll
212523338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (Input=kernel32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001eea81:<flags> [calling]
212623338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077200000 'C:\Windows\system32\kernel32.dll'
212723338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe660000 'C:\Windows\system32\ADVAPI32.dll'
212823338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000570 pwszName=\Device\HarddiskVolume1\Windows\System32\clbcatq.dll
212923338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
213023338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
213123338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B01469787CE9D8C6FEE98FB207652B88B8494526
213223338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume1\Windows\System32\clbcatq.dll'
213323338.1f228: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
213423338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
213523338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'ole32.dll'.
213623338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
213723338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
213823338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
213923338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'rpcrt4.dll'.
214023338.1f228: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\clbcatq.dll) WinVerifyTrust
214123338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\clbcatq.dll
214223338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
214323338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
214423338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
214523338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume1\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
214623338.1f228: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\oleaut32.dll
214723338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
214823338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
214923338.1f228: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\advapi32.dll
215023338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
215123338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
215223338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
215323338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
215423338.1f228: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ole32.dll
215523338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
215623338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
215723338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CLBCatQ.DLL (Input=CLBCatQ.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ec7a1:<flags> [calling]
215823338.1f228: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\clbcatq.dll
215923338.1f228: supR3HardenedDllNotificationCallback: load 000007fefefe0000 LB 0x00099000 C:\Windows\system32\CLBCatQ.DLL [fFlags=0x0]
216023338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\clbcatq.dll
216123338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefefe0000 'C:\Windows\system32\CLBCatQ.DLL'
216223338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\cryptsp.dll
216323338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTSP.dll (Input=CRYPTSP.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001eb5f1:<flags> [calling]
216423338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc410000 'C:\Windows\system32\CRYPTSP.dll'
216523338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000005ac pwszName=\Device\HarddiskVolume1\Windows\System32\RpcRtRemote.dll
216623338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
216723338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
216823338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=DFC4A7C7E103D324218E6EF5D219B953746D6EC1
216923338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\RpcRtRemote.dll'
217023338.1f228: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
217123338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'rpcrt4.dll'.
217223338.1f228: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\RpcRtRemote.dll) WinVerifyTrust
217323338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\RpcRtRemote.dll
217423338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
217523338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
217623338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\RpcRtRemote.dll (Input=RpcRtRemote.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001eb1b1:<flags> [calling]
217723338.1f228: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\RpcRtRemote.dll
217823338.1f228: supR3HardenedDllNotificationCallback: load 000007fefce80000 LB 0x00014000 C:\Windows\system32\RpcRtRemote.dll [fFlags=0x0]
217923338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\RpcRtRemote.dll
218023338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefce80000 'C:\Windows\system32\RpcRtRemote.dll'
218123338.20418: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
218223338.20418: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
218323338.20418: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
218423338.20418: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
218523338.20418: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ole32.dll'.
218623338.20418: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'oleaut32.dll'.
218723338.20418: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxC.dll) WinVerifyTrust
218823338.20418: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxC.dll
218923338.20418: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
219023338.20418: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume1\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
219123338.20418: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\oleaut32.dll
219223338.20418: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
219323338.20418: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
219423338.20418: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
219523338.20418: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
219623338.20418: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
219723338.20418: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
219823338.20418: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
219923338.20418: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
220023338.20418: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcp100.dll
220123338.20418: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
220223338.20418: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
220323338.20418: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxC.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000052dea31:<flags> [calling]
220423338.20418: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxC.dll
220523338.20418: supR3HardenedDllNotificationCallback: load 000007fee0480000 LB 0x003b0000 C:\Program Files\Oracle\VirtualBox\VBoxC.dll [fFlags=0x0]
220623338.20418: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxC.dll
220723338.20418: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee0480000 'C:\Program Files\Oracle\VirtualBox\VBoxC.dll'
220823338.20418: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
220923338.20418: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
221023338.20418: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
221123338.20418: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'shlwapi.dll'.
221223338.20418: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ole32.dll'.
221323338.20418: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'oleaut32.dll'.
221423338.20418: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
221523338.20418: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll) WinVerifyTrust
221623338.20418: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll
221723338.20418: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
221823338.20418: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
221923338.20418: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\rpcrt4.dll
222023338.20418: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
222123338.20418: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume1\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
222223338.20418: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\oleaut32.dll
222323338.20418: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
222423338.20418: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
222523338.20418: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
222623338.20418: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume1\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
222723338.20418: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\shlwapi.dll
222823338.20418: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
222923338.20418: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
223023338.20418: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
223123338.20418: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
223223338.20418: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
223323338.20418: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
223423338.20418: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000052dd461:<flags> [calling]
223523338.20418: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll
223623338.20418: supR3HardenedDllNotificationCallback: load 000007fee20e0000 LB 0x000ed000 C:\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll [fFlags=0x0]
223723338.20418: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll
223823338.20418: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee20e0000 'C:\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll'
223923338.20418: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\oleaut32.dll
224023338.20418: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\oleaut32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000052dd2f1:<flags> [calling]
224123338.20418: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe7c0000 'C:\Windows\system32\oleaut32.dll'
224223338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe660000 'C:\Windows\system32\ADVAPI32.dll'
224323338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefed50000 'C:\Windows\system32\gdi32.dll'
224423338.1dd68: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
224523338.1dd68: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
224623338.1dd68: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMainVM.dll) WinVerifyTrust
224723338.1dd68: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMainVM.dll
224823338.1dd68: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
224923338.1dd68: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
225023338.1dd68: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
225123338.1dd68: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
225223338.1dd68: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMainVM.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000004e0a431:<flags> [calling]
225323338.1dd68: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMainVM.dll
225423338.1dd68: supR3HardenedDllNotificationCallback: load 000007fef4cd0000 LB 0x0000e000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMainVM.DLL [fFlags=0x0]
225523338.1dd68: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMainVM.dll
225623338.1dd68: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef4cd0000 'C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMainVM.DLL'
225723338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\shell32.dll
225823338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001ea4f1:<flags> [calling]
225923338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd370000 'C:\Windows\system32\shell32.dll'
226023338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
226123338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
226223338.1f228: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxVMM.dll) WinVerifyTrust
226323338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxVMM.dll
226423338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
226523338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
226623338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
226723338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
226823338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001e8d01:<flags> [calling]
226923338.1f228: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxVMM.dll
227023338.1f228: supR3HardenedDllNotificationCallback: load 000007fee0100000 LB 0x0037d000 C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL [fFlags=0x0]
227123338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxVMM.dll
227223338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee0100000 'C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL'
227323338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status -23021 (0xffffa613)) on \Device\HarddiskVolume1\Program Files (x86)\Dexpot\hooxpot64.dll
227423338.1f228: Error (rc=0):
227523338.1f228: supR3HardenedScreenImage/LdrLoadDll: cached rc=Unknown Status -23021 (0xffffa613) fImage=1 fProtect=0x0 fAccess=0x0 cHits=3 \Device\HarddiskVolume1\Program Files (x86)\Dexpot\hooxpot64.dll
227623338.1f228: Error (rc=0):
227723338.1f228: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\Program Files (x86)\Dexpot\hooxpot64.dll' (C:\Program Files (x86)\Dexpot\hooxpot64.dll): rcNt=0xc0000190
227823338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Program Files (x86)\Dexpot\hooxpot64.dll'
227923338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status -23021 (0xffffa613)) on \Device\HarddiskVolume1\Program Files (x86)\Dexpot\hooxpot64.dll
228023338.1f228: Error (rc=0):
228123338.1f228: supR3HardenedScreenImage/LdrLoadDll: cached rc=Unknown Status -23021 (0xffffa613) fImage=1 fProtect=0x0 fAccess=0x0 cHits=4 \Device\HarddiskVolume1\Program Files (x86)\Dexpot\hooxpot64.dll
228223338.1f228: Error (rc=0):
228323338.1f228: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\Program Files (x86)\Dexpot\hooxpot64.dll' (C:\Program Files (x86)\Dexpot\hooxpot64.dll): rcNt=0xc0000190
228423338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Program Files (x86)\Dexpot\hooxpot64.dll'
228523338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status -23021 (0xffffa613)) on \Device\HarddiskVolume1\Program Files (x86)\Dexpot\hooxpot64.dll
228623338.1f228: Error (rc=0):
228723338.1f228: supR3HardenedScreenImage/LdrLoadDll: cached rc=Unknown Status -23021 (0xffffa613) fImage=1 fProtect=0x0 fAccess=0x0 cHits=5 \Device\HarddiskVolume1\Program Files (x86)\Dexpot\hooxpot64.dll
228823338.1f228: Error (rc=0):
228923338.1f228: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\Program Files (x86)\Dexpot\hooxpot64.dll' (C:\Program Files (x86)\Dexpot\hooxpot64.dll): rcNt=0xc0000190
229023338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Program Files (x86)\Dexpot\hooxpot64.dll'
229123338.1f228: supR3HardNtViCallWinVerifyTrust: WinVerifyTrust failed with 0x800b010c (CERT_E_REVOKED) on '\Device\HarddiskVolume1\Program Files\ThinkPad\Bluetooth Software\BtMmHook.dll'
229223338.1f228: supHardenedWinVerifyImageByHandle: -> -22919 (\Device\HarddiskVolume1\Program Files\ThinkPad\Bluetooth Software\BtMmHook.dll) WinVerifyTrust
229323338.1f228: Error (rc=0):
229423338.1f228: supR3HardenedScreenImage/LdrLoadDll: rc=Unknown Status -22919 (0xffffa679) fImage=1 fProtect=0x0 fAccess=0x0 \Device\HarddiskVolume1\Program Files\ThinkPad\Bluetooth Software\BtMmHook.dll: WinVerifyTrust failed with hrc=CERT_E_REVOKED on '\Device\HarddiskVolume1\Program Files\ThinkPad\Bluetooth Software\BtMmHook.dll'
229523338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\ThinkPad\Bluetooth Software\BtMmHook.dll
229623338.1f228: Error (rc=0):
229723338.1f228: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\Program Files\ThinkPad\Bluetooth Software\btmmhook.dll' (C:\Program Files\ThinkPad\Bluetooth Software\btmmhook.dll): rcNt=0xc0000190
229823338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Program Files\ThinkPad\Bluetooth Software\btmmhook.dll'
229923338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status -23021 (0xffffa613)) on \Device\HarddiskVolume1\Program Files (x86)\Dexpot\hooxpot64.dll
230023338.1f228: Error (rc=0):
230123338.1f228: supR3HardenedScreenImage/LdrLoadDll: cached rc=Unknown Status -23021 (0xffffa613) fImage=1 fProtect=0x0 fAccess=0x0 cHits=6 \Device\HarddiskVolume1\Program Files (x86)\Dexpot\hooxpot64.dll
230223338.1f228: Error (rc=0):
230323338.1f228: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\Program Files (x86)\Dexpot\hooxpot64.dll' (C:\Program Files (x86)\Dexpot\hooxpot64.dll): rcNt=0xc0000190
230423338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Program Files (x86)\Dexpot\hooxpot64.dll'
230523338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status -23021 (0xffffa613)) on \Device\HarddiskVolume1\Program Files (x86)\Dexpot\hooxpot64.dll
230623338.1f228: Error (rc=0):
230723338.1f228: supR3HardenedScreenImage/LdrLoadDll: cached rc=Unknown Status -23021 (0xffffa613) fImage=1 fProtect=0x0 fAccess=0x0 cHits=7 \Device\HarddiskVolume1\Program Files (x86)\Dexpot\hooxpot64.dll
230823338.1f228: Error (rc=0):
230923338.1f228: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\Program Files (x86)\Dexpot\hooxpot64.dll' (C:\Program Files (x86)\Dexpot\hooxpot64.dll): rcNt=0xc0000190
231023338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Program Files (x86)\Dexpot\hooxpot64.dll'
231123338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status -23021 (0xffffa613)) on \Device\HarddiskVolume1\Program Files (x86)\Dexpot\hooxpot64.dll
231223338.1f228: Error (rc=0):
231323338.1f228: supR3HardenedScreenImage/LdrLoadDll: cached rc=Unknown Status -23021 (0xffffa613) fImage=1 fProtect=0x0 fAccess=0x0 cHits=8 \Device\HarddiskVolume1\Program Files (x86)\Dexpot\hooxpot64.dll
231423338.1f228: Error (rc=0):
231523338.1f228: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\Program Files (x86)\Dexpot\hooxpot64.dll' (C:\Program Files (x86)\Dexpot\hooxpot64.dll): rcNt=0xc0000190
231623338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Program Files (x86)\Dexpot\hooxpot64.dll'
231723338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status -22919 (0xffffa679)) on \Device\HarddiskVolume1\Program Files\ThinkPad\Bluetooth Software\BtMmHook.dll
231823338.1f228: Error (rc=0):
231923338.1f228: supR3HardenedScreenImage/LdrLoadDll: cached rc=Unknown Status -22919 (0xffffa679) fImage=1 fProtect=0x0 fAccess=0x0 cHits=1 \Device\HarddiskVolume1\Program Files\ThinkPad\Bluetooth Software\BtMmHook.dll
232023338.1f228: Error (rc=0):
232123338.1f228: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\Program Files\ThinkPad\Bluetooth Software\btmmhook.dll' (C:\Program Files\ThinkPad\Bluetooth Software\btmmhook.dll): rcNt=0xc0000190
232223338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Program Files\ThinkPad\Bluetooth Software\btmmhook.dll'
232323338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status -22919 (0xffffa679)) on \Device\HarddiskVolume1\Program Files\ThinkPad\Bluetooth Software\BtMmHook.dll
232423338.1f228: Error (rc=0):
232523338.1f228: supR3HardenedScreenImage/LdrLoadDll: cached rc=Unknown Status -22919 (0xffffa679) fImage=1 fProtect=0x0 fAccess=0x0 cHits=2 \Device\HarddiskVolume1\Program Files\ThinkPad\Bluetooth Software\BtMmHook.dll
232623338.1f228: Error (rc=0):
232723338.1f228: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\Program Files\ThinkPad\Bluetooth Software\btmmhook.dll' (C:\Program Files\ThinkPad\Bluetooth Software\btmmhook.dll): rcNt=0xc0000190
232823338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Program Files\ThinkPad\Bluetooth Software\btmmhook.dll'
232923338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe660000 'C:\Windows\system32\ADVAPI32.dll'
233023338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status -22919 (0xffffa679)) on \Device\HarddiskVolume1\Program Files\ThinkPad\Bluetooth Software\BtMmHook.dll
233123338.1f228: Error (rc=0):
233223338.1f228: supR3HardenedScreenImage/LdrLoadDll: cached rc=Unknown Status -22919 (0xffffa679) fImage=1 fProtect=0x0 fAccess=0x0 cHits=3 \Device\HarddiskVolume1\Program Files\ThinkPad\Bluetooth Software\BtMmHook.dll
233323338.1f228: Error (rc=0):
233423338.1f228: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\Program Files\ThinkPad\Bluetooth Software\btmmhook.dll' (C:\Program Files\ThinkPad\Bluetooth Software\btmmhook.dll): rcNt=0xc0000190
233523338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Program Files\ThinkPad\Bluetooth Software\btmmhook.dll'
233623338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status -23021 (0xffffa613)) on \Device\HarddiskVolume1\Program Files (x86)\Dexpot\hooxpot64.dll
233723338.1f228: Error (rc=0):
233823338.1f228: supR3HardenedScreenImage/LdrLoadDll: cached rc=Unknown Status -23021 (0xffffa613) fImage=1 fProtect=0x0 fAccess=0x0 cHits=16 \Device\HarddiskVolume1\Program Files (x86)\Dexpot\hooxpot64.dll
233923338.1f228: Error (rc=0):
234023338.1f228: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\Program Files (x86)\Dexpot\hooxpot64.dll' (C:\Program Files (x86)\Dexpot\hooxpot64.dll): rcNt=0xc0000190
234123338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Program Files (x86)\Dexpot\hooxpot64.dll'
234223338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe2b0000 'C:\Windows\system32\ole32.dll'
234323338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe2b0000 'C:\Windows\system32\ole32.dll'
234423338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe7c0000 'C:\Windows\system32\OLEAUT32.dll'
234523338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000008bc pwszName=\Device\HarddiskVolume1\Windows\System32\wbem\wbemprox.dll
234623338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
234723338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
234823338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=41D7AA7A9ECA84ABF6801478BA3134174B21C472
234923338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\wbem\wbemprox.dll'
235023338.1f228: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
235123338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
235223338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'wbemcomn.dll'.
235323338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
235423338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
235523338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ole32.dll'.
235623338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'ws2_32.dll'.
235723338.1f228: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\wbem\wbemprox.dll) WinVerifyTrust
235823338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\wbem\wbemprox.dll
235923338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
236023338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
236123338.1f228: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ws2_32.dll
236223338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
236323338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
236423338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
236523338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume1\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
236623338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
236723338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
236823338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wbemcomn.dll'...
236923338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'wbemcomn.dll' -> '\Device\HarddiskVolume1\Windows\System32\wbemcomn.dll' [rcNtRedir=0xc0150008]
237023338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000008c0 pwszName=\Device\HarddiskVolume1\Windows\System32\wbemcomn.dll
237123338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
237223338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
237323338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=03D0A77E5195AA70198FDE6C2FAC2C76FF200674
237423338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\wbemcomn.dll'
237523338.1f228: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
237623338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
237723338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'oleaut32.dll'.
237823338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'ole32.dll'.
237923338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
238023338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ws2_32.dll'.
238123338.1f228: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\wbemcomn.dll) WinVerifyTrust
238223338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\wbemcomn.dll
238323338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
238423338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
238523338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
238623338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
238723338.1f228: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ws2_32.dll
238823338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
238923338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
239023338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
239123338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
239223338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
239323338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume1\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
239423338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
239523338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
239623338.1f228: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\msvcrt.dll
239723338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wbem\wbemprox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001e6701:<flags> [calling]
239823338.1f228: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\wbem\wbemprox.dll
239923338.1f228: supR3HardenedDllNotificationCallback: load 000007fef81f0000 LB 0x0000f000 C:\Windows\system32\wbem\wbemprox.dll [fFlags=0x0]
240023338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\wbem\wbemprox.dll
240123338.1f228: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\wbemcomn.dll
240223338.1f228: supR3HardenedDllNotificationCallback: load 000007fef8410000 LB 0x00086000 C:\Windows\system32\wbemcomn.dll [fFlags=0x0]
240323338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\wbemcomn.dll
240423338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef81f0000 'C:\Windows\system32\wbem\wbemprox.dll'
240523338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000008e4 pwszName=\Device\HarddiskVolume1\Windows\System32\wbem\wbemsvc.dll
240623338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
240723338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
240823338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=83AB88529BF28CFF670EA617E0B9C376CFE28B0F
240923338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\wbem\wbemsvc.dll'
241023338.1f228: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
241123338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
241223338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'rpcrt4.dll'.
241323338.1f228: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\wbem\wbemsvc.dll) WinVerifyTrust
241423338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\wbem\wbemsvc.dll
241523338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
241623338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
241723338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
241823338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
241923338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wbem\wbemsvc.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001e6301:<flags> [calling]
242023338.1f228: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\wbem\wbemsvc.dll
242123338.1f228: supR3HardenedDllNotificationCallback: load 000007fef7ce0000 LB 0x00014000 C:\Windows\system32\wbem\wbemsvc.dll [fFlags=0x0]
242223338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\wbem\wbemsvc.dll
242323338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef7ce0000 'C:\Windows\system32\wbem\wbemsvc.dll'
242423338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000008e8 pwszName=\Device\HarddiskVolume1\Windows\System32\wbem\fastprox.dll
242523338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
242623338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
242723338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=391AD7580DBA8EA6A4190F5A010E834B8C320D79
242823338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume1\Windows\System32\wbem\fastprox.dll'
242923338.1f228: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
243023338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
243123338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'wbemcomn.dll'.
243223338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
243323338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'oleaut32.dll'.
243423338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ole32.dll'.
243523338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ntdsapi.dll'.
243623338.1f228: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\wbem\fastprox.dll) WinVerifyTrust
243723338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\wbem\fastprox.dll
243823338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntdsapi.dll'...
243923338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntdsapi.dll' -> '\Device\HarddiskVolume1\Windows\System32\ntdsapi.dll' [rcNtRedir=0xc0150008]
244023338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000008c8 pwszName=\Device\HarddiskVolume1\Windows\System32\ntdsapi.dll
244123338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
244223338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
244323338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=67C74E045820FCAB3FC8AD5C180928A20C1F11CE
244423338.1f228: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume1\Windows\System32\ntdsapi.dll'
244523338.1f228: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
244623338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
244723338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'rpcrt4.dll'.
244823338.1f228: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'ws2_32.dll'.
244923338.1f228: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\ntdsapi.dll) WinVerifyTrust
245023338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\ntdsapi.dll
245123338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
245223338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
245323338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
245423338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume1\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
245523338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
245623338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
245723338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wbemcomn.dll'...
245823338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'wbemcomn.dll' -> '\Device\HarddiskVolume1\Windows\System32\wbemcomn.dll' [rcNtRedir=0xc0150008]
245923338.1f228: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\wbemcomn.dll
246023338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
246123338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
246223338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
246323338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
246423338.1f228: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ws2_32.dll
246523338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
246623338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
246723338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
246823338.1f228: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
246923338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wbem\fastprox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001e6361:<flags> [calling]
247023338.1f228: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\wbem\fastprox.dll
247123338.1f228: supR3HardenedDllNotificationCallback: load 000007fef82c0000 LB 0x000e2000 C:\Windows\system32\wbem\fastprox.dll [fFlags=0x0]
247223338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\wbem\fastprox.dll
247323338.1f228: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ntdsapi.dll
247423338.1f228: supR3HardenedDllNotificationCallback: load 000007fef8250000 LB 0x00027000 C:\Windows\system32\NTDSAPI.dll [fFlags=0x0]
247523338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ntdsapi.dll
247623338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef82c0000 'C:\Windows\system32\wbem\fastprox.dll'
247723338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe7c0000 'C:\Windows\system32\OLEAUT32.dll'
247823338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe660000 'C:\Windows\system32\ADVAPI32.dll'
247923338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status -22919 (0xffffa679)) on \Device\HarddiskVolume1\Program Files\ThinkPad\Bluetooth Software\BtMmHook.dll
248023338.1f228: Error (rc=0):
248123338.1f228: supR3HardenedScreenImage/LdrLoadDll: cached rc=Unknown Status -22919 (0xffffa679) fImage=1 fProtect=0x0 fAccess=0x0 cHits=4 \Device\HarddiskVolume1\Program Files\ThinkPad\Bluetooth Software\BtMmHook.dll
248223338.1f228: Error (rc=0):
248323338.1f228: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\Program Files\ThinkPad\Bluetooth Software\btmmhook.dll' (C:\Program Files\ThinkPad\Bluetooth Software\btmmhook.dll): rcNt=0xc0000190
248423338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Program Files\ThinkPad\Bluetooth Software\btmmhook.dll'
248523338.7858: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000009d4 pwszName=\Device\HarddiskVolume1\Windows\System32\netcfgx.dll
248623338.7858: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
248723338.7858: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
248823338.7858: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B2E2834BA132AEF0C1091DED23D983BBB0CDB980
248923338.7858: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\netcfgx.dll'
249023338.7858: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
249123338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'shlwapi.dll'.
249223338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
249323338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'gdi32.dll'.
249423338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ole32.dll'.
249523338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'oleaut32.dll'.
249623338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'user32.dll'.
249723338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'nsi.dll'.
249823338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'iphlpapi.dll'.
249923338.7858: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\netcfgx.dll) WinVerifyTrust
250023338.7858: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\netcfgx.dll
250123338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'iphlpapi.dll'...
250223338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'iphlpapi.dll' -> '\Device\HarddiskVolume1\Windows\System32\iphlpapi.dll' [rcNtRedir=0xc0150008]
250323338.7858: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000009e0 pwszName=\Device\HarddiskVolume1\Windows\System32\IPHLPAPI.DLL
250423338.7858: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
250523338.7858: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
250623338.7858: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=3BDC72529DA09BA841BE702C4C902C8AA1242642
250723338.7858: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\IPHLPAPI.DLL'
250823338.7858: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
250923338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
251023338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'nsi.dll'.
251123338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'winnsi.dll'.
251223338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'rpcrt4.dll'.
251323338.7858: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\IPHLPAPI.DLL) WinVerifyTrust
251423338.7858: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\IPHLPAPI.DLL
251523338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
251623338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume1\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
251723338.7858: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\nsi.dll
251823338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
251923338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
252023338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
252123338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume1\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
252223338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
252323338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
252423338.7858: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ole32.dll
252523338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
252623338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
252723338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
252823338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
252923338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
253023338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume1\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
253123338.7858: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\shlwapi.dll
253223338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
253323338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
253423338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winnsi.dll'...
253523338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'winnsi.dll' -> '\Device\HarddiskVolume1\Windows\System32\winnsi.dll' [rcNtRedir=0xc0150008]
253623338.7858: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000009c8 pwszName=\Device\HarddiskVolume1\Windows\System32\winnsi.dll
253723338.7858: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
253823338.7858: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
253923338.7858: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=28DC1A34E4A6B1464B25E6B8BF4EBE1D6A50922D
254023338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd0b0000 'C:\Windows\system32\crypt32.dll'
254123338.7858: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_822_for_KB4534310~31bf3856ad364e35~amd64~~6.1.1.9.cat'; file='\Device\HarddiskVolume1\Windows\System32\winnsi.dll'
254223338.7858: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
254323338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
254423338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'rpcrt4.dll'.
254523338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'nsi.dll'.
254623338.7858: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\winnsi.dll) WinVerifyTrust
254723338.7858: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\winnsi.dll
254823338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
254923338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume1\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
255023338.7858: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\nsi.dll
255123338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
255223338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
255323338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
255423338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume1\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
255523338.7858: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\nsi.dll
255623338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
255723338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
255823338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
255923338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
256023338.7858: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\netcfgx.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000d41bb71:<flags> [calling]
256123338.7858: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\netcfgx.dll
256223338.7858: supR3HardenedDllNotificationCallback: load 000007fef7f80000 LB 0x00084000 C:\Windows\system32\netcfgx.dll [fFlags=0x0]
256323338.7858: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\netcfgx.dll
256423338.7858: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\IPHLPAPI.DLL
256523338.7858: supR3HardenedDllNotificationCallback: load 000007fefa4f0000 LB 0x00027000 C:\Windows\system32\IPHLPAPI.DLL [fFlags=0x0]
256623338.7858: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\IPHLPAPI.DLL
256723338.7858: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\winnsi.dll
256823338.7858: supR3HardenedDllNotificationCallback: load 000007fefa4e0000 LB 0x0000b000 C:\Windows\system32\WINNSI.DLL [fFlags=0x0]
256923338.7858: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\winnsi.dll
257023338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef7f80000 'C:\Windows\system32\netcfgx.dll'
257123338.7858: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\setupapi.dll
257223338.7858: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\SETUPAPI.dll (Input=SETUPAPI.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000d41d371:<flags> [calling]
257323338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe8a0000 'C:\Windows\system32\SETUPAPI.dll'
257423338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
257523338.7858: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume1\Windows\System32\devrtl.dll)
257623338.7858: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\devrtl.dll
257723338.7858: supR3HardenedDllNotificationCallback: load 000007fefb6e0000 LB 0x00012000 C:\Windows\system32\devrtl.DLL [fFlags=0x0]
257823338.7858: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume1\Windows\System32\devrtl.dll [avoiding WinVerifyTrust]
257923338.7858: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000a2c pwszName=\Device\HarddiskVolume1\Windows\System32\devrtl.dll
258023338.7858: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
258123338.7858: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
258223338.7858: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=445E5B0E9F43B5D56A5B9C4BC3369E3D076ACA1A
258323338.7858: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\devrtl.dll'
258423338.7858: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
258523338.7858: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume1\Windows\System32\devrtl.dll'
258623338.7858: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\wintrust.dll
258723338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
258823338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
258923338.7858: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\WINTRUST.dll (Input=WINTRUST.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000d41d111:<flags> [calling]
259023338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd240000 'C:\Windows\system32\WINTRUST.dll'
259123338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\winmm.dll
259223338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\WINMM.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001e5cc1:<flags> [calling]
259323338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa3f0000 'C:\Windows\system32\WINMM.dll'
259423338.20e18: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
259523338.20e18: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
259623338.20e18: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxvmm.dll'.
259723338.20e18: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vboxrt.dll'.
259823338.20e18: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'user32.dll'.
259923338.20e18: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll) WinVerifyTrust
260023338.20e18: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll
260123338.20e18: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
260223338.20e18: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
260323338.20e18: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\user32.dll
260423338.20e18: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
260523338.20e18: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
260623338.20e18: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
260723338.20e18: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
260823338.20e18: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxVMM.dll
260923338.20e18: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
261023338.20e18: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
261123338.20e18: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcp100.dll
261223338.20e18: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
261323338.20e18: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
261423338.20e18: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000e1ddb01:<flags> [calling]
261523338.20e18: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll
261623338.20e18: supR3HardenedDllNotificationCallback: load 000007fef3160000 LB 0x0000f000 C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL [fFlags=0x0]
261723338.20e18: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll
261823338.20e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef3160000 'C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL'
261923338.1e71c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
262023338.1e71c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
262123338.1e71c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
262223338.1e71c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll) WinVerifyTrust
262323338.1e71c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll
262423338.1e71c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
262523338.1e71c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
262623338.1e71c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
262723338.1e71c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
262823338.1e71c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
262923338.1e71c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
263023338.1e71c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcr100.dll
263123338.1e71c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000e35d8b1:<flags> [calling]
263223338.1e71c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll
263323338.1e71c: supR3HardenedDllNotificationCallback: load 000007fef2e20000 LB 0x0000d000 C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL [fFlags=0x0]
263423338.1e71c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll
263523338.1e71c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef2e20000 'C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL'
263623338.7858: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\shell32.dll
263723338.7858: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\Shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000d41a401:<flags> [calling]
263823338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd370000 'C:\Windows\system32\Shell32.dll'
263923338.7858: supR3HardenedIsApiSetDll: '<NULL>' -> true
264023338.7858: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=000000000d419501:<flags> [calling]
264123338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd350000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
264223338.7858: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxVMM.dll
264323338.7858: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000d41b831:<flags> [calling]
264423338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee0100000 'C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL'
264523338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
264623338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
264723338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
264823338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ole32.dll'.
264923338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
265023338.7858: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll) WinVerifyTrust
265123338.7858: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
265223338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
265323338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume1\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
265423338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
265523338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
265623338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
265723338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
265823338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
265923338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
266023338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
266123338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
266223338.7858: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000d41c9e1:<flags> [calling]
266323338.7858: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
266423338.7858: supR3HardenedDllNotificationCallback: load 000007fee33c0000 LB 0x00041000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL [fFlags=0x0]
266523338.7858: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
266623338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee33c0000 'C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL'
266723338.7858: supR3HardenedDllNotificationCallback: Unload 000007fee33c0000 LB 0x00041000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL [flags=0x0]
266823338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
266923338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
267023338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
267123338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vboxddu.dll'.
267223338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'vboxdd2.dll'.
267323338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
267423338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'setupapi.dll'.
267523338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'ws2_32.dll'.
267623338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'ole32.dll'.
267723338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'iphlpapi.dll'.
267823338.7858: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxDD.dll) WinVerifyTrust
267923338.7858: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxDD.dll
268023338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'iphlpapi.dll'...
268123338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'iphlpapi.dll' -> '\Device\HarddiskVolume1\Windows\System32\iphlpapi.dll' [rcNtRedir=0xc0150008]
268223338.7858: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\IPHLPAPI.DLL
268323338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
268423338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
268523338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
268623338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
268723338.7858: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ws2_32.dll
268823338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
268923338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume1\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
269023338.7858: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\setupapi.dll
269123338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
269223338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
269323338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxdd2.dll'...
269423338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxdd2.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\vboxdd2.dll' [rcNtRedir=0xc0150008]
269523338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
269623338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
269723338.7858: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxDD2.dll) WinVerifyTrust
269823338.7858: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxDD2.dll
269923338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxddu.dll'...
270023338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxddu.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\vboxddu.dll' [rcNtRedir=0xc0150008]
270123338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
270223338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
270323338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
270423338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'setupapi.dll'.
270523338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'advapi32.dll'.
270623338.7858: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxDDU.dll) WinVerifyTrust
270723338.7858: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxDDU.dll
270823338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
270923338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
271023338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
271123338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
271223338.7858: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxVMM.dll
271323338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
271423338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
271523338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
271623338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
271723338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
271823338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume1\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
271923338.7858: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\setupapi.dll
272023338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
272123338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
272223338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
272323338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
272423338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
272523338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
272623338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
272723338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
272823338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
272923338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
273023338.7858: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxDD.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000d41dbf1:<flags> [calling]
273123338.7858: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxDD.dll
273223338.7858: supR3HardenedDllNotificationCallback: load 000007fedd8d0000 LB 0x009e4000 C:\Program Files\Oracle\VirtualBox\VBoxDD.DLL [fFlags=0x0]
273323338.7858: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxDD.dll
273423338.7858: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxDDU.dll
273523338.7858: supR3HardenedDllNotificationCallback: load 000007fee2070000 LB 0x00066000 C:\Program Files\Oracle\VirtualBox\VBoxDDU.dll [fFlags=0x0]
273623338.7858: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxDDU.dll
273723338.7858: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxDD2.dll
273823338.7858: supR3HardenedDllNotificationCallback: load 000007fede450000 LB 0x0085c000 C:\Program Files\Oracle\VirtualBox\VBoxDD2.dll [fFlags=0x0]
273923338.7858: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxDD2.dll
274023338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fedd8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxDD.DLL'
274123338.7858: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
274223338.7858: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000d41dbf1:<flags> [calling]
274323338.7858: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
274423338.7858: supR3HardenedDllNotificationCallback: load 000007fee33c0000 LB 0x00041000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL [fFlags=0x0]
274523338.7858: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
274623338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee33c0000 'C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL'
274723338.7858: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxC.dll
274823338.7858: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxC.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000d41dbf1:<flags> [calling]
274923338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee0480000 'C:\Program Files\Oracle\VirtualBox\VBoxC.DLL'
275023338.7858: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxDD2.dll
275123338.7858: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxDD2.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000d41da51:<flags> [calling]
275223338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fede450000 'C:\Program Files\Oracle\VirtualBox\VBoxDD2.DLL'
275323338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
275423338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
275523338.7858: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.dll) WinVerifyTrust
275623338.7858: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.dll
275723338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
275823338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
275923338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
276023338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
276123338.7858: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000d41da51:<flags> [calling]
276223338.7858: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.dll
276323338.7858: supR3HardenedDllNotificationCallback: load 000007fef1300000 LB 0x00018000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.DLL [fFlags=0x0]
276423338.7858: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.dll
276523338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef1300000 'C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.DLL'
276623338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
276723338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
276823338.7858: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.dll) WinVerifyTrust
276923338.7858: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.dll
277023338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
277123338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
277223338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
277323338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
277423338.7858: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000d41da51:<flags> [calling]
277523338.7858: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.dll
277623338.7858: supR3HardenedDllNotificationCallback: load 000007fef0750000 LB 0x00012000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.DLL [fFlags=0x0]
277723338.7858: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.dll
277823338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef0750000 'C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.DLL'
277923338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
278023338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
278123338.7858: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.dll) WinVerifyTrust
278223338.7858: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.dll
278323338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
278423338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
278523338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
278623338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
278723338.7858: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000d41da51:<flags> [calling]
278823338.7858: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.dll
278923338.7858: supR3HardenedDllNotificationCallback: load 000007fef0370000 LB 0x00018000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.DLL [fFlags=0x0]
279023338.7858: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.dll
279123338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef0370000 'C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.DLL'
279223338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
279323338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
279423338.7858: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.dll) WinVerifyTrust
279523338.7858: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.dll
279623338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
279723338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
279823338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
279923338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
280023338.7858: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000d41da51:<flags> [calling]
280123338.7858: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.dll
280223338.7858: supR3HardenedDllNotificationCallback: load 000007fef01b0000 LB 0x00019000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.DLL [fFlags=0x0]
280323338.7858: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.dll
280423338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef01b0000 'C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.DLL'
280523338.23378: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
280623338.23378: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
280723338.23378: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
280823338.23378: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll) WinVerifyTrust
280923338.23378: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll
281023338.23378: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
281123338.23378: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
281223338.23378: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
281323338.23378: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
281423338.23378: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxVMM.dll
281523338.23378: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
281623338.23378: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
281723338.23378: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000097cd8b1:<flags> [calling]
281823338.23378: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll
281923338.23378: supR3HardenedDllNotificationCallback: load 000007feefe20000 LB 0x00014000 C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL [fFlags=0x0]
282023338.23378: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll
282123338.23378: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feefe20000 'C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL'
282223338.21634: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
282323338.21634: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
282423338.21634: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxvmm.dll'.
282523338.21634: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vboxrt.dll'.
282623338.21634: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll) WinVerifyTrust
282723338.21634: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll
282823338.21634: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
282923338.21634: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
283023338.21634: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
283123338.21634: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
283223338.21634: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxVMM.dll
283323338.21634: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
283423338.21634: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
283523338.21634: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
283623338.21634: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
283723338.21634: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000996db61:<flags> [calling]
283823338.21634: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll
283923338.21634: supR3HardenedDllNotificationCallback: load 000007fef12d0000 LB 0x0000c000 C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL [fFlags=0x0]
284023338.21634: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll
284123338.21634: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef12d0000 'C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL'
284223338.1b798: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
284323338.1b798: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
284423338.1b798: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
284523338.1b798: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll) WinVerifyTrust
284623338.1b798: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll
284723338.1b798: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
284823338.1b798: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
284923338.1b798: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
285023338.1b798: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
285123338.1b798: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
285223338.1b798: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
285323338.1b798: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000009c1d7f1:<flags> [calling]
285423338.1b798: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll
285523338.1b798: supR3HardenedDllNotificationCallback: load 000007fef1060000 LB 0x0000d000 C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL [fFlags=0x0]
285623338.1b798: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll
285723338.1b798: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef1060000 'C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL'
285823338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
285923338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
286023338.7858: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.dll) WinVerifyTrust
286123338.7858: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.dll
286223338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
286323338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
286423338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
286523338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
286623338.7858: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000d41f1e1:<flags> [calling]
286723338.7858: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.dll
286823338.7858: supR3HardenedDllNotificationCallback: load 000007fef6210000 LB 0x0000a000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.DLL [fFlags=0x0]
286923338.7858: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.dll
287023338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef6210000 'C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.DLL'
287123338.7858: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000cf4 pwszName=\Device\HarddiskVolume1\Windows\System32\MMDevAPI.dll
287223338.7858: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
287323338.7858: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
287423338.7858: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=704F97298D44B8146C54067788F597E0BF365197
287523338.7858: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume1\Windows\System32\MMDevAPI.dll'
287623338.7858: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
287723338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
287823338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'user32.dll'.
287923338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'rpcrt4.dll'.
288023338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'propsys.dll'.
288123338.7858: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\MMDevAPI.dll) WinVerifyTrust
288223338.7858: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\MMDevAPI.dll
288323338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'propsys.dll'...
288423338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'propsys.dll' -> '\Device\HarddiskVolume1\Windows\System32\propsys.dll' [rcNtRedir=0xc0150008]
288523338.7858: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000cf8 pwszName=\Device\HarddiskVolume1\Windows\System32\propsys.dll
288623338.7858: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
288723338.7858: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
288823338.7858: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=6A1594E841359779EF7EA7EBCF775D89F55388D3
288923338.7858: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\propsys.dll'
289023338.7858: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
289123338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
289223338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ole32.dll'.
289323338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'oleaut32.dll'.
289423338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'user32.dll'.
289523338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'rpcrt4.dll'.
289623338.7858: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\propsys.dll) WinVerifyTrust
289723338.7858: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\propsys.dll
289823338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
289923338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
290023338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
290123338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
290223338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
290323338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
290423338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
290523338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
290623338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
290723338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
290823338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
290923338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume1\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
291023338.7858: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\oleaut32.dll
291123338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
291223338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
291323338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
291423338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
291523338.7858: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\MMDevApi.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000d41d8e1:<flags> [calling]
291623338.7858: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\MMDevAPI.dll
291723338.7858: supR3HardenedDllNotificationCallback: load 000007fefb1f0000 LB 0x0004b000 C:\Windows\System32\MMDevApi.dll [fFlags=0x0]
291823338.7858: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\MMDevAPI.dll
291923338.7858: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\propsys.dll
292023338.7858: supR3HardenedDllNotificationCallback: load 000007fefb0c0000 LB 0x0012c000 C:\Windows\System32\PROPSYS.dll [fFlags=0x0]
292123338.7858: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\propsys.dll
292223338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe660000 'C:\Windows\system32\ADVAPI32.dll'
292323338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefb1f0000 'C:\Windows\System32\MMDevApi.dll'
292423338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe2b0000 'C:\Windows\system32\ole32.dll'
292523338.7858: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\setupapi.dll
292623338.7858: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\SETUPAPI.dll (Input=SETUPAPI.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000d41dc11:<flags> [calling]
292723338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe8a0000 'C:\Windows\system32\SETUPAPI.dll'
292823338.23014: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\cfgmgr32.dll
292923338.23014: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CFGMGR32.dll (Input=CFGMGR32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000a7af401:<flags> [calling]
293023338.23014: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcff0000 'C:\Windows\system32\CFGMGR32.dll'
293123338.7858: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000d48 pwszName=\Device\HarddiskVolume1\Windows\System32\dsound.dll
293223338.7858: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
293323338.7858: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
293423338.7858: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F6C3E3D9F8B48D816E52C31576FFFD4AF86AB813
293523338.7858: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume1\Windows\System32\dsound.dll'
293623338.7858: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
293723338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
293823338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
293923338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
294023338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ole32.dll'.
294123338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'winmm.dll'.
294223338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'powrprof.dll'.
294323338.7858: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\dsound.dll) WinVerifyTrust
294423338.7858: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\dsound.dll
294523338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'powrprof.dll'...
294623338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'powrprof.dll' -> '\Device\HarddiskVolume1\Windows\System32\powrprof.dll' [rcNtRedir=0xc0150008]
294723338.7858: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000d4c pwszName=\Device\HarddiskVolume1\Windows\System32\powrprof.dll
294823338.7858: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
294923338.7858: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
295023338.7858: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=E0B7DE18787DB24DAD3580634869A9A8FF4AB48F
295123338.7858: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume1\Windows\System32\powrprof.dll'
295223338.7858: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
295323338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
295423338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'rpcrt4.dll'.
295523338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'setupapi.dll'.
295623338.7858: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\powrprof.dll) WinVerifyTrust
295723338.7858: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\powrprof.dll
295823338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
295923338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume1\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
296023338.7858: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\winmm.dll
296123338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
296223338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
296323338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
296423338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
296523338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
296623338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
296723338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
296823338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
296923338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
297023338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume1\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
297123338.7858: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\setupapi.dll
297223338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
297323338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
297423338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
297523338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
297623338.7858: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000d41da11:<flags> [calling]
297723338.7858: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\dsound.dll
297823338.7858: supR3HardenedDllNotificationCallback: load 000007fef1780000 LB 0x00088000 C:\Windows\System32\dsound.dll [fFlags=0x0]
297923338.7858: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\dsound.dll
298023338.7858: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\powrprof.dll
298123338.7858: supR3HardenedDllNotificationCallback: load 000007fefb610000 LB 0x0002c000 C:\Windows\System32\POWRPROF.dll [fFlags=0x0]
298223338.7858: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\powrprof.dll
298323338.7858: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\dsound.dll
298423338.7858: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000d41cd51:<flags> [calling]
298523338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef1780000 'C:\Windows\System32\dsound.dll'
298623338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef1780000 'C:\Windows\System32\dsound.dll'
298723338.7858: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\dsound.dll
298823338.7858: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000d41db11:<flags> [calling]
298923338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef1780000 'C:\Windows\system32\dsound.dll'
299023338.7858: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\shlwapi.dll
299123338.7858: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\SHLWAPI.dll (Input=SHLWAPI.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000d41e711:<flags> [calling]
299223338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe740000 'C:\Windows\system32\SHLWAPI.dll'
299323338.7858: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\MMDevAPI.dll
299423338.7858: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\MMDEVAPI.DLL (Input=MMDEVAPI.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000d41e931:<flags> [calling]
299523338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefb1f0000 'C:\Windows\system32\MMDEVAPI.DLL'
299623338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe2b0000 'C:\Windows\system32\ole32.dll'
299723338.6250: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000d80 pwszName=\Device\HarddiskVolume1\Windows\System32\AudioSes.dll
299823338.6250: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
299923338.6250: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
300023338.6250: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=DEC7EC10FABD9D64EA15E6F9C426B2BBBC4DFEED
300123338.6250: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd0b0000 'C:\Windows\system32\crypt32.dll'
300223338.6250: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_242_for_KB4534310~31bf3856ad364e35~amd64~~6.1.1.9.cat'; file='\Device\HarddiskVolume1\Windows\System32\AudioSes.dll'
300323338.6250: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
300423338.6250: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
300523338.6250: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
300623338.6250: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ole32.dll'.
300723338.6250: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
300823338.6250: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
300923338.6250: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
301023338.6250: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'mmdevapi.dll'.
301123338.6250: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\AudioSes.dll) WinVerifyTrust
301223338.6250: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\AudioSes.dll
301323338.6250: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mmdevapi.dll'...
301423338.6250: supR3HardenedWinVerifyCacheProcessImportTodos: 'mmdevapi.dll' -> '\Device\HarddiskVolume1\Windows\System32\mmdevapi.dll' [rcNtRedir=0xc0150008]
301523338.6250: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\MMDevAPI.dll
301623338.6250: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
301723338.6250: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume1\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
301823338.6250: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
301923338.6250: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
302023338.6250: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
302123338.6250: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume1\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
302223338.6250: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
302323338.6250: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
302423338.6250: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
302523338.6250: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
302623338.6250: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
302723338.6250: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
302823338.6250: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\AUDIOSES.DLL (Input=AUDIOSES.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000b74f4e1:<flags> [calling]
302923338.6250: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\AudioSes.dll
303023338.6250: supR3HardenedDllNotificationCallback: load 000007fef8c70000 LB 0x0004f000 C:\Windows\system32\AUDIOSES.DLL [fFlags=0x0]
303123338.6250: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\AudioSes.dll
303223338.6250: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef8c70000 'C:\Windows\system32\AUDIOSES.DLL'
303323338.6250: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe7c0000 'C:\Windows\system32\OLEAUT32.dll'
303423338.7858: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\winmm.dll
303523338.7858: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\winmm.dll (Input=winmm.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000d41e561:<flags> [calling]
303623338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa3f0000 'C:\Windows\system32\winmm.dll'
303723338.7858: supR3HardenedIsApiSetDll: '<NULL>' -> true
303823338.7858: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-Management-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=000000000d41e3c1:<flags> [calling]
303923338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd350000 'API-MS-WIN-Service-Management-L1-1-0.dll'
304023338.7858: supR3HardenedIsApiSetDll: '<NULL>' -> true
304123338.7858: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-winsvc-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=000000000d41e3c1:<flags> [calling]
304223338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd350000 'API-MS-WIN-Service-winsvc-L1-1-0.dll'
304323338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe180000 'C:\Windows\system32\RPCRT4.dll'
304423338.7858: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\MMDevAPI.dll
304523338.7858: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\MMDevAPI.DLL (Input=MMDevAPI.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000d41e421:<flags> [calling]
304623338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefb1f0000 'C:\Windows\system32\MMDevAPI.DLL'
304723338.7858: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000d5c pwszName=\Device\HarddiskVolume1\Windows\System32\wdmaud.drv
304823338.7858: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
304923338.7858: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
305023338.7858: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=4B64306F5558D2DEC53CF11AAF17F02438929FDD
305123338.7858: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume1\Windows\System32\wdmaud.drv'
305223338.7858: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
305323338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
305423338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
305523338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ole32.dll'.
305623338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'user32.dll'.
305723338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'winmm.dll'.
305823338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'ksuser.dll'.
305923338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'mmdevapi.dll'.
306023338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'avrt.dll'.
306123338.7858: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\wdmaud.drv) WinVerifyTrust
306223338.7858: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\wdmaud.drv
306323338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'avrt.dll'...
306423338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'avrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\avrt.dll' [rcNtRedir=0xc0150008]
306523338.7858: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000d88 pwszName=\Device\HarddiskVolume1\Windows\System32\avrt.dll
306623338.7858: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
306723338.7858: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
306823338.7858: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=1362C343929DD08AB918B38DE195D1A11B1D1365
306923338.7858: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume1\Windows\System32\avrt.dll'
307023338.7858: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
307123338.7858: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\avrt.dll) WinVerifyTrust
307223338.7858: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\avrt.dll
307323338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mmdevapi.dll'...
307423338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'mmdevapi.dll' -> '\Device\HarddiskVolume1\Windows\System32\mmdevapi.dll' [rcNtRedir=0xc0150008]
307523338.7858: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\MMDevAPI.dll
307623338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ksuser.dll'...
307723338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'ksuser.dll' -> '\Device\HarddiskVolume1\Windows\System32\ksuser.dll' [rcNtRedir=0xc0150008]
307823338.7858: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000d68 pwszName=\Device\HarddiskVolume1\Windows\System32\ksuser.dll
307923338.7858: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
308023338.7858: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
308123338.7858: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2D99CFB3BFCA1F454FC7109DB98D18923ABBA361
308223338.7858: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_5_for_KB3110329~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume1\Windows\System32\ksuser.dll'
308323338.7858: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
308423338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
308523338.7858: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\ksuser.dll) WinVerifyTrust
308623338.7858: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\ksuser.dll
308723338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
308823338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume1\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
308923338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
309023338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
309123338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
309223338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume1\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
309323338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
309423338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
309523338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
309623338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
309723338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
309823338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
309923338.7858: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000d41df91:<flags> [calling]
310023338.7858: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\wdmaud.drv
310123338.7858: supR3HardenedDllNotificationCallback: load 000007fef37f0000 LB 0x0003b000 C:\Windows\system32\wdmaud.drv [fFlags=0x0]
310223338.7858: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\wdmaud.drv
310323338.7858: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ksuser.dll
310423338.7858: supR3HardenedDllNotificationCallback: load 000000006f2f0000 LB 0x00006000 C:\Windows\system32\ksuser.dll [fFlags=0x0]
310523338.7858: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\ksuser.dll
310623338.7858: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\avrt.dll
310723338.7858: supR3HardenedDllNotificationCallback: load 000007fefb0b0000 LB 0x00009000 C:\Windows\system32\AVRT.dll [fFlags=0x0]
310823338.7858: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\avrt.dll
310923338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef37f0000 'C:\Windows\system32\wdmaud.drv'
311023338.7858: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\wdmaud.drv
311123338.7858: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000d41df91:<flags> [calling]
311223338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef37f0000 'C:\Windows\system32\wdmaud.drv'
311323338.7858: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\wdmaud.drv
311423338.7858: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000d41e141:<flags> [calling]
311523338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef37f0000 'C:\Windows\system32\wdmaud.drv'
311623338.7858: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\wdmaud.drv
311723338.7858: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000d41e141:<flags> [calling]
311823338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef37f0000 'C:\Windows\system32\wdmaud.drv'
311923338.7858: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\wdmaud.drv
312023338.7858: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000d41e141:<flags> [calling]
312123338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef37f0000 'C:\Windows\system32\wdmaud.drv'
312223338.7858: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\wdmaud.drv
312323338.7858: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000d41e141:<flags> [calling]
312423338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef37f0000 'C:\Windows\system32\wdmaud.drv'
312523338.7858: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\wdmaud.drv
312623338.7858: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000d41e141:<flags> [calling]
312723338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef37f0000 'C:\Windows\system32\wdmaud.drv'
312823338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef37f0000 'C:\Windows\system32\wdmaud.drv'
312923338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef37f0000 'C:\Windows\system32\wdmaud.drv'
313023338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef37f0000 'C:\Windows\system32\wdmaud.drv'
313123338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef37f0000 'C:\Windows\system32\wdmaud.drv'
313223338.7858: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000db8 pwszName=\Device\HarddiskVolume1\Windows\System32\msacm32.drv
313323338.7858: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
313423338.7858: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
313523338.7858: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=522563F5384AD4C93CF5CF4EEA899D3267552328
313623338.7858: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume1\Windows\System32\msacm32.drv'
313723338.7858: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
313823338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
313923338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
314023338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'winmm.dll'.
314123338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msacm32.dll'.
314223338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'mmdevapi.dll'.
314323338.7858: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\msacm32.drv) WinVerifyTrust
314423338.7858: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\msacm32.drv
314523338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mmdevapi.dll'...
314623338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'mmdevapi.dll' -> '\Device\HarddiskVolume1\Windows\System32\mmdevapi.dll' [rcNtRedir=0xc0150008]
314723338.7858: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\MMDevAPI.dll
314823338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msacm32.dll'...
314923338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'msacm32.dll' -> '\Device\HarddiskVolume1\Windows\System32\msacm32.dll' [rcNtRedir=0xc0150008]
315023338.7858: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000d94 pwszName=\Device\HarddiskVolume1\Windows\System32\msacm32.dll
315123338.7858: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
315223338.7858: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
315323338.7858: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=DCA0A8AEE81B82C402AA72A300B2C8D2DC17C1DA
315423338.7858: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume1\Windows\System32\msacm32.dll'
315523338.7858: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
315623338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
315723338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
315823338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
315923338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
316023338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'winmm.dll'.
316123338.7858: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\msacm32.dll) WinVerifyTrust
316223338.7858: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\msacm32.dll
316323338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
316423338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume1\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
316523338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
316623338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
316723338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
316823338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
316923338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
317023338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume1\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
317123338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
317223338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
317323338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
317423338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
317523338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
317623338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume1\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
317723338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
317823338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
317923338.7858: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000d41df41:<flags> [calling]
318023338.7858: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\msacm32.drv
318123338.7858: supR3HardenedDllNotificationCallback: load 000007fef61d0000 LB 0x0000a000 C:\Windows\system32\msacm32.drv [fFlags=0x0]
318223338.7858: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\msacm32.drv
318323338.7858: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\msacm32.dll
318423338.7858: supR3HardenedDllNotificationCallback: load 000007fef37d0000 LB 0x00018000 C:\Windows\system32\MSACM32.dll [fFlags=0x0]
318523338.7858: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\msacm32.dll
318623338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef61d0000 'C:\Windows\system32\msacm32.drv'
318723338.7858: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\msacm32.drv
318823338.7858: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000d41d941:<flags> [calling]
318923338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef61d0000 'C:\Windows\system32\msacm32.drv'
319023338.7858: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\msacm32.drv
319123338.7858: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000d41d941:<flags> [calling]
319223338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef61d0000 'C:\Windows\system32\msacm32.drv'
319323338.7858: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\msacm32.drv
319423338.7858: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000d41d941:<flags> [calling]
319523338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef61d0000 'C:\Windows\system32\msacm32.drv'
319623338.7858: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\msacm32.drv
319723338.7858: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000d41d941:<flags> [calling]
319823338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef61d0000 'C:\Windows\system32\msacm32.drv'
319923338.7858: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\msacm32.drv
320023338.7858: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000d41d941:<flags> [calling]
320123338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef61d0000 'C:\Windows\system32\msacm32.drv'
320223338.7858: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\msacm32.drv
320323338.7858: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000d41d941:<flags> [calling]
320423338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef61d0000 'C:\Windows\system32\msacm32.drv'
320523338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef61d0000 'C:\Windows\system32\msacm32.drv'
320623338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef61d0000 'C:\Windows\system32\msacm32.drv'
320723338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef61d0000 'C:\Windows\system32\msacm32.drv'
320823338.7858: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000dbc pwszName=\Device\HarddiskVolume1\Windows\System32\midimap.dll
320923338.7858: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000957000
321023338.7858: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000957000
321123338.7858: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=43116C5C719A4751DA70B12932084D73D7AACEA3
321223338.7858: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume1\Windows\System32\midimap.dll'
321323338.7858: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
321423338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
321523338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
321623338.7858: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'winmm.dll'.
321723338.7858: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Windows\System32\midimap.dll) WinVerifyTrust
321823338.7858: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Windows\System32\midimap.dll
321923338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
322023338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume1\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
322123338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
322223338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume1\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
322323338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
322423338.7858: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume1\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
322523338.7858: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000d41df41:<flags> [calling]
322623338.7858: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\midimap.dll
322723338.7858: supR3HardenedDllNotificationCallback: load 000007fef37c0000 LB 0x00009000 C:\Windows\system32\midimap.dll [fFlags=0x0]
322823338.7858: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\midimap.dll
322923338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef37c0000 'C:\Windows\system32\midimap.dll'
323023338.7858: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\midimap.dll
323123338.7858: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000d41d911:<flags> [calling]
323223338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef37c0000 'C:\Windows\system32\midimap.dll'
323323338.7858: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\midimap.dll
323423338.7858: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000d41d911:<flags> [calling]
323523338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef37c0000 'C:\Windows\system32\midimap.dll'
323623338.7858: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\midimap.dll
323723338.7858: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000d41df41:<flags> [calling]
323823338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef37c0000 'C:\Windows\system32\midimap.dll'
323923338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa3f0000 'C:\Windows\system32\winmm.dll'
324023338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa3f0000 'C:\Windows\system32\winmm.dll'
324123338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa3f0000 'C:\Windows\system32\winmm.dll'
324223338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe2b0000 'C:\Windows\system32\ole32.dll'
324323338.7858: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\winmm.dll
324423338.7858: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\winmm.dll (Input=winmm.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000d41e561:<flags> [calling]
324523338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa3f0000 'C:\Windows\system32\winmm.dll'
324623338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa3f0000 'C:\Windows\system32\winmm.dll'
324723338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa3f0000 'C:\Windows\system32\winmm.dll'
324823338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa3f0000 'C:\Windows\system32\winmm.dll'
324923338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa3f0000 'C:\Windows\system32\winmm.dll'
325023338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa3f0000 'C:\Windows\system32\winmm.dll'
325123338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa3f0000 'C:\Windows\system32\winmm.dll'
325223338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa3f0000 'C:\Windows\system32\winmm.dll'
325323338.7858: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\dsound.dll
325423338.7858: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000d41dae1:<flags> [calling]
325523338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef1780000 'C:\Windows\system32\dsound.dll'
325623338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa3f0000 'C:\Windows\system32\winmm.dll'
325723338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa3f0000 'C:\Windows\system32\winmm.dll'
325823338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa3f0000 'C:\Windows\system32\winmm.dll'
325923338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa3f0000 'C:\Windows\system32\winmm.dll'
326023338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa3f0000 'C:\Windows\system32\winmm.dll'
326123338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa3f0000 'C:\Windows\system32\winmm.dll'
326223338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status -23021 (0xffffa613)) on \Device\HarddiskVolume1\Program Files (x86)\Dexpot\hooxpot64.dll
326323338.1f228: Error (rc=0):
326423338.1f228: supR3HardenedScreenImage/LdrLoadDll: cached rc=Unknown Status -23021 (0xffffa613) fImage=1 fProtect=0x0 fAccess=0x0 cHits=32 \Device\HarddiskVolume1\Program Files (x86)\Dexpot\hooxpot64.dll
326523338.1f228: Error (rc=0):
326623338.1f228: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\Program Files (x86)\Dexpot\hooxpot64.dll' (C:\Program Files (x86)\Dexpot\hooxpot64.dll): rcNt=0xc0000190
326723338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Program Files (x86)\Dexpot\hooxpot64.dll'
326823338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status -23021 (0xffffa613)) on \Device\HarddiskVolume1\Program Files (x86)\Dexpot\hooxpot64.dll
326923338.1f228: Error (rc=0):
327023338.1f228: supR3HardenedScreenImage/LdrLoadDll: cached rc=Unknown Status -23021 (0xffffa613) fImage=1 fProtect=0x0 fAccess=0x0 cHits=64 \Device\HarddiskVolume1\Program Files (x86)\Dexpot\hooxpot64.dll
327123338.1f228: Error (rc=0):
327223338.1f228: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\Program Files (x86)\Dexpot\hooxpot64.dll' (C:\Program Files (x86)\Dexpot\hooxpot64.dll): rcNt=0xc0000190
327323338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Program Files (x86)\Dexpot\hooxpot64.dll'
327423338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status -22919 (0xffffa679)) on \Device\HarddiskVolume1\Program Files\ThinkPad\Bluetooth Software\BtMmHook.dll
327523338.1f228: Error (rc=0):
327623338.1f228: supR3HardenedScreenImage/LdrLoadDll: cached rc=Unknown Status -22919 (0xffffa679) fImage=1 fProtect=0x0 fAccess=0x0 cHits=5 \Device\HarddiskVolume1\Program Files\ThinkPad\Bluetooth Software\BtMmHook.dll
327723338.1f228: Error (rc=0):
327823338.1f228: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\Program Files\ThinkPad\Bluetooth Software\btmmhook.dll' (C:\Program Files\ThinkPad\Bluetooth Software\btmmhook.dll): rcNt=0xc0000190
327923338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Program Files\ThinkPad\Bluetooth Software\btmmhook.dll'
328023338.20e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077320000 'C:\Windows\system32\User32.dll'
328123338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status -22919 (0xffffa679)) on \Device\HarddiskVolume1\Program Files\ThinkPad\Bluetooth Software\BtMmHook.dll
328223338.1f228: Error (rc=0):
328323338.1f228: supR3HardenedScreenImage/LdrLoadDll: cached rc=Unknown Status -22919 (0xffffa679) fImage=1 fProtect=0x0 fAccess=0x0 cHits=6 \Device\HarddiskVolume1\Program Files\ThinkPad\Bluetooth Software\BtMmHook.dll
328423338.1f228: Error (rc=0):
328523338.1f228: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\Program Files\ThinkPad\Bluetooth Software\btmmhook.dll' (C:\Program Files\ThinkPad\Bluetooth Software\btmmhook.dll): rcNt=0xc0000190
328623338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Program Files\ThinkPad\Bluetooth Software\btmmhook.dll'
328723338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status -22919 (0xffffa679)) on \Device\HarddiskVolume1\Program Files\ThinkPad\Bluetooth Software\BtMmHook.dll
328823338.1f228: Error (rc=0):
328923338.1f228: supR3HardenedScreenImage/LdrLoadDll: cached rc=Unknown Status -22919 (0xffffa679) fImage=1 fProtect=0x0 fAccess=0x0 cHits=7 \Device\HarddiskVolume1\Program Files\ThinkPad\Bluetooth Software\BtMmHook.dll
329023338.1f228: Error (rc=0):
329123338.1f228: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\Program Files\ThinkPad\Bluetooth Software\btmmhook.dll' (C:\Program Files\ThinkPad\Bluetooth Software\btmmhook.dll): rcNt=0xc0000190
329223338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Program Files\ThinkPad\Bluetooth Software\btmmhook.dll'
329323338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status -22919 (0xffffa679)) on \Device\HarddiskVolume1\Program Files\ThinkPad\Bluetooth Software\BtMmHook.dll
329423338.1f228: Error (rc=0):
329523338.1f228: supR3HardenedScreenImage/LdrLoadDll: cached rc=Unknown Status -22919 (0xffffa679) fImage=1 fProtect=0x0 fAccess=0x0 cHits=8 \Device\HarddiskVolume1\Program Files\ThinkPad\Bluetooth Software\BtMmHook.dll
329623338.1f228: Error (rc=0):
329723338.1f228: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\Program Files\ThinkPad\Bluetooth Software\btmmhook.dll' (C:\Program Files\ThinkPad\Bluetooth Software\btmmhook.dll): rcNt=0xc0000190
329823338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Program Files\ThinkPad\Bluetooth Software\btmmhook.dll'
329923338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status -23021 (0xffffa613)) on \Device\HarddiskVolume1\Program Files (x86)\Dexpot\hooxpot64.dll
330023338.1f228: Error (rc=0):
330123338.1f228: supR3HardenedScreenImage/LdrLoadDll: cached rc=Unknown Status -23021 (0xffffa613) fImage=1 fProtect=0x0 fAccess=0x0 cHits=128 \Device\HarddiskVolume1\Program Files (x86)\Dexpot\hooxpot64.dll
330223338.1f228: Error (rc=0):
330323338.1f228: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\Program Files (x86)\Dexpot\hooxpot64.dll' (C:\Program Files (x86)\Dexpot\hooxpot64.dll): rcNt=0xc0000190
330423338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Program Files (x86)\Dexpot\hooxpot64.dll'
330523338.7858: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\dsound.dll
330623338.7858: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000d41cc01:<flags> [calling]
330723338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef1780000 'C:\Windows\system32\dsound.dll'
330823338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa3f0000 'C:\Windows\system32\winmm.dll'
330923338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa3f0000 'C:\Windows\system32\winmm.dll'
331023338.7858: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\winmm.dll
331123338.7858: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\winmm.dll (Input=winmm.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000d41dd21:<flags> [calling]
331223338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa3f0000 'C:\Windows\system32\winmm.dll'
331323338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa3f0000 'C:\Windows\system32\winmm.dll'
331423338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa3f0000 'C:\Windows\system32\winmm.dll'
331523338.7858: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa3f0000 'C:\Windows\system32\winmm.dll'
331623338.172b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\AudioSes.dll
331723338.172b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\audioses.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000d1fd151:<flags> [calling]
331823338.172b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef8c70000 'C:\Windows\System32\audioses.dll'
331923338.13e00: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\avrt.dll
332023338.13e00: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\avrt.dll (Input=avrt.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000005623f881:<flags> [calling]
332123338.13e00: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefb0b0000 'C:\Windows\system32\avrt.dll'
332223338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status -23021 (0xffffa613)) on \Device\HarddiskVolume1\Program Files (x86)\Dexpot\hooxpot64.dll
332323338.1f228: Error (rc=0):
332423338.1f228: supR3HardenedScreenImage/LdrLoadDll: cached rc=Unknown Status -23021 (0xffffa613) fImage=1 fProtect=0x0 fAccess=0x0 cHits=256 \Device\HarddiskVolume1\Program Files (x86)\Dexpot\hooxpot64.dll
332523338.1f228: Error (rc=0):
332623338.1f228: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\Program Files (x86)\Dexpot\hooxpot64.dll' (C:\Program Files (x86)\Dexpot\hooxpot64.dll): rcNt=0xc0000190
332723338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Program Files (x86)\Dexpot\hooxpot64.dll'
332823338.1f228: supR3HardNtViCallWinVerifyTrust: WinVerifyTrust failed with 0x800b010c (CERT_E_REVOKED) on '\Device\HarddiskVolume1\Program Files\ThinkPad\Bluetooth Software\BTKeyInd.dll'
332923338.1f228: supHardenedWinVerifyImageByHandle: -> -22919 (\Device\HarddiskVolume1\Program Files\ThinkPad\Bluetooth Software\BTKeyInd.dll) WinVerifyTrust
333023338.1f228: Error (rc=0):
333123338.1f228: supR3HardenedScreenImage/LdrLoadDll: rc=Unknown Status -22919 (0xffffa679) fImage=1 fProtect=0x0 fAccess=0x0 \Device\HarddiskVolume1\Program Files\ThinkPad\Bluetooth Software\BTKeyInd.dll: WinVerifyTrust failed with hrc=CERT_E_REVOKED on '\Device\HarddiskVolume1\Program Files\ThinkPad\Bluetooth Software\BTKeyInd.dll'
333223338.1f228: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume1\Program Files\ThinkPad\Bluetooth Software\BTKeyInd.dll
333323338.1f228: Error (rc=0):
333423338.1f228: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\Program Files\ThinkPad\Bluetooth Software\btkeyind.dll' (C:\Program Files\ThinkPad\Bluetooth Software\btkeyind.dll): rcNt=0xc0000190
333523338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Program Files\ThinkPad\Bluetooth Software\btkeyind.dll'
333623338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status -22919 (0xffffa679)) on \Device\HarddiskVolume1\Program Files\ThinkPad\Bluetooth Software\BTKeyInd.dll
333723338.1f228: Error (rc=0):
333823338.1f228: supR3HardenedScreenImage/LdrLoadDll: cached rc=Unknown Status -22919 (0xffffa679) fImage=1 fProtect=0x0 fAccess=0x0 cHits=1 \Device\HarddiskVolume1\Program Files\ThinkPad\Bluetooth Software\BTKeyInd.dll
333923338.1f228: Error (rc=0):
334023338.1f228: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\Program Files\ThinkPad\Bluetooth Software\btkeyind.dll' (C:\Program Files\ThinkPad\Bluetooth Software\btkeyind.dll): rcNt=0xc0000190
334123338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Program Files\ThinkPad\Bluetooth Software\btkeyind.dll'
334223338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status -22919 (0xffffa679)) on \Device\HarddiskVolume1\Program Files\ThinkPad\Bluetooth Software\BTKeyInd.dll
334323338.1f228: Error (rc=0):
334423338.1f228: supR3HardenedScreenImage/LdrLoadDll: cached rc=Unknown Status -22919 (0xffffa679) fImage=1 fProtect=0x0 fAccess=0x0 cHits=2 \Device\HarddiskVolume1\Program Files\ThinkPad\Bluetooth Software\BTKeyInd.dll
334523338.1f228: Error (rc=0):
334623338.1f228: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\Program Files\ThinkPad\Bluetooth Software\btkeyind.dll' (C:\Program Files\ThinkPad\Bluetooth Software\btkeyind.dll): rcNt=0xc0000190
334723338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Program Files\ThinkPad\Bluetooth Software\btkeyind.dll'
334823338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status -22919 (0xffffa679)) on \Device\HarddiskVolume1\Program Files\ThinkPad\Bluetooth Software\BTKeyInd.dll
334923338.1f228: Error (rc=0):
335023338.1f228: supR3HardenedScreenImage/LdrLoadDll: cached rc=Unknown Status -22919 (0xffffa679) fImage=1 fProtect=0x0 fAccess=0x0 cHits=3 \Device\HarddiskVolume1\Program Files\ThinkPad\Bluetooth Software\BTKeyInd.dll
335123338.1f228: Error (rc=0):
335223338.1f228: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\Program Files\ThinkPad\Bluetooth Software\btkeyind.dll' (C:\Program Files\ThinkPad\Bluetooth Software\btkeyind.dll): rcNt=0xc0000190
335323338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Program Files\ThinkPad\Bluetooth Software\btkeyind.dll'
335423338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status -22919 (0xffffa679)) on \Device\HarddiskVolume1\Program Files\ThinkPad\Bluetooth Software\BTKeyInd.dll
335523338.1f228: Error (rc=0):
335623338.1f228: supR3HardenedScreenImage/LdrLoadDll: cached rc=Unknown Status -22919 (0xffffa679) fImage=1 fProtect=0x0 fAccess=0x0 cHits=4 \Device\HarddiskVolume1\Program Files\ThinkPad\Bluetooth Software\BTKeyInd.dll
335723338.1f228: Error (rc=0):
335823338.1f228: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\Program Files\ThinkPad\Bluetooth Software\btkeyind.dll' (C:\Program Files\ThinkPad\Bluetooth Software\btkeyind.dll): rcNt=0xc0000190
335923338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Program Files\ThinkPad\Bluetooth Software\btkeyind.dll'
336023338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status -22919 (0xffffa679)) on \Device\HarddiskVolume1\Program Files\ThinkPad\Bluetooth Software\BTKeyInd.dll
336123338.1f228: Error (rc=0):
336223338.1f228: supR3HardenedScreenImage/LdrLoadDll: cached rc=Unknown Status -22919 (0xffffa679) fImage=1 fProtect=0x0 fAccess=0x0 cHits=5 \Device\HarddiskVolume1\Program Files\ThinkPad\Bluetooth Software\BTKeyInd.dll
336323338.1f228: Error (rc=0):
336423338.1f228: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\Program Files\ThinkPad\Bluetooth Software\btkeyind.dll' (C:\Program Files\ThinkPad\Bluetooth Software\btkeyind.dll): rcNt=0xc0000190
336523338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Program Files\ThinkPad\Bluetooth Software\btkeyind.dll'
336623338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status -22919 (0xffffa679)) on \Device\HarddiskVolume1\Program Files\ThinkPad\Bluetooth Software\BTKeyInd.dll
336723338.1f228: Error (rc=0):
336823338.1f228: supR3HardenedScreenImage/LdrLoadDll: cached rc=Unknown Status -22919 (0xffffa679) fImage=1 fProtect=0x0 fAccess=0x0 cHits=6 \Device\HarddiskVolume1\Program Files\ThinkPad\Bluetooth Software\BTKeyInd.dll
336923338.1f228: Error (rc=0):
337023338.1f228: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\Program Files\ThinkPad\Bluetooth Software\btkeyind.dll' (C:\Program Files\ThinkPad\Bluetooth Software\btkeyind.dll): rcNt=0xc0000190
337123338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Program Files\ThinkPad\Bluetooth Software\btkeyind.dll'
337223338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status -23021 (0xffffa613)) on \Device\HarddiskVolume1\Program Files (x86)\Dexpot\hooxpot64.dll
337323338.1f228: Error (rc=0):
337423338.1f228: supR3HardenedScreenImage/LdrLoadDll: cached rc=Unknown Status -23021 (0xffffa613) fImage=1 fProtect=0x0 fAccess=0x0 cHits=512 \Device\HarddiskVolume1\Program Files (x86)\Dexpot\hooxpot64.dll
337523338.1f228: Error (rc=0):
337623338.1f228: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\Program Files (x86)\Dexpot\hooxpot64.dll' (C:\Program Files (x86)\Dexpot\hooxpot64.dll): rcNt=0xc0000190
337723338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Program Files (x86)\Dexpot\hooxpot64.dll'
337823338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status -22919 (0xffffa679)) on \Device\HarddiskVolume1\Program Files\ThinkPad\Bluetooth Software\BtMmHook.dll
337923338.1f228: Error (rc=0):
338023338.1f228: supR3HardenedScreenImage/LdrLoadDll: cached rc=Unknown Status -22919 (0xffffa679) fImage=1 fProtect=0x0 fAccess=0x0 cHits=16 \Device\HarddiskVolume1\Program Files\ThinkPad\Bluetooth Software\BtMmHook.dll
338123338.1f228: Error (rc=0):
338223338.1f228: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\Program Files\ThinkPad\Bluetooth Software\btmmhook.dll' (C:\Program Files\ThinkPad\Bluetooth Software\btmmhook.dll): rcNt=0xc0000190
338323338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Program Files\ThinkPad\Bluetooth Software\btmmhook.dll'
338423338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status -23021 (0xffffa613)) on \Device\HarddiskVolume1\Program Files (x86)\Dexpot\hooxpot64.dll
338523338.1f228: Error (rc=0):
338623338.1f228: supR3HardenedScreenImage/LdrLoadDll: cached rc=Unknown Status -23021 (0xffffa613) fImage=1 fProtect=0x0 fAccess=0x0 cHits=1024 \Device\HarddiskVolume1\Program Files (x86)\Dexpot\hooxpot64.dll
338723338.1f228: Error (rc=0):
338823338.1f228: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\Program Files (x86)\Dexpot\hooxpot64.dll' (C:\Program Files (x86)\Dexpot\hooxpot64.dll): rcNt=0xc0000190
338923338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Program Files (x86)\Dexpot\hooxpot64.dll'
339023338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status -23021 (0xffffa613)) on \Device\HarddiskVolume1\Program Files (x86)\Dexpot\hooxpot64.dll
339123338.1f228: Error (rc=0):
339223338.1f228: supR3HardenedScreenImage/LdrLoadDll: cached rc=Unknown Status -23021 (0xffffa613) fImage=1 fProtect=0x0 fAccess=0x0 cHits=2048 \Device\HarddiskVolume1\Program Files (x86)\Dexpot\hooxpot64.dll
339323338.1f228: Error (rc=0):
339423338.1f228: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\Program Files (x86)\Dexpot\hooxpot64.dll' (C:\Program Files (x86)\Dexpot\hooxpot64.dll): rcNt=0xc0000190
339523338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Program Files (x86)\Dexpot\hooxpot64.dll'
339623338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status -22919 (0xffffa679)) on \Device\HarddiskVolume1\Program Files\ThinkPad\Bluetooth Software\BTKeyInd.dll
339723338.1f228: Error (rc=0):
339823338.1f228: supR3HardenedScreenImage/LdrLoadDll: cached rc=Unknown Status -22919 (0xffffa679) fImage=1 fProtect=0x0 fAccess=0x0 cHits=7 \Device\HarddiskVolume1\Program Files\ThinkPad\Bluetooth Software\BTKeyInd.dll
339923338.1f228: Error (rc=0):
340023338.1f228: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\Program Files\ThinkPad\Bluetooth Software\btkeyind.dll' (C:\Program Files\ThinkPad\Bluetooth Software\btkeyind.dll): rcNt=0xc0000190
340123338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Program Files\ThinkPad\Bluetooth Software\btkeyind.dll'
340223338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status -22919 (0xffffa679)) on \Device\HarddiskVolume1\Program Files\ThinkPad\Bluetooth Software\BTKeyInd.dll
340323338.1f228: Error (rc=0):
340423338.1f228: supR3HardenedScreenImage/LdrLoadDll: cached rc=Unknown Status -22919 (0xffffa679) fImage=1 fProtect=0x0 fAccess=0x0 cHits=8 \Device\HarddiskVolume1\Program Files\ThinkPad\Bluetooth Software\BTKeyInd.dll
340523338.1f228: Error (rc=0):
340623338.1f228: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\Program Files\ThinkPad\Bluetooth Software\btkeyind.dll' (C:\Program Files\ThinkPad\Bluetooth Software\btkeyind.dll): rcNt=0xc0000190
340723338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Program Files\ThinkPad\Bluetooth Software\btkeyind.dll'
340823338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\shell32.dll
340923338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001e90d1:<flags> [calling]
341023338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd370000 'C:\Windows\system32\shell32.dll'
341123338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd370000 'C:\Windows\system32\shell32.dll'
341223338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd370000 'C:\Windows\system32\shell32.dll'
341323338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd370000 'C:\Windows\system32\shell32.dll'
341423338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd370000 'C:\Windows\system32\shell32.dll'
341523338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd370000 'C:\Windows\system32\shell32.dll'
341623338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd370000 'C:\Windows\system32\shell32.dll'
341723338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd370000 'C:\Windows\system32\shell32.dll'
341823338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume1\Windows\System32\shell32.dll
341923338.1f228: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001e90d1:<flags> [calling]
342023338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd370000 'C:\Windows\system32\shell32.dll'
342123338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd370000 'C:\Windows\system32\shell32.dll'
342223338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd370000 'C:\Windows\system32\shell32.dll'
342323338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd370000 'C:\Windows\system32\shell32.dll'
342423338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd370000 'C:\Windows\system32\shell32.dll'
342523338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd370000 'C:\Windows\system32\shell32.dll'
342623338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd370000 'C:\Windows\system32\shell32.dll'
342723338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd370000 'C:\Windows\system32\shell32.dll'
342823338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd370000 'C:\Windows\system32\shell32.dll'
342923338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status -22919 (0xffffa679)) on \Device\HarddiskVolume1\Program Files\ThinkPad\Bluetooth Software\BtMmHook.dll
343023338.1f228: Error (rc=0):
343123338.1f228: supR3HardenedScreenImage/LdrLoadDll: cached rc=Unknown Status -22919 (0xffffa679) fImage=1 fProtect=0x0 fAccess=0x0 cHits=32 \Device\HarddiskVolume1\Program Files\ThinkPad\Bluetooth Software\BtMmHook.dll
343223338.1f228: Error (rc=0):
343323338.1f228: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\Program Files\ThinkPad\Bluetooth Software\btmmhook.dll' (C:\Program Files\ThinkPad\Bluetooth Software\btmmhook.dll): rcNt=0xc0000190
343423338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Program Files\ThinkPad\Bluetooth Software\btmmhook.dll'
343523338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd370000 'C:\Windows\system32\shell32.dll'
343623338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd370000 'C:\Windows\system32\shell32.dll'
343723338.1f228: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status -23021 (0xffffa613)) on \Device\HarddiskVolume1\Program Files (x86)\Dexpot\hooxpot64.dll
343823338.1f228: Error (rc=0):
343923338.1f228: supR3HardenedScreenImage/LdrLoadDll: cached rc=Unknown Status -23021 (0xffffa613) fImage=1 fProtect=0x0 fAccess=0x0 cHits=4096 \Device\HarddiskVolume1\Program Files (x86)\Dexpot\hooxpot64.dll
344023338.1f228: Error (rc=0):
344123338.1f228: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\Program Files (x86)\Dexpot\hooxpot64.dll' (C:\Program Files (x86)\Dexpot\hooxpot64.dll): rcNt=0xc0000190
344223338.1f228: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Program Files (x86)\Dexpot\hooxpot64.dll'

© 2024 Oracle Support Privacy / Do Not Sell My Info Terms of Use Trademark Policy Automated Access Etiquette