VirtualBox

Ticket #22057: VBoxHardening-1.log

File VBoxHardening-1.log, 298.2 KB (added by nobel, 9 months ago)
Line 
15754.62fc: \SystemRoot\System32\ntdll.dll:
25754.62fc: CreationTime: 2024-04-25T21:50:52.933474100Z
35754.62fc: LastWriteTime: 2024-04-25T21:50:52.967360700Z
45754.62fc: ChangeTime: 2024-04-25T22:15:47.894551900Z
55754.62fc: FileAttributes: 0x20
65754.62fc: Size: 0x216008
75754.62fc: NT Headers: 0xe8
85754.62fc: Timestamp: 0x92b2df34
95754.62fc: Machine: 0x8664 - amd64
105754.62fc: Timestamp: 0x92b2df34
115754.62fc: Image Version: 10.0
125754.62fc: SizeOfImage: 0x217000 (2191360)
135754.62fc: Resource Dir: 0x1a0000 LB 0x759a8
145754.62fc: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
155754.62fc: [Raw version resource data: 0x1a00f0 LB 0x380, codepage 0x0 (reserved 0x0)]
165754.62fc: ProductName: Microsoft® Windows® Operating System
175754.62fc: ProductVersion: 10.0.22621.3527
185754.62fc: FileVersion: 10.0.22621.3527 (WinBuild.160101.0800)
195754.62fc: FileDescription: NT Layer DLL
205754.62fc: \SystemRoot\System32\kernel32.dll:
215754.62fc: CreationTime: 2024-04-25T21:50:52.649892600Z
225754.62fc: LastWriteTime: 2024-04-25T21:50:52.664841500Z
235754.62fc: ChangeTime: 2024-04-25T22:15:37.505042500Z
245754.62fc: FileAttributes: 0x20
255754.62fc: Size: 0xc7158
265754.62fc: NT Headers: 0xe8
275754.62fc: Timestamp: 0x6b8a5ea3
285754.62fc: Machine: 0x8664 - amd64
295754.62fc: Timestamp: 0x6b8a5ea3
305754.62fc: Image Version: 10.0
315754.62fc: SizeOfImage: 0xc4000 (802816)
325754.62fc: Resource Dir: 0xc2000 LB 0x520
335754.62fc: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
345754.62fc: [Raw version resource data: 0xc20b0 LB 0x3a4, codepage 0x0 (reserved 0x0)]
355754.62fc: ProductName: Microsoft® Windows® Operating System
365754.62fc: ProductVersion: 10.0.22621.3527
375754.62fc: FileVersion: 10.0.22621.3527 (WinBuild.160101.0800)
385754.62fc: FileDescription: Windows NT BASE API Client DLL
395754.62fc: \SystemRoot\System32\KernelBase.dll:
405754.62fc: CreationTime: 2024-04-25T21:50:53.507611100Z
415754.62fc: LastWriteTime: 2024-04-25T21:50:53.604794300Z
425754.62fc: ChangeTime: 2024-04-25T22:15:45.722906700Z
435754.62fc: FileAttributes: 0x20
445754.62fc: Size: 0x3ae908
455754.62fc: NT Headers: 0xf8
465754.62fc: Timestamp: 0x83efbeab
475754.62fc: Machine: 0x8664 - amd64
485754.62fc: Timestamp: 0x83efbeab
495754.62fc: Image Version: 10.0
505754.62fc: SizeOfImage: 0x3a7000 (3829760)
515754.62fc: Resource Dir: 0x376000 LB 0x548
525754.62fc: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
535754.62fc: [Raw version resource data: 0x3760b0 LB 0x3bc, codepage 0x0 (reserved 0x0)]
545754.62fc: ProductName: Microsoft® Windows® Operating System
555754.62fc: ProductVersion: 10.0.22621.3527
565754.62fc: FileVersion: 10.0.22621.3527 (WinBuild.160101.0800)
575754.62fc: FileDescription: Windows NT BASE API Client DLL
585754.62fc: \SystemRoot\System32\apisetschema.dll:
595754.62fc: CreationTime: 2024-04-25T21:50:27.205621000Z
605754.62fc: LastWriteTime: 2024-04-25T21:50:27.208610400Z
615754.62fc: ChangeTime: 2024-04-25T22:15:42.442010700Z
625754.62fc: FileAttributes: 0x20
635754.62fc: Size: 0x245e0
645754.62fc: NT Headers: 0xc8
655754.62fc: Timestamp: 0x2f79598b
665754.62fc: Machine: 0x8664 - amd64
675754.62fc: Timestamp: 0x2f79598b
685754.62fc: Image Version: 10.0
695754.62fc: SizeOfImage: 0x23000 (143360)
705754.62fc: Resource Dir: 0x22000 LB 0x408
715754.62fc: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
725754.62fc: [Raw version resource data: 0x22060 LB 0x3a8, codepage 0x0 (reserved 0x0)]
735754.62fc: ProductName: Microsoft® Windows® Operating System
745754.62fc: ProductVersion: 10.0.22621.3527
755754.62fc: FileVersion: 10.0.22621.3527 (WinBuild.160101.0800)
765754.62fc: FileDescription: ApiSet Schema DLL
775754.62fc: NtOpenDirectoryObject failed on \Driver: 0xc0000022
785754.62fc: supR3HardenedWinFindAdversaries: 0x4
795754.62fc: \SystemRoot\System32\drivers\aswMonFlt.sys:
805754.62fc: CreationTime: 2022-11-24T10:33:09.488089900Z
815754.62fc: LastWriteTime: 2024-04-12T01:45:56.269304300Z
825754.62fc: ChangeTime: 2024-04-12T01:45:56.269304300Z
835754.62fc: FileAttributes: 0x20
845754.62fc: Size: 0x41a38
855754.62fc: NT Headers: 0xf0
865754.62fc: Timestamp: 0x660161d5
875754.62fc: Machine: 0x8664 - amd64
885754.62fc: Timestamp: 0x660161d5
895754.62fc: Image Version: 10.0
905754.62fc: SizeOfImage: 0x49000 (299008)
915754.62fc: Resource Dir: 0x47000 LB 0x3b0
925754.62fc: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
935754.62fc: [Raw version resource data: 0x47058 LB 0x358, codepage 0x0 (reserved 0x0)]
945754.62fc: ProductName: Antivirus
955754.62fc: ProductVersion: 24.3.683.0
965754.62fc: FileVersion: 24.3.683.0
975754.62fc: FileDescription: Gen File System Filter
985754.62fc: \SystemRoot\System32\drivers\aswRdr2.sys:
995754.62fc: CreationTime: 2022-11-24T10:33:09.486096500Z
1005754.62fc: LastWriteTime: 2024-04-12T01:45:56.261304700Z
1015754.62fc: ChangeTime: 2024-04-12T01:45:56.261304700Z
1025754.62fc: FileAttributes: 0x20
1035754.62fc: Size: 0x16e38
1045754.62fc: NT Headers: 0xe8
1055754.62fc: Timestamp: 0x660161d2
1065754.62fc: Machine: 0x8664 - amd64
1075754.62fc: Timestamp: 0x660161d2
1085754.62fc: Image Version: 10.0
1095754.62fc: SizeOfImage: 0x1b000 (110592)
1105754.62fc: Resource Dir: 0x19000 LB 0x398
1115754.62fc: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
1125754.62fc: [Raw version resource data: 0x19058 LB 0x33c, codepage 0x0 (reserved 0x0)]
1135754.62fc: ProductName: Antivirus
1145754.62fc: ProductVersion: 24.3.683.0
1155754.62fc: FileVersion: 24.3.683.0
1165754.62fc: FileDescription: Gen Antivirus
1175754.62fc: \SystemRoot\System32\drivers\aswRvrt.sys:
1185754.62fc: CreationTime: 2022-11-24T10:33:09.489086600Z
1195754.62fc: LastWriteTime: 2024-04-12T01:45:56.277304500Z
1205754.62fc: ChangeTime: 2024-04-12T01:45:56.277304500Z
1215754.62fc: FileAttributes: 0x20
1225754.62fc: Size: 0x10e38
1235754.62fc: NT Headers: 0xe0
1245754.62fc: Timestamp: 0x660161cb
1255754.62fc: Machine: 0x8664 - amd64
1265754.62fc: Timestamp: 0x660161cb
1275754.62fc: Image Version: 10.0
1285754.62fc: SizeOfImage: 0x13000 (77824)
1295754.62fc: Resource Dir: 0x11000 LB 0x390
1305754.62fc: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
1315754.62fc: [Raw version resource data: 0x11058 LB 0x338, codepage 0x0 (reserved 0x0)]
1325754.62fc: ProductName: Antivirus
1335754.62fc: ProductVersion: 24.3.683.0
1345754.62fc: FileVersion: 24.3.683.0
1355754.62fc: FileDescription: Gen Revert
1365754.62fc: \SystemRoot\System32\drivers\aswSnx.sys:
1375754.62fc: CreationTime: 2022-11-24T10:33:09.480116700Z
1385754.62fc: LastWriteTime: 2024-04-12T01:45:53.466864800Z
1395754.62fc: ChangeTime: 2024-04-12T01:45:53.466864800Z
1405754.62fc: FileAttributes: 0x20
1415754.62fc: Size: 0xe4838
1425754.62fc: NT Headers: 0x100
1435754.62fc: Timestamp: 0x660161ff
1445754.62fc: Machine: 0x8664 - amd64
1455754.62fc: Timestamp: 0x660161ff
1465754.62fc: Image Version: 10.0
1475754.62fc: SizeOfImage: 0xe9000 (954368)
1485754.62fc: Resource Dir: 0xe6000 LB 0x3b0
1495754.62fc: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
1505754.62fc: [Raw version resource data: 0xe6058 LB 0x354, codepage 0x0 (reserved 0x0)]
1515754.62fc: ProductName: Antivirus
1525754.62fc: ProductVersion: 24.3.683.0
1535754.62fc: FileVersion: 24.3.683.0
1545754.62fc: FileDescription: Gen Virtualization Driver
1555754.62fc: \SystemRoot\System32\drivers\aswsp.sys:
1565754.62fc: CreationTime: 2022-11-24T10:33:09.490083300Z
1575754.62fc: LastWriteTime: 2024-04-12T01:45:56.288304000Z
1585754.62fc: ChangeTime: 2024-04-12T01:45:56.288304000Z
1595754.62fc: FileAttributes: 0x20
1605754.62fc: Size: 0xa9e38
1615754.62fc: NT Headers: 0xe8
1625754.62fc: Timestamp: 0x660161ed
1635754.62fc: Machine: 0x8664 - amd64
1645754.62fc: Timestamp: 0x660161ed
1655754.62fc: Image Version: 10.0
1665754.62fc: SizeOfImage: 0xb0000 (720896)
1675754.62fc: Resource Dir: 0xad000 LB 0x398
1685754.62fc: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
1695754.62fc: [Raw version resource data: 0xad058 LB 0x340, codepage 0x0 (reserved 0x0)]
1705754.62fc: ProductName: Antivirus
1715754.62fc: ProductVersion: 24.3.683.0
1725754.62fc: FileVersion: 24.3.683.0
1735754.62fc: FileDescription: Gen Self Protection
1745754.62fc: \SystemRoot\System32\drivers\aswStm.sys:
1755754.62fc: CreationTime: 2024-04-12T01:45:58.391309500Z
1765754.62fc: LastWriteTime: 2024-04-12T01:45:56.481310100Z
1775754.62fc: ChangeTime: 2024-04-12T01:45:56.481310100Z
1785754.62fc: FileAttributes: 0x20
1795754.62fc: Size: 0x31438
1805754.62fc: NT Headers: 0xf0
1815754.62fc: Timestamp: 0x66016201
1825754.62fc: Machine: 0x8664 - amd64
1835754.62fc: Timestamp: 0x66016201
1845754.62fc: Image Version: 10.0
1855754.62fc: SizeOfImage: 0x36000 (221184)
1865754.62fc: Resource Dir: 0x34000 LB 0x3a0
1875754.62fc: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
1885754.62fc: [Raw version resource data: 0x34058 LB 0x344, codepage 0x0 (reserved 0x0)]
1895754.62fc: ProductName: Antivirus
1905754.62fc: ProductVersion: 24.3.683.0
1915754.62fc: FileVersion: 24.3.683.0
1925754.62fc: FileDescription: Gen Stream Filter
1935754.62fc: \SystemRoot\System32\drivers\aswVmm.sys:
1945754.62fc: CreationTime: 2022-11-24T10:33:09.495066500Z
1955754.62fc: LastWriteTime: 2024-04-12T01:45:56.819309900Z
1965754.62fc: ChangeTime: 2024-04-12T01:45:56.819309900Z
1975754.62fc: FileAttributes: 0x20
1985754.62fc: Size: 0x4ac38
1995754.62fc: NT Headers: 0xe8
2005754.62fc: Timestamp: 0x660161d4
2015754.62fc: Machine: 0x8664 - amd64
2025754.62fc: Timestamp: 0x660161d4
2035754.62fc: Image Version: 10.0
2045754.62fc: SizeOfImage: 0x4d000 (315392)
2055754.62fc: Resource Dir: 0x4b000 LB 0x398
2065754.62fc: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
2075754.62fc: [Raw version resource data: 0x4b058 LB 0x340, codepage 0x0 (reserved 0x0)]
2085754.62fc: ProductName: Antivirus
2095754.62fc: ProductVersion: 24.3.683.0
2105754.62fc: FileVersion: 24.3.683.0
2115754.62fc: FileDescription: Gen VM Monitor
2125754.62fc: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox'
2135754.62fc: Calling main()
2145754.62fc: SUPR3HardenedMain: pszProgName=VirtualBoxVM fFlags=0x2
2155754.62fc: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox'
2165754.62fc: SUPR3HardenedMain: Respawn #1
2175754.62fc: System32: \Device\HarddiskVolume3\Windows\System32
2185754.62fc: WinSxS: \Device\HarddiskVolume3\Windows\WinSxS
2195754.62fc: KnownDllPath: C:\WINDOWS\System32
2205754.62fc: supR3HardenedWinInit: Performing a limited self purification...
2215754.62fc: supHardNtVpScanVirtualMemory: enmKind=SELF_PURIFICATION
2225754.62fc: *0000000000000000-000000007ffdffff 0x0001/0x0000 0x0000000
2235754.62fc: *000000007ffe0000-000000007ffe0fff 0x0002/0x0002 0x0020000
2245754.62fc: 000000007ffe1000-000000007ffeefff 0x0001/0x0000 0x0000000
2255754.62fc: *000000007ffef000-000000007ffeffff 0x0002/0x0002 0x0020000
2265754.62fc: 000000007fff0000-000000baf9e0ffff 0x0001/0x0000 0x0000000
2275754.62fc: *000000baf9e10000-000000baf9ec0fff 0x0000/0x0004 0x0020000
2285754.62fc: 000000baf9ec1000-000000baf9ec3fff 0x0104/0x0004 0x0020000
2295754.62fc: 000000baf9ec4000-000000baf9f0ffff 0x0004/0x0004 0x0020000
2305754.62fc: 000000baf9f10000-000000baf9ffffff 0x0001/0x0000 0x0000000
2315754.62fc: *000000bafa000000-000000bafa010fff 0x0000/0x0004 0x0020000
2325754.62fc: 000000bafa011000-000000bafa013fff 0x0004/0x0004 0x0020000
2335754.62fc: 000000bafa014000-000000bafa1fffff 0x0000/0x0004 0x0020000
2345754.62fc: 000000bafa200000-00000224c5dbffff 0x0001/0x0000 0x0000000
2355754.62fc: *00000224c5dc0000-00000224c5dcffff 0x0004/0x0004 0x0040000
2365754.62fc: *00000224c5dd0000-00000224c5dd2fff 0x0002/0x0002 0x0040000
2375754.62fc: 00000224c5dd3000-00000224c5ddffff 0x0001/0x0000 0x0000000
2385754.62fc: *00000224c5de0000-00000224c5dfefff 0x0002/0x0002 0x0040000
2395754.62fc: 00000224c5dff000-00000224c5dfffff 0x0001/0x0000 0x0000000
2405754.62fc: *00000224c5e00000-00000224c5e00fff 0x0020/0x0020 0x0040000 !!
2415754.62fc: 00000224c5e01000-00000224c5e0ffff 0x0001/0x0000 0x0000000
2425754.62fc: *00000224c5e10000-00000224c5e13fff 0x0002/0x0002 0x0040000
2435754.62fc: 00000224c5e14000-00000224c5e1ffff 0x0001/0x0000 0x0000000
2445754.62fc: *00000224c5e20000-00000224c5e20fff 0x0002/0x0002 0x0040000
2455754.62fc: 00000224c5e21000-00000224c5e2ffff 0x0001/0x0000 0x0000000
2465754.62fc: *00000224c5e30000-00000224c5e31fff 0x0004/0x0004 0x0020000
2475754.62fc: 00000224c5e32000-00000224c5e3ffff 0x0001/0x0000 0x0000000
2485754.62fc: *00000224c5e40000-00000224c5e42fff 0x0002/0x0002 0x0040000
2495754.62fc: 00000224c5e43000-00000224c5e4ffff 0x0001/0x0000 0x0000000
2505754.62fc: *00000224c5e50000-00000224c5e51fff 0x0004/0x0004 0x0020000
2515754.62fc: 00000224c5e52000-00000224c5f12fff 0x0000/0x0004 0x0020000
2525754.62fc: 00000224c5f13000-00000224c5f5ffff 0x0001/0x0000 0x0000000
2535754.62fc: *00000224c5f60000-00000224c5f6efff 0x0004/0x0004 0x0020000
2545754.62fc: 00000224c5f6f000-00000224c5f6ffff 0x0000/0x0004 0x0020000
2555754.62fc: 00000224c5f70000-00000224c5f9ffff 0x0001/0x0000 0x0000000
2565754.62fc: *00000224c5fa0000-00000224c5faafff 0x0004/0x0004 0x0020000
2575754.62fc: 00000224c5fab000-00000224c609ffff 0x0000/0x0004 0x0020000
2585754.62fc: *00000224c60a0000-00000224c616dfff 0x0002/0x0002 0x0040000
2595754.62fc: 00000224c616e000-00000224c616ffff 0x0001/0x0000 0x0000000
2605754.62fc: *00000224c6170000-00000224c617dfff 0x0000/0x0004 0x0020000
2615754.62fc: 00000224c617e000-00000224c6395fff 0x0004/0x0004 0x0020000
2625754.62fc: 00000224c6396000-00000224c6396fff 0x0000/0x0004 0x0020000
2635754.62fc: 00000224c6397000-00000224c639ffff 0x0001/0x0000 0x0000000
2645754.62fc: *00000224c63a0000-00000224c63a1fff 0x0004/0x0004 0x0020000
2655754.62fc: 00000224c63a2000-00000224c6462fff 0x0000/0x0004 0x0020000
2665754.62fc: 00000224c6463000-00000224c646ffff 0x0001/0x0000 0x0000000
2675754.62fc: *00000224c6470000-00000224c649dfff 0x0004/0x0004 0x0020000
2685754.62fc: 00000224c649e000-00000224c656ffff 0x0000/0x0004 0x0020000
2695754.62fc: 00000224c6570000-00007df4a14fffff 0x0001/0x0000 0x0000000
2705754.62fc: *00007df4a1500000-00007df4a1504fff 0x0002/0x0002 0x0040000
2715754.62fc: 00007df4a1505000-00007df4a15fffff 0x0000/0x0002 0x0040000
2725754.62fc: *00007df4a1600000-00007df5a161ffff 0x0000/0x0004 0x0020000
2735754.62fc: *00007df5a1620000-00007df5a361ffff 0x0000/0x0004 0x0020000
2745754.62fc: 00007df5a3620000-00007df5a3620fff 0x0004/0x0004 0x0020000
2755754.62fc: 00007df5a3621000-00007df5a362ffff 0x0001/0x0000 0x0000000
2765754.62fc: *00007df5a3630000-00007df5a3630fff 0x0002/0x0002 0x0040000
2775754.62fc: 00007df5a3631000-00007df5a363ffff 0x0001/0x0000 0x0000000
2785754.62fc: *00007df5a3640000-00007df5a4bbdfff 0x0000/0x0001 0x0040000
2795754.62fc: 00007df5a4bbe000-00007df5a4c2afff 0x0001/0x0001 0x0040000
2805754.62fc: 00007df5a4c2b000-00007df5a5428fff 0x0000/0x0001 0x0040000
2815754.62fc: 00007df5a5429000-00007df5a5429fff 0x0001/0x0001 0x0040000
2825754.62fc: 00007df5a542a000-00007dfe367b7fff 0x0000/0x0001 0x0040000
2835754.62fc: 00007dfe367b8000-00007dfe367b8fff 0x0002/0x0001 0x0040000
2845754.62fc: 00007dfe367b9000-00007ff57ca50fff 0x0000/0x0001 0x0040000
2855754.62fc: 00007ff57ca51000-00007ff57ca56fff 0x0002/0x0001 0x0040000
2865754.62fc: 00007ff57ca57000-00007ff59283bfff 0x0000/0x0001 0x0040000
2875754.62fc: 00007ff59283c000-00007ff5954bdfff 0x0001/0x0001 0x0040000
2885754.62fc: 00007ff5954be000-00007ff5954befff 0x0002/0x0001 0x0040000
2895754.62fc: 00007ff5954bf000-00007ff59577dfff 0x0001/0x0001 0x0040000
2905754.62fc: 00007ff59577e000-00007ff59577ffff 0x0002/0x0001 0x0040000
2915754.62fc: 00007ff595780000-00007ff596412fff 0x0001/0x0001 0x0040000
2925754.62fc: 00007ff596413000-00007ff596422fff 0x0002/0x0001 0x0040000
2935754.62fc: 00007ff596423000-00007ff59645efff 0x0001/0x0001 0x0040000
2945754.62fc: 00007ff59645f000-00007ff596462fff 0x0002/0x0001 0x0040000
2955754.62fc: 00007ff596463000-00007ff5964bbfff 0x0001/0x0001 0x0040000
2965754.62fc: 00007ff5964bc000-00007ff5964c4fff 0x0002/0x0001 0x0040000
2975754.62fc: 00007ff5964c5000-00007ff5a363ffff 0x0000/0x0001 0x0040000
2985754.62fc: 00007ff5a3640000-00007ff65046ffff 0x0001/0x0000 0x0000000
2995754.62fc: *00007ff650470000-00007ff650470fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
3005754.62fc: 00007ff650471000-00007ff6504dafff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
3015754.62fc: 00007ff6504db000-00007ff6504dbfff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
3025754.62fc: 00007ff6504dc000-00007ff65052efff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
3035754.62fc: 00007ff65052f000-00007ff650531fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
3045754.62fc: 00007ff650532000-00007ff650534fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
3055754.62fc: 00007ff650535000-00007ff650537fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
3065754.62fc: 00007ff650538000-00007ff650538fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
3075754.62fc: 00007ff650539000-00007ff65053afff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
3085754.62fc: 00007ff65053b000-00007ff65053bfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
3095754.62fc: 00007ff65053c000-00007ff650583fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
3105754.62fc: 00007ff650584000-00007ffc79f7ffff 0x0001/0x0000 0x0000000
3115754.62fc: *00007ffc79f80000-00007ffc79f8ffff 0x0020/0x0040 0x0020000 !!
3125754.62fc: 00007ffc79f90000-00007ffc84faffff 0x0001/0x0000 0x0000000
3135754.62fc: *00007ffc84fb0000-00007ffc84fb0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Avast Software\Avast\aswhook.dll
3145754.62fc: supHardNtVpScanVirtualMemory: Ignoring unknown mem at 00007ffc84fb0000 LB 0x1000 (base 00007ffc84fb0000) - 'aswhook.dll'
3155754.62fc: 00007ffc84fb1000-00007ffc84fbcfff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Avast Software\Avast\aswhook.dll
3165754.62fc: supHardNtVpScanVirtualMemory: Ignoring unknown mem at 00007ffc84fb1000 LB 0xc000 (base 00007ffc84fb0000) - 'aswhook.dll'
3175754.62fc: 00007ffc84fbd000-00007ffc84fbffff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Avast Software\Avast\aswhook.dll
3185754.62fc: supHardNtVpScanVirtualMemory: Ignoring unknown mem at 00007ffc84fbd000 LB 0x3000 (base 00007ffc84fb0000) - 'aswhook.dll'
3195754.62fc: 00007ffc84fc0000-00007ffc84fc1fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Avast Software\Avast\aswhook.dll
3205754.62fc: supHardNtVpScanVirtualMemory: Ignoring unknown mem at 00007ffc84fc0000 LB 0x2000 (base 00007ffc84fb0000) - 'aswhook.dll'
3215754.62fc: 00007ffc84fc2000-00007ffc84fc5fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Avast Software\Avast\aswhook.dll
3225754.62fc: supHardNtVpScanVirtualMemory: Ignoring unknown mem at 00007ffc84fc2000 LB 0x4000 (base 00007ffc84fb0000) - 'aswhook.dll'
3235754.62fc: 00007ffc84fc6000-00007ffc84fc6fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Avast Software\Avast\aswhook.dll
3245754.62fc: supHardNtVpScanVirtualMemory: Ignoring unknown mem at 00007ffc84fc6000 LB 0x1000 (base 00007ffc84fb0000) - 'aswhook.dll'
3255754.62fc: 00007ffc84fc7000-00007ffc84fc8fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Avast Software\Avast\aswhook.dll
3265754.62fc: supHardNtVpScanVirtualMemory: Ignoring unknown mem at 00007ffc84fc7000 LB 0x2000 (base 00007ffc84fb0000) - 'aswhook.dll'
3275754.62fc: 00007ffc84fc9000-00007ffcb74dffff 0x0001/0x0000 0x0000000
3285754.62fc: *00007ffcb74e0000-00007ffcb74e0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\KernelBase.dll
3295754.62fc: 00007ffcb74e1000-00007ffcb7670fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\KernelBase.dll
3305754.62fc: 00007ffcb7671000-00007ffcb7835fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\KernelBase.dll
3315754.62fc: 00007ffcb7836000-00007ffcb783afff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\KernelBase.dll
3325754.62fc: 00007ffcb783b000-00007ffcb7886fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\KernelBase.dll
3335754.62fc: 00007ffcb7887000-00007ffcb87dffff 0x0001/0x0000 0x0000000
3345754.62fc: *00007ffcb87e0000-00007ffcb87e0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\kernel32.dll
3355754.62fc: 00007ffcb87e1000-00007ffcb8861fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\kernel32.dll
3365754.62fc: 00007ffcb8862000-00007ffcb8898fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\kernel32.dll
3375754.62fc: 00007ffcb8899000-00007ffcb8899fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\kernel32.dll
3385754.62fc: 00007ffcb889a000-00007ffcb889afff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\kernel32.dll
3395754.62fc: 00007ffcb889b000-00007ffcb88a3fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\kernel32.dll
3405754.62fc: 00007ffcb88a4000-00007ffcb9f0ffff 0x0001/0x0000 0x0000000
3415754.62fc: *00007ffcb9f10000-00007ffcb9f10fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
3425754.62fc: 00007ffcb9f11000-00007ffcba041fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
3435754.62fc: 00007ffcba042000-00007ffcba08ffff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
3445754.62fc: 00007ffcba090000-00007ffcba090fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
3455754.62fc: 00007ffcba091000-00007ffcba092fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
3465754.62fc: 00007ffcba093000-00007ffcba09bfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
3475754.62fc: 00007ffcba09c000-00007ffcba126fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
3485754.62fc: 00007ffcba127000-00007ffffffeffff 0x0001/0x0000 0x0000000
3495754.62fc: kernel32.dll: timestamp 0x6b8a5ea3 (rc=VINF_SUCCESS)
3505754.62fc: kernelbase.dll: timestamp 0x83efbeab (rc=VINF_SUCCESS)
3515754.62fc: VirtualBoxVM.exe: timestamp 0x65a53a70 (rc=VINF_SUCCESS)
3525754.62fc: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe: Signature #1/2: info status: 24202
3535754.62fc: '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
3545754.62fc: VirtualBoxVM.exe: Differences in section #7 (.00cfg) between file and memory:
3555754.62fc: 00007ff650543000 / 0x00d3000: 00 != f0
3565754.62fc: 00007ff650543001 / 0x00d3001: 0d != eb
3575754.62fc: 00007ff650543002 / 0x00d3002: 49 != f9
3585754.62fc: 00007ff650543003 / 0x00d3003: 50 != b9
3595754.62fc: 00007ff650543004 / 0x00d3004: f6 != fc
3605754.62fc: 00007ff650543008 / 0x00d3008: 00 != f0
3615754.62fc: 00007ff650543009 / 0x00d3009: 0d != eb
3625754.62fc: 00007ff65054300a / 0x00d300a: 49 != f9
3635754.62fc: 00007ff65054300b / 0x00d300b: 50 != b9
3645754.62fc: 00007ff65054300c / 0x00d300c: f6 != fc
3655754.62fc: 00007ff650543011 / 0x00d3011: aa != ed
3665754.62fc: 00007ff650543012 / 0x00d3012: 4d != f9
3675754.62fc: 00007ff650543013 / 0x00d3013: 50 != b9
3685754.62fc: 00007ff650543014 / 0x00d3014: f6 != fc
3695754.62fc: 00007ff650543018 / 0x00d3018: 50 != 30
3705754.62fc: 00007ff650543019 / 0x00d3019: aa != ed
3715754.62fc: 00007ff65054301a / 0x00d301a: 4d != f9
3725754.62fc: 00007ff65054301b / 0x00d301b: 50 != b9
3735754.62fc: 00007ff65054301c / 0x00d301c: f6 != fc
3745754.62fc: 00007ff650543020 / 0x00d3020: 50 != 30
3755754.62fc: 00007ff650543021 / 0x00d3021: aa != ed
3765754.62fc: 00007ff650543022 / 0x00d3022: 4d != f9
3775754.62fc: 00007ff650543023 / 0x00d3023: 50 != b9
3785754.62fc: 00007ff650543024 / 0x00d3024: f6 != fc
3795754.62fc: Restored 0x28 bytes of original file content at 00007ff650543000
3805754.62fc: VirtualBoxVM.exe: Differences in section #8 (.rsrc) between file and memory:
3815754.62fc: 00007ff6505825f4 / 0x01125f4: 00 != 50
3825754.62fc: 00007ff6505825f5 / 0x01125f5: 00 != 41
3835754.62fc: 00007ff6505825f6 / 0x01125f6: 00 != 44
3845754.62fc: 00007ff6505825f7 / 0x01125f7: 00 != 44
3855754.62fc: 00007ff6505825f8 / 0x01125f8: 00 != 49
3865754.62fc: 00007ff6505825f9 / 0x01125f9: 00 != 4e
3875754.62fc: 00007ff6505825fa / 0x01125fa: 00 != 47
3885754.62fc: 00007ff6505825fb / 0x01125fb: 00 != 58
3895754.62fc: 00007ff6505825fc / 0x01125fc: 00 != 58
3905754.62fc: 00007ff6505825fd / 0x01125fd: 00 != 50
3915754.62fc: 00007ff6505825fe / 0x01125fe: 00 != 41
3925754.62fc: 00007ff6505825ff / 0x01125ff: 00 != 44
3935754.62fc: Restored 0xa0c bytes of original file content at 00007ff6505825f4
3945754.62fc: '\Device\HarddiskVolume3\Windows\System32\ntdll.dll' has no imports
3955754.62fc: ntdll.dll: Differences in section #1 (.text) between file and memory:
3965754.62fc: 00007ffcb9f2e6f0 / 0x001e6f0: 48 != e9
3975754.62fc: 00007ffcb9f2e6f1 / 0x001e6f1: 89 != 43
3985754.62fc: 00007ffcb9f2e6f2 / 0x001e6f2: 5c != 1b
3995754.62fc: 00007ffcb9f2e6f3 / 0x001e6f3: 24 != 05
4005754.62fc: 00007ffcb9f2e6f4 / 0x001e6f4: 08 != c0
4015754.62fc: 00007ffcb9f2e6f5 / 0x001e6f5: 48 != cc
4025754.62fc: 00007ffcb9f2e6f6 / 0x001e6f6: 89 != cc
4035754.62fc: 00007ffcb9f2e6f7 / 0x001e6f7: 74 != cc
4045754.62fc: 00007ffcb9f2e6f8 / 0x001e6f8: 24 != cc
4055754.62fc: 00007ffcb9f2e6f9 / 0x001e6f9: 20 != cc
4065754.62fc: Restored 0x2000 bytes of original file content at 00007ffcb9f2d000
4075754.62fc: ntdll.dll: Differences in section #1 (.text) between file and memory:
4085754.62fc: 00007ffcb9f3a160 / 0x002a160: 48 != e9
4095754.62fc: 00007ffcb9f3a161 / 0x002a161: 89 != 33
4105754.62fc: 00007ffcb9f3a162 / 0x002a162: 5c != 61
4115754.62fc: 00007ffcb9f3a163 / 0x002a163: 24 != 04
4125754.62fc: 00007ffcb9f3a164 / 0x002a164: 10 != c0
4135754.62fc: 00007ffcb9f3a165 / 0x002a165: 56 != cc
4145754.62fc: Restored 0x2000 bytes of original file content at 00007ffcb9f39000
4155754.62fc: ntdll.dll: Differences in section #1 (.text) between file and memory:
4165754.62fc: 00007ffcb9f94500 / 0x0084500: 45 != e9
4175754.62fc: 00007ffcb9f94501 / 0x0084501: 33 != 73
4185754.62fc: 00007ffcb9f94502 / 0x0084502: c0 != bc
4195754.62fc: 00007ffcb9f94503 / 0x0084503: e9 != fe
4205754.62fc: 00007ffcb9f94504 / 0x0084504: 08 != bf
4215754.62fc: 00007ffcb9f94505 / 0x0084505: 00 != cc
4225754.62fc: 00007ffcb9f94506 / 0x0084506: 00 != cc
4235754.62fc: 00007ffcb9f94507 / 0x0084507: 00 != cc
4245754.62fc: Restored 0x2000 bytes of original file content at 00007ffcb9f93dce
4255754.62fc: ntdll.dll: Differences in section #1 (.text) between file and memory:
4265754.62fc: 00007ffcba011840 / 0x0101840: 48 != e9
4275754.62fc: 00007ffcba011841 / 0x0101841: 89 != 93
4285754.62fc: 00007ffcba011842 / 0x0101842: 5c != e9
4295754.62fc: 00007ffcba011843 / 0x0101843: 24 != f6
4305754.62fc: 00007ffcba011844 / 0x0101844: 08 != bf
4315754.62fc: 00007ffcba011845 / 0x0101845: 48 != cc
4325754.62fc: 00007ffcba011846 / 0x0101846: 89 != cc
4335754.62fc: 00007ffcba011847 / 0x0101847: 74 != cc
4345754.62fc: 00007ffcba011848 / 0x0101848: 24 != cc
4355754.62fc: 00007ffcba011849 / 0x0101849: 10 != cc
4365754.62fc: Restored 0x2000 bytes of original file content at 00007ffcba00f9ce
4375754.62fc: ntdll.dll: Differences in section #9 (.00cfg) between file and memory:
4385754.62fc: 00007ffcba0af000 / 0x019f000: 00 != 30
4395754.62fc: 00007ffcba0af001 / 0x019f001: 36 != ed
4405754.62fc: 00007ffcba0af002 / 0x019f002: fb != f9
4415754.62fc: 00007ffcba0af008 / 0x019f008: e0 != f0
4425754.62fc: 00007ffcba0af009 / 0x019f009: ea != eb
4435754.62fc: 00007ffcba0af010 / 0x019f010: 20 != 30
4445754.62fc: 00007ffcba0af011 / 0x019f011: 36 != ed
4455754.62fc: 00007ffcba0af012 / 0x019f012: fb != f9
4465754.62fc: 00007ffcba0af018 / 0x019f018: 20 != 30
4475754.62fc: 00007ffcba0af019 / 0x019f019: 36 != ed
4485754.62fc: 00007ffcba0af01a / 0x019f01a: fb != f9
4495754.62fc: Restored 0x28 bytes of original file content at 00007ffcba0af000
4505754.62fc: kernel32.dll: Differences in section #2 (.rdata) between file and memory:
4515754.62fc: 00007ffcb88666c8 / 0x00866c8: 70 != f0
4525754.62fc: 00007ffcb88666c9 / 0x00866c9: ff != eb
4535754.62fc: 00007ffcb88666ca / 0x00866ca: 7f != f9
4545754.62fc: 00007ffcb88666cb / 0x00866cb: b8 != b9
4555754.62fc: 00007ffcb88666d0 / 0x00866d0: 90 != 30
4565754.62fc: 00007ffcb88666d1 / 0x00866d1: 41 != ed
4575754.62fc: 00007ffcb88666d2 / 0x00866d2: 80 != f9
4585754.62fc: 00007ffcb88666d3 / 0x00866d3: b8 != b9
4595754.62fc: 00007ffcb88666d8 / 0x00866d8: 70 != f0
4605754.62fc: 00007ffcb88666d9 / 0x00866d9: ff != eb
4615754.62fc: 00007ffcb88666da / 0x00866da: 7f != f9
4625754.62fc: 00007ffcb88666db / 0x00866db: b8 != b9
4635754.62fc: 00007ffcb88666e0 / 0x00866e0: b0 != 30
4645754.62fc: 00007ffcb88666e1 / 0x00866e1: 41 != ed
4655754.62fc: 00007ffcb88666e2 / 0x00866e2: 80 != f9
4665754.62fc: 00007ffcb88666e3 / 0x00866e3: b8 != b9
4675754.62fc: 00007ffcb88666e8 / 0x00866e8: b0 != 30
4685754.62fc: 00007ffcb88666e9 / 0x00866e9: 41 != ed
4695754.62fc: 00007ffcb88666ea / 0x00866ea: 80 != f9
4705754.62fc: 00007ffcb88666eb / 0x00866eb: b8 != b9
4715754.62fc: Restored 0x2000 bytes of original file content at 00007ffcb8866000
4725754.62fc: kernelbase.dll: Differences in section #2 (.rdata) between file and memory:
4735754.62fc: 00007ffcb7741878 / 0x0261878: 50 != f0
4745754.62fc: 00007ffcb7741879 / 0x0261879: 4b != eb
4755754.62fc: 00007ffcb774187a / 0x026187a: 5a != f9
4765754.62fc: 00007ffcb774187b / 0x026187b: b7 != b9
4775754.62fc: 00007ffcb7741880 / 0x0261880: 00 != 30
4785754.62fc: 00007ffcb7741881 / 0x0261881: 4f != ed
4795754.62fc: 00007ffcb7741882 / 0x0261882: 5a != f9
4805754.62fc: 00007ffcb7741883 / 0x0261883: b7 != b9
4815754.62fc: 00007ffcb7741888 / 0x0261888: 50 != f0
4825754.62fc: 00007ffcb7741889 / 0x0261889: 4b != eb
4835754.62fc: 00007ffcb774188a / 0x026188a: 5a != f9
4845754.62fc: 00007ffcb774188b / 0x026188b: b7 != b9
4855754.62fc: 00007ffcb7741890 / 0x0261890: 20 != 30
4865754.62fc: 00007ffcb7741891 / 0x0261891: 4f != ed
4875754.62fc: 00007ffcb7741892 / 0x0261892: 5a != f9
4885754.62fc: 00007ffcb7741893 / 0x0261893: b7 != b9
4895754.62fc: 00007ffcb7741898 / 0x0261898: 20 != 30
4905754.62fc: 00007ffcb7741899 / 0x0261899: 4f != ed
4915754.62fc: 00007ffcb774189a / 0x026189a: 5a != f9
4925754.62fc: 00007ffcb774189b / 0x026189b: b7 != b9
4935754.62fc: Restored 0x2000 bytes of original file content at 00007ffcb7741000
4945754.62fc: supHardNtVpCheckHandles:
4955754.62fc: supHardNtVpCheckHandles: Marked Mutant handle non-inheritable: 0000000000002aa4
4965754.62fc: supR3HardenedWinInit: SUPHARDNTVPKIND_SELF_PURIFICATION_LIMITED -> VINF_SUCCESS, cFixes=10
4975754.62fc: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe: Signature #1/2: info status: 24202
4985754.62fc: '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
4995754.62fc: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe)
5005754.62fc: supR3HardNtEnableThreadCreationEx:
5015754.62fc: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffcb9f83dc0 pvNtTerminateThread=00007ffcb9fb03a0
5025754.62fc: supR3HardenedWinDoReSpawn(1): New child 2968.6b30 [kernel32].
5035754.62fc: supR3HardNtChildGatherData: PebBaseAddress=000000a3df71e000 cbPeb=0x388
5045754.62fc: supR3HardNtPuChFindNtdll: uNtDllParentAddr=00007ffcb9f10000 uNtDllChildAddr=00007ffcb9f10000
5055754.62fc: supR3HardenedWinSetupChildInit: uLdrInitThunk=00007ffcb9f83dc0
5065754.62fc: supR3HardenedWinSetupChildInit: Initial context:
507 rax=0000000000000000 rbx=0000000000000000 rcx=00007ff65047b7a0 rdx=000000a3df71e000
508 rsi=0000000000000000 rdi=0000000000000000 r8 =0000000000000000 r9 =0000000000000000
509 r10=0000000000000000 r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
510 r14=0000000000000000 r15=0000000000000000 P1=0000000000000000 P2=0000000000000000
511 rip=00007ffcb9f6aa20 rsp=000000a3df52ffd8 rbp=0000000000000000 ctxflags=0010001b
512 cs=0033 ss=002b ds=0000 es=0000 fs=0000 gs=0000 eflags=00000200 mxcrx=00001f80
513 P3=0000000000000000 P4=0000000000000000 P5=0000000000000000 P6=0000000000000000
514 dr0=0000000000000000 dr1=0000000000000000 dr2=0000000000000000 dr3=0000000000000000
515 dr6=0000000000000000 dr7=0000000000000000 vcr=0000000000000000 dcr=0000000000000000
516 lbt=0000000000000000 lbf=0000000000000000 lxt=0000000000000000 lxf=0000000000000000
5175754.62fc: supR3HardenedWinSetupChildInit: Start child.
5185754.62fc: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
5195754.62fc: supR3HardNtChildPurify: Startup delay kludge #1/0: 525 ms, 34 sleeps
5205754.62fc: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
5215754.62fc: *0000000000000000-000000007ffdffff 0x0001/0x0000 0x0000000
5225754.62fc: *000000007ffe0000-000000007ffe0fff 0x0002/0x0002 0x0020000
5235754.62fc: 000000007ffe1000-000000007ffeefff 0x0001/0x0000 0x0000000
5245754.62fc: *000000007ffef000-000000007ffeffff 0x0002/0x0002 0x0020000
5255754.62fc: 000000007fff0000-000000a3df42ffff 0x0001/0x0000 0x0000000
5265754.62fc: *000000a3df430000-000000a3df52afff 0x0000/0x0004 0x0020000
5275754.62fc: 000000a3df52b000-000000a3df52dfff 0x0104/0x0004 0x0020000
5285754.62fc: 000000a3df52e000-000000a3df52ffff 0x0004/0x0004 0x0020000
5295754.62fc: 000000a3df530000-000000a3df5fffff 0x0001/0x0000 0x0000000
5305754.62fc: *000000a3df600000-000000a3df71dfff 0x0000/0x0004 0x0020000
5315754.62fc: 000000a3df71e000-000000a3df720fff 0x0004/0x0004 0x0020000
5325754.62fc: 000000a3df721000-000000a3df7fffff 0x0000/0x0004 0x0020000
5335754.62fc: 000000a3df800000-000001a8ffb4ffff 0x0001/0x0000 0x0000000
5345754.62fc: *000001a8ffb50000-000001a8ffb6ffff 0x0004/0x0004 0x0020000
5355754.62fc: *000001a8ffb70000-000001a8ffb8efff 0x0002/0x0002 0x0040000
5365754.62fc: 000001a8ffb8f000-000001a8ffb8ffff 0x0001/0x0000 0x0000000
5375754.62fc: *000001a8ffb90000-000001a8ffb90fff 0x0020/0x0020 0x0040000 !!
5385754.62fc: supHardNtVpScanVirtualMemory: Unmapping exec mem at 000001a8ffb90000 (000001a8ffb90000/000001a8ffb90000 LB 0x1000)
5395754.62fc: 000001a8ffb91000-000001a8ffb9ffff 0x0001/0x0000 0x0000000
5405754.62fc: *000001a8ffba0000-000001a8ffba3fff 0x0002/0x0002 0x0040000
5415754.62fc: 000001a8ffba4000-000001a8ffbaffff 0x0001/0x0000 0x0000000
5425754.62fc: *000001a8ffbb0000-000001a8ffbb0fff 0x0002/0x0002 0x0040000
5435754.62fc: 000001a8ffbb1000-000001a8ffbbffff 0x0001/0x0000 0x0000000
5445754.62fc: *000001a8ffbc0000-000001a8ffbc1fff 0x0004/0x0004 0x0020000
5455754.62fc: 000001a8ffbc2000-00007df5d32bffff 0x0001/0x0000 0x0000000
5465754.62fc: *00007df5d32c0000-00007df5d32c0fff 0x0002/0x0002 0x0040000
5475754.62fc: 00007df5d32c1000-00007df5d32cffff 0x0001/0x0000 0x0000000
5485754.62fc: *00007df5d32d0000-00007df5d484dfff 0x0000/0x0001 0x0040000
5495754.62fc: 00007df5d484e000-00007df5d48bafff 0x0001/0x0001 0x0040000
5505754.62fc: 00007df5d48bb000-00007df5d50b8fff 0x0000/0x0001 0x0040000
5515754.62fc: 00007df5d50b9000-00007df5d50b9fff 0x0001/0x0001 0x0040000
5525754.62fc: 00007df5d50ba000-00007dfc772bdfff 0x0000/0x0001 0x0040000
5535754.62fc: 00007dfc772be000-00007dfc772befff 0x0002/0x0001 0x0040000
5545754.62fc: 00007dfc772bf000-00007ff5ac6e0fff 0x0000/0x0001 0x0040000
5555754.62fc: 00007ff5ac6e1000-00007ff5ac6e6fff 0x0002/0x0001 0x0040000
5565754.62fc: 00007ff5ac6e7000-00007ff5c24cbfff 0x0000/0x0001 0x0040000
5575754.62fc: 00007ff5c24cc000-00007ff5c614bfff 0x0001/0x0001 0x0040000
5585754.62fc: 00007ff5c614c000-00007ff5c6154fff 0x0002/0x0001 0x0040000
5595754.62fc: 00007ff5c6155000-00007ff5d32cffff 0x0000/0x0001 0x0040000
5605754.62fc: 00007ff5d32d0000-00007ff65046ffff 0x0001/0x0000 0x0000000
5615754.62fc: *00007ff650470000-00007ff650470fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
5625754.62fc: 00007ff650471000-00007ff6504dafff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
5635754.62fc: 00007ff6504db000-00007ff6504dbfff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
5645754.62fc: 00007ff6504dc000-00007ff65052efff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
5655754.62fc: 00007ff65052f000-00007ff65052ffff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
5665754.62fc: 00007ff650530000-00007ff650530fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
5675754.62fc: 00007ff650531000-00007ff650535fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
5685754.62fc: 00007ff650536000-00007ff65053bfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
5695754.62fc: 00007ff65053c000-00007ff650583fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
5705754.62fc: 00007ff650584000-00007ffcb9f0ffff 0x0001/0x0000 0x0000000
5715754.62fc: *00007ffcb9f10000-00007ffcb9f10fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
5725754.62fc: 00007ffcb9f11000-00007ffcba041fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
5735754.62fc: 00007ffcba042000-00007ffcba08ffff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
5745754.62fc: 00007ffcba090000-00007ffcba09bfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
5755754.62fc: 00007ffcba09c000-00007ffcba0aafff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
5765754.62fc: 00007ffcba0ab000-00007ffcba0abfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
5775754.62fc: 00007ffcba0ac000-00007ffcba0aefff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
5785754.62fc: 00007ffcba0af000-00007ffcba126fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
5795754.62fc: 00007ffcba127000-00007ffffffeffff 0x0001/0x0000 0x0000000
5805754.62fc: VirtualBoxVM.exe: Differences in section #8 (.rsrc) between file and memory:
5815754.62fc: 00007ff6505825f4 / 0x01125f4: 00 != 50
5825754.62fc: 00007ff6505825f5 / 0x01125f5: 00 != 41
5835754.62fc: 00007ff6505825f6 / 0x01125f6: 00 != 44
5845754.62fc: 00007ff6505825f7 / 0x01125f7: 00 != 44
5855754.62fc: 00007ff6505825f8 / 0x01125f8: 00 != 49
5865754.62fc: 00007ff6505825f9 / 0x01125f9: 00 != 4e
5875754.62fc: 00007ff6505825fa / 0x01125fa: 00 != 47
5885754.62fc: 00007ff6505825fb / 0x01125fb: 00 != 58
5895754.62fc: 00007ff6505825fc / 0x01125fc: 00 != 58
5905754.62fc: 00007ff6505825fd / 0x01125fd: 00 != 50
5915754.62fc: 00007ff6505825fe / 0x01125fe: 00 != 41
5925754.62fc: 00007ff6505825ff / 0x01125ff: 00 != 44
5935754.62fc: Restored 0xa0c bytes of original file content at 00007ff6505825f4
5945754.62fc: supR3HardNtChildPurify: cFixes=2 g_fSupAdversaries=0x4
5955754.62fc: supR3HardNtChildPurify: Startup delay kludge #1/1: 527 ms, 34 sleeps
5965754.62fc: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
5975754.62fc: *0000000000000000-000000007ffdffff 0x0001/0x0000 0x0000000
5985754.62fc: *000000007ffe0000-000000007ffe0fff 0x0002/0x0002 0x0020000
5995754.62fc: 000000007ffe1000-000000007ffeefff 0x0001/0x0000 0x0000000
6005754.62fc: *000000007ffef000-000000007ffeffff 0x0002/0x0002 0x0020000
6015754.62fc: 000000007fff0000-000000a3df42ffff 0x0001/0x0000 0x0000000
6025754.62fc: *000000a3df430000-000000a3df52afff 0x0000/0x0004 0x0020000
6035754.62fc: 000000a3df52b000-000000a3df52dfff 0x0104/0x0004 0x0020000
6045754.62fc: 000000a3df52e000-000000a3df52ffff 0x0004/0x0004 0x0020000
6055754.62fc: 000000a3df530000-000000a3df5fffff 0x0001/0x0000 0x0000000
6065754.62fc: *000000a3df600000-000000a3df71dfff 0x0000/0x0004 0x0020000
6075754.62fc: 000000a3df71e000-000000a3df720fff 0x0004/0x0004 0x0020000
6085754.62fc: 000000a3df721000-000000a3df7fffff 0x0000/0x0004 0x0020000
6095754.62fc: 000000a3df800000-000001a8ffb4ffff 0x0001/0x0000 0x0000000
6105754.62fc: *000001a8ffb50000-000001a8ffb6ffff 0x0004/0x0004 0x0020000
6115754.62fc: *000001a8ffb70000-000001a8ffb8efff 0x0002/0x0002 0x0040000
6125754.62fc: 000001a8ffb8f000-000001a8ffb9ffff 0x0001/0x0000 0x0000000
6135754.62fc: *000001a8ffba0000-000001a8ffba3fff 0x0002/0x0002 0x0040000
6145754.62fc: 000001a8ffba4000-000001a8ffbaffff 0x0001/0x0000 0x0000000
6155754.62fc: *000001a8ffbb0000-000001a8ffbb0fff 0x0002/0x0002 0x0040000
6165754.62fc: 000001a8ffbb1000-000001a8ffbbffff 0x0001/0x0000 0x0000000
6175754.62fc: *000001a8ffbc0000-000001a8ffbc1fff 0x0004/0x0004 0x0020000
6185754.62fc: 000001a8ffbc2000-00007df5d32bffff 0x0001/0x0000 0x0000000
6195754.62fc: *00007df5d32c0000-00007df5d32c0fff 0x0002/0x0002 0x0040000
6205754.62fc: 00007df5d32c1000-00007df5d32cffff 0x0001/0x0000 0x0000000
6215754.62fc: *00007df5d32d0000-00007df5d484dfff 0x0000/0x0001 0x0040000
6225754.62fc: 00007df5d484e000-00007df5d48bafff 0x0001/0x0001 0x0040000
6235754.62fc: 00007df5d48bb000-00007df5d50b8fff 0x0000/0x0001 0x0040000
6245754.62fc: 00007df5d50b9000-00007df5d50b9fff 0x0001/0x0001 0x0040000
6255754.62fc: 00007df5d50ba000-00007dfc772bdfff 0x0000/0x0001 0x0040000
6265754.62fc: 00007dfc772be000-00007dfc772befff 0x0002/0x0001 0x0040000
6275754.62fc: 00007dfc772bf000-00007ff5ac6e0fff 0x0000/0x0001 0x0040000
6285754.62fc: 00007ff5ac6e1000-00007ff5ac6e6fff 0x0002/0x0001 0x0040000
6295754.62fc: 00007ff5ac6e7000-00007ff5c24cbfff 0x0000/0x0001 0x0040000
6305754.62fc: 00007ff5c24cc000-00007ff5c614bfff 0x0001/0x0001 0x0040000
6315754.62fc: 00007ff5c614c000-00007ff5c6154fff 0x0002/0x0001 0x0040000
6325754.62fc: 00007ff5c6155000-00007ff5d32cffff 0x0000/0x0001 0x0040000
6335754.62fc: 00007ff5d32d0000-00007ff65046ffff 0x0001/0x0000 0x0000000
6345754.62fc: *00007ff650470000-00007ff650470fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
6355754.62fc: 00007ff650471000-00007ff6504dafff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
6365754.62fc: 00007ff6504db000-00007ff6504dbfff 0x0040/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
6375754.62fc: 00007ff6504dc000-00007ff65052efff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
6385754.62fc: 00007ff65052f000-00007ff65053bfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
6395754.62fc: 00007ff65053c000-00007ff650583fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
6405754.62fc: 00007ff650584000-00007ffcb9f0ffff 0x0001/0x0000 0x0000000
6415754.62fc: *00007ffcb9f10000-00007ffcb9f10fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
6425754.62fc: 00007ffcb9f11000-00007ffcba041fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
6435754.62fc: 00007ffcba042000-00007ffcba08ffff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
6445754.62fc: 00007ffcba090000-00007ffcba093fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
6455754.62fc: 00007ffcba094000-00007ffcba09bfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
6465754.62fc: 00007ffcba09c000-00007ffcba0aafff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
6475754.62fc: 00007ffcba0ab000-00007ffcba0abfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
6485754.62fc: 00007ffcba0ac000-00007ffcba0aefff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
6495754.62fc: 00007ffcba0af000-00007ffcba126fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
6505754.62fc: 00007ffcba127000-00007ffffffeffff 0x0001/0x0000 0x0000000
6515754.62fc: supR3HardNtChildPurify: Done after 1063 ms and 2 fixes (loop #1).
6522968.6b30: supR3HardenedVmProcessInit: uNtDllAddr=00007ffcb9f10000 g_uNtVerCombined=0xa0586700 (stack ~000000a3df52eda0)
6532968.6b30: ntdll.dll: timestamp 0x92b2df34 (rc=VINF_SUCCESS)
6542968.6b30: New simple heap: #1 000001a880000000 LB 0x800000 (for 2191360 allocation)
6555754.62fc: supR3HardNtEnableThreadCreationEx:
6562968.6b30: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox'
6572968.6b30: System32: \Device\HarddiskVolume3\Windows\System32
6582968.6b30: WinSxS: \Device\HarddiskVolume3\Windows\WinSxS
6592968.6b30: KnownDllPath: C:\WINDOWS\System32
6602968.6b30: supR3HardenedVmProcessInit: Opening vboxsup stub...
6612968.6b30: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
6622968.6b30: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
6632968.6b30: Registered Dll notification callback with NTDLL.
6642968.6b30: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\kernel32.dll)
6652968.6b30: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\kernel32.dll
6662968.6b30: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\KERNEL32.DLL (Input=KERNEL32.DLL, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000004001:<flags> [calling]
6672968.6b30: supR3HardenedMonitor_KiUserApcDispatcher_C: pfnRoutine=000001a8ffb90088 enmState=3 -> supR3HardenedWinDummyApcRoutine
6682968.6b30: supR3HardenedWinDummyApcRoutine: pvArg1=000001a8ffb90000 pvArg2=0000000000000000 pvArg3=0000000000000000
6692968.6b30: supR3HardenedDllNotificationCallback: load 00007ffcb74e0000 LB 0x003a7000 C:\WINDOWS\System32\KERNELBASE.dll [fFlags=0x0]
6702968.6b30: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\KernelBase.dll)
6712968.6b30: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\KernelBase.dll
6722968.6b30: supR3HardenedDllNotificationCallback: load 00007ffcb87e0000 LB 0x000c4000 C:\WINDOWS\System32\KERNEL32.DLL [fFlags=0x0]
6732968.6b30: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
6742968.6b30: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb87e0000 'C:\WINDOWS\System32\KERNEL32.DLL'
6752968.6b30: supR3HardenedDllNotificationCallback: load 00007ff650470000 LB 0x00114000 C:\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe [fFlags=0x0]
6762968.6b30: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe: Signature #1/2: info status: 24202
6772968.6b30: '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
6782968.6b30: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe)
6792968.6b30: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
6802968.6b30: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffcb9f83dc0 pvNtTerminateThread=00007ffcb9fb03a0
6815754.62fc: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 57 ms.
6822968.6b30: \SystemRoot\System32\ntdll.dll:
6832968.6b30: CreationTime: 2024-04-25T21:50:52.933474100Z
6842968.6b30: LastWriteTime: 2024-04-25T21:50:52.967360700Z
6852968.6b30: ChangeTime: 2024-04-25T22:15:47.894551900Z
6862968.6b30: FileAttributes: 0x20
6872968.6b30: Size: 0x216008
6882968.6b30: NT Headers: 0xe8
6892968.6b30: Timestamp: 0x92b2df34
6902968.6b30: Machine: 0x8664 - amd64
6912968.6b30: Timestamp: 0x92b2df34
6922968.6b30: Image Version: 10.0
6932968.6b30: SizeOfImage: 0x217000 (2191360)
6942968.6b30: Resource Dir: 0x1a0000 LB 0x759a8
6952968.6b30: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
6962968.6b30: [Raw version resource data: 0x1a00f0 LB 0x380, codepage 0x0 (reserved 0x0)]
6972968.6b30: ProductName: Microsoft® Windows® Operating System
6982968.6b30: ProductVersion: 10.0.22621.3527
6992968.6b30: FileVersion: 10.0.22621.3527 (WinBuild.160101.0800)
7002968.6b30: FileDescription: NT Layer DLL
7012968.6b30: \SystemRoot\System32\kernel32.dll:
7022968.6b30: CreationTime: 2024-04-25T21:50:52.649892600Z
7032968.6b30: LastWriteTime: 2024-04-25T21:50:52.664841500Z
7042968.6b30: ChangeTime: 2024-04-25T22:15:37.505042500Z
7052968.6b30: FileAttributes: 0x20
7062968.6b30: Size: 0xc7158
7072968.6b30: NT Headers: 0xe8
7082968.6b30: Timestamp: 0x6b8a5ea3
7092968.6b30: Machine: 0x8664 - amd64
7102968.6b30: Timestamp: 0x6b8a5ea3
7112968.6b30: Image Version: 10.0
7122968.6b30: SizeOfImage: 0xc4000 (802816)
7132968.6b30: Resource Dir: 0xc2000 LB 0x520
7142968.6b30: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
7152968.6b30: [Raw version resource data: 0xc20b0 LB 0x3a4, codepage 0x0 (reserved 0x0)]
7162968.6b30: ProductName: Microsoft® Windows® Operating System
7172968.6b30: ProductVersion: 10.0.22621.3527
7182968.6b30: FileVersion: 10.0.22621.3527 (WinBuild.160101.0800)
7192968.6b30: FileDescription: Windows NT BASE API Client DLL
7202968.6b30: \SystemRoot\System32\KernelBase.dll:
7212968.6b30: CreationTime: 2024-04-25T21:50:53.507611100Z
7222968.6b30: LastWriteTime: 2024-04-25T21:50:53.604794300Z
7232968.6b30: ChangeTime: 2024-04-25T22:15:45.722906700Z
7242968.6b30: FileAttributes: 0x20
7252968.6b30: Size: 0x3ae908
7262968.6b30: NT Headers: 0xf8
7272968.6b30: Timestamp: 0x83efbeab
7282968.6b30: Machine: 0x8664 - amd64
7292968.6b30: Timestamp: 0x83efbeab
7302968.6b30: Image Version: 10.0
7312968.6b30: SizeOfImage: 0x3a7000 (3829760)
7322968.6b30: Resource Dir: 0x376000 LB 0x548
7332968.6b30: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
7342968.6b30: [Raw version resource data: 0x3760b0 LB 0x3bc, codepage 0x0 (reserved 0x0)]
7352968.6b30: ProductName: Microsoft® Windows® Operating System
7362968.6b30: ProductVersion: 10.0.22621.3527
7372968.6b30: FileVersion: 10.0.22621.3527 (WinBuild.160101.0800)
7382968.6b30: FileDescription: Windows NT BASE API Client DLL
7392968.6b30: \SystemRoot\System32\apisetschema.dll:
7402968.6b30: CreationTime: 2024-04-25T21:50:27.205621000Z
7412968.6b30: LastWriteTime: 2024-04-25T21:50:27.208610400Z
7422968.6b30: ChangeTime: 2024-04-25T22:15:42.442010700Z
7432968.6b30: FileAttributes: 0x20
7442968.6b30: Size: 0x245e0
7452968.6b30: NT Headers: 0xc8
7462968.6b30: Timestamp: 0x2f79598b
7472968.6b30: Machine: 0x8664 - amd64
7482968.6b30: Timestamp: 0x2f79598b
7492968.6b30: Image Version: 10.0
7502968.6b30: SizeOfImage: 0x23000 (143360)
7512968.6b30: Resource Dir: 0x22000 LB 0x408
7522968.6b30: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
7532968.6b30: [Raw version resource data: 0x22060 LB 0x3a8, codepage 0x0 (reserved 0x0)]
7542968.6b30: ProductName: Microsoft® Windows® Operating System
7552968.6b30: ProductVersion: 10.0.22621.3527
7562968.6b30: FileVersion: 10.0.22621.3527 (WinBuild.160101.0800)
7572968.6b30: FileDescription: ApiSet Schema DLL
7582968.6b30: NtOpenDirectoryObject failed on \Driver: 0xc0000022
7592968.6b30: supR3HardenedWinFindAdversaries: 0x4
7602968.6b30: \SystemRoot\System32\drivers\aswMonFlt.sys:
7612968.6b30: CreationTime: 2022-11-24T10:33:09.488089900Z
7622968.6b30: LastWriteTime: 2024-04-12T01:45:56.269304300Z
7632968.6b30: ChangeTime: 2024-04-12T01:45:56.269304300Z
7642968.6b30: FileAttributes: 0x20
7652968.6b30: Size: 0x41a38
7662968.6b30: NT Headers: 0xf0
7672968.6b30: Timestamp: 0x660161d5
7682968.6b30: Machine: 0x8664 - amd64
7692968.6b30: Timestamp: 0x660161d5
7702968.6b30: Image Version: 10.0
7712968.6b30: SizeOfImage: 0x49000 (299008)
7722968.6b30: Resource Dir: 0x47000 LB 0x3b0
7732968.6b30: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
7742968.6b30: [Raw version resource data: 0x47058 LB 0x358, codepage 0x0 (reserved 0x0)]
7752968.6b30: ProductName: Antivirus
7762968.6b30: ProductVersion: 24.3.683.0
7772968.6b30: FileVersion: 24.3.683.0
7782968.6b30: FileDescription: Gen File System Filter
7792968.6b30: \SystemRoot\System32\drivers\aswRdr2.sys:
7802968.6b30: CreationTime: 2022-11-24T10:33:09.486096500Z
7812968.6b30: LastWriteTime: 2024-04-12T01:45:56.261304700Z
7822968.6b30: ChangeTime: 2024-04-12T01:45:56.261304700Z
7832968.6b30: FileAttributes: 0x20
7842968.6b30: Size: 0x16e38
7852968.6b30: NT Headers: 0xe8
7862968.6b30: Timestamp: 0x660161d2
7872968.6b30: Machine: 0x8664 - amd64
7882968.6b30: Timestamp: 0x660161d2
7892968.6b30: Image Version: 10.0
7902968.6b30: SizeOfImage: 0x1b000 (110592)
7912968.6b30: Resource Dir: 0x19000 LB 0x398
7922968.6b30: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
7932968.6b30: [Raw version resource data: 0x19058 LB 0x33c, codepage 0x0 (reserved 0x0)]
7942968.6b30: ProductName: Antivirus
7952968.6b30: ProductVersion: 24.3.683.0
7962968.6b30: FileVersion: 24.3.683.0
7972968.6b30: FileDescription: Gen Antivirus
7982968.6b30: \SystemRoot\System32\drivers\aswRvrt.sys:
7992968.6b30: CreationTime: 2022-11-24T10:33:09.489086600Z
8002968.6b30: LastWriteTime: 2024-04-12T01:45:56.277304500Z
8012968.6b30: ChangeTime: 2024-04-12T01:45:56.277304500Z
8022968.6b30: FileAttributes: 0x20
8032968.6b30: Size: 0x10e38
8042968.6b30: NT Headers: 0xe0
8052968.6b30: Timestamp: 0x660161cb
8062968.6b30: Machine: 0x8664 - amd64
8072968.6b30: Timestamp: 0x660161cb
8082968.6b30: Image Version: 10.0
8092968.6b30: SizeOfImage: 0x13000 (77824)
8102968.6b30: Resource Dir: 0x11000 LB 0x390
8112968.6b30: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
8122968.6b30: [Raw version resource data: 0x11058 LB 0x338, codepage 0x0 (reserved 0x0)]
8132968.6b30: ProductName: Antivirus
8142968.6b30: ProductVersion: 24.3.683.0
8152968.6b30: FileVersion: 24.3.683.0
8162968.6b30: FileDescription: Gen Revert
8172968.6b30: \SystemRoot\System32\drivers\aswSnx.sys:
8182968.6b30: CreationTime: 2022-11-24T10:33:09.480116700Z
8192968.6b30: LastWriteTime: 2024-04-12T01:45:53.466864800Z
8202968.6b30: ChangeTime: 2024-04-12T01:45:53.466864800Z
8212968.6b30: FileAttributes: 0x20
8222968.6b30: Size: 0xe4838
8232968.6b30: NT Headers: 0x100
8242968.6b30: Timestamp: 0x660161ff
8252968.6b30: Machine: 0x8664 - amd64
8262968.6b30: Timestamp: 0x660161ff
8272968.6b30: Image Version: 10.0
8282968.6b30: SizeOfImage: 0xe9000 (954368)
8292968.6b30: Resource Dir: 0xe6000 LB 0x3b0
8302968.6b30: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
8312968.6b30: [Raw version resource data: 0xe6058 LB 0x354, codepage 0x0 (reserved 0x0)]
8322968.6b30: ProductName: Antivirus
8332968.6b30: ProductVersion: 24.3.683.0
8342968.6b30: FileVersion: 24.3.683.0
8352968.6b30: FileDescription: Gen Virtualization Driver
8362968.6b30: \SystemRoot\System32\drivers\aswsp.sys:
8372968.6b30: CreationTime: 2022-11-24T10:33:09.490083300Z
8382968.6b30: LastWriteTime: 2024-04-12T01:45:56.288304000Z
8392968.6b30: ChangeTime: 2024-04-12T01:45:56.288304000Z
8402968.6b30: FileAttributes: 0x20
8412968.6b30: Size: 0xa9e38
8422968.6b30: NT Headers: 0xe8
8432968.6b30: Timestamp: 0x660161ed
8442968.6b30: Machine: 0x8664 - amd64
8452968.6b30: Timestamp: 0x660161ed
8462968.6b30: Image Version: 10.0
8472968.6b30: SizeOfImage: 0xb0000 (720896)
8482968.6b30: Resource Dir: 0xad000 LB 0x398
8492968.6b30: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
8502968.6b30: [Raw version resource data: 0xad058 LB 0x340, codepage 0x0 (reserved 0x0)]
8512968.6b30: ProductName: Antivirus
8522968.6b30: ProductVersion: 24.3.683.0
8532968.6b30: FileVersion: 24.3.683.0
8542968.6b30: FileDescription: Gen Self Protection
8552968.6b30: \SystemRoot\System32\drivers\aswStm.sys:
8562968.6b30: CreationTime: 2024-04-12T01:45:58.391309500Z
8572968.6b30: LastWriteTime: 2024-04-12T01:45:56.481310100Z
8582968.6b30: ChangeTime: 2024-04-12T01:45:56.481310100Z
8592968.6b30: FileAttributes: 0x20
8602968.6b30: Size: 0x31438
8612968.6b30: NT Headers: 0xf0
8622968.6b30: Timestamp: 0x66016201
8632968.6b30: Machine: 0x8664 - amd64
8642968.6b30: Timestamp: 0x66016201
8652968.6b30: Image Version: 10.0
8662968.6b30: SizeOfImage: 0x36000 (221184)
8672968.6b30: Resource Dir: 0x34000 LB 0x3a0
8682968.6b30: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
8692968.6b30: [Raw version resource data: 0x34058 LB 0x344, codepage 0x0 (reserved 0x0)]
8702968.6b30: ProductName: Antivirus
8712968.6b30: ProductVersion: 24.3.683.0
8722968.6b30: FileVersion: 24.3.683.0
8732968.6b30: FileDescription: Gen Stream Filter
8742968.6b30: \SystemRoot\System32\drivers\aswVmm.sys:
8752968.6b30: CreationTime: 2022-11-24T10:33:09.495066500Z
8762968.6b30: LastWriteTime: 2024-04-12T01:45:56.819309900Z
8772968.6b30: ChangeTime: 2024-04-12T01:45:56.819309900Z
8782968.6b30: FileAttributes: 0x20
8792968.6b30: Size: 0x4ac38
8802968.6b30: NT Headers: 0xe8
8812968.6b30: Timestamp: 0x660161d4
8822968.6b30: Machine: 0x8664 - amd64
8832968.6b30: Timestamp: 0x660161d4
8842968.6b30: Image Version: 10.0
8852968.6b30: SizeOfImage: 0x4d000 (315392)
8862968.6b30: Resource Dir: 0x4b000 LB 0x398
8872968.6b30: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
8882968.6b30: [Raw version resource data: 0x4b058 LB 0x340, codepage 0x0 (reserved 0x0)]
8892968.6b30: ProductName: Antivirus
8902968.6b30: ProductVersion: 24.3.683.0
8912968.6b30: FileVersion: 24.3.683.0
8922968.6b30: FileDescription: Gen VM Monitor
8932968.6b30: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox'
8942968.6b30: Calling main()
8952968.6b30: SUPR3HardenedMain: pszProgName=VirtualBoxVM fFlags=0x2
8962968.6b30: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox'
8972968.6b30: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe: Signature #1/2: info status: 24202
8982968.6b30: '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
8992968.6b30: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe)
9002968.6b30: SUPR3HardenedMain: Respawn #2
9012968.6b30: supR3HardNtEnableThreadCreationEx:
9022968.6b30: supR3HardenedDllNotificationCallback: load 00007ffcb7890000 LB 0x00028000 C:\WINDOWS\System32\bcrypt.dll [fFlags=0x0]
9032968.6b30: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\bcrypt.dll)
9042968.6b30: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\bcrypt.dll
9052968.6b30: supR3HardenedDllNotificationCallback: load 00007ffcb8900000 LB 0x000a8000 C:\WINDOWS\System32\sechost.dll [fFlags=0x0]
9062968.6b30: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #24 'bcrypt.dll'.
9072968.6b30: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\sechost.dll)
9082968.6b30: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\sechost.dll
9092968.6b30: '\Device\HarddiskVolume3\Windows\System32\ntdll.dll' has no imports
9102968.6b30: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\ntdll.dll)
9112968.6b30: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\ntdll.dll
9122968.6b30: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
9132968.6b30: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume3\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
9142968.6b30: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
9152968.6b30: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\ntdll.dll (Input=ntdll.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
9162968.6b30: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb9f10000 'C:\WINDOWS\System32\ntdll.dll'
9172968.6b30: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\KernelBase.dll [lacks WinVerifyTrust]
9182968.6b30: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\KernelBase.dll (Input=KernelBase, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
9192968.6b30: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb74e0000 'C:\WINDOWS\System32\KernelBase.dll'
9202968.6b30: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffcb9f83dc0 pvNtTerminateThread=00007ffcb9fb03a0
9212968.6b30: supR3HardenedWinDoReSpawn(2): New child 4ad4.60b4 [kernel32].
9222968.6b30: supR3HardenedWinReSpawn: NtSetInformationThread/ThreadHideFromDebugger failed: 0xc0000022 (harmless)
9232968.6b30: supR3HardNtChildGatherData: PebBaseAddress=000000c34e269000 cbPeb=0x388
9242968.6b30: supR3HardNtPuChFindNtdll: uNtDllParentAddr=00007ffcb9f10000 uNtDllChildAddr=00007ffcb9f10000
9252968.6b30: supR3HardenedWinSetupChildInit: uLdrInitThunk=00007ffcb9f83dc0
9262968.6b30: supR3HardenedWinSetupChildInit: Initial context:
927 rax=0000000000000000 rbx=0000000000000000 rcx=00007ff65047b7a0 rdx=000000c34e269000
928 rsi=0000000000000000 rdi=0000000000000000 r8 =0000000000000000 r9 =0000000000000000
929 r10=0000000000000000 r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
930 r14=0000000000000000 r15=0000000000000000 P1=0000000000000000 P2=0000000000000000
931 rip=00007ffcb9f6aa20 rsp=000000c34e1efcd8 rbp=0000000000000000 ctxflags=0010001b
932 cs=0033 ss=002b ds=0000 es=0000 fs=0000 gs=0000 eflags=00000200 mxcrx=00001f80
933 P3=0000000000000000 P4=0000000000000000 P5=0000000000000000 P6=0000000000000000
934 dr0=0000000000000000 dr1=0000000000000000 dr2=0000000000000000 dr3=0000000000000000
935 dr6=0000000000000000 dr7=0000000000000000 vcr=0000000000000000 dcr=0000000000000000
936 lbt=0000000000000000 lbf=0000000000000000 lxt=0000000000000000 lxf=0000000000000000
9372968.6b30: kernel32.dll: timestamp 0x6b8a5ea3 (rc=VINF_SUCCESS)
9382968.6b30: supR3HardenedWinSetupChildInit: Start child.
9392968.6b30: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
9402968.6b30: supR3HardNtChildPurify: Startup delay kludge #1/0: 524 ms, 33 sleeps
9412968.6b30: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
9422968.6b30: *0000000000000000-000000007ffdffff 0x0001/0x0000 0x0000000
9432968.6b30: *000000007ffe0000-000000007ffe0fff 0x0002/0x0002 0x0020000
9442968.6b30: 000000007ffe1000-000000007ffeefff 0x0001/0x0000 0x0000000
9452968.6b30: *000000007ffef000-000000007ffeffff 0x0002/0x0002 0x0020000
9462968.6b30: 000000007fff0000-000000c34e0effff 0x0001/0x0000 0x0000000
9472968.6b30: *000000c34e0f0000-000000c34e1eafff 0x0000/0x0004 0x0020000
9482968.6b30: 000000c34e1eb000-000000c34e1edfff 0x0104/0x0004 0x0020000
9492968.6b30: 000000c34e1ee000-000000c34e1effff 0x0004/0x0004 0x0020000
9502968.6b30: 000000c34e1f0000-000000c34e1fffff 0x0001/0x0000 0x0000000
9512968.6b30: *000000c34e200000-000000c34e268fff 0x0000/0x0004 0x0020000
9522968.6b30: 000000c34e269000-000000c34e26bfff 0x0004/0x0004 0x0020000
9532968.6b30: 000000c34e26c000-000000c34e3fffff 0x0000/0x0004 0x0020000
9542968.6b30: 000000c34e400000-0000029a0b78ffff 0x0001/0x0000 0x0000000
9552968.6b30: *0000029a0b790000-0000029a0b7affff 0x0004/0x0004 0x0020000
9562968.6b30: *0000029a0b7b0000-0000029a0b7cefff 0x0002/0x0002 0x0040000
9572968.6b30: 0000029a0b7cf000-0000029a0b7cffff 0x0001/0x0000 0x0000000
9582968.6b30: *0000029a0b7d0000-0000029a0b7d0fff 0x0020/0x0020 0x0040000 !!
9592968.6b30: supHardNtVpScanVirtualMemory: Unmapping exec mem at 0000029a0b7d0000 (0000029a0b7d0000/0000029a0b7d0000 LB 0x1000)
9602968.6b30: 0000029a0b7d1000-0000029a0b7dffff 0x0001/0x0000 0x0000000
9612968.6b30: *0000029a0b7e0000-0000029a0b7e3fff 0x0002/0x0002 0x0040000
9622968.6b30: 0000029a0b7e4000-0000029a0b7effff 0x0001/0x0000 0x0000000
9632968.6b30: *0000029a0b7f0000-0000029a0b7f0fff 0x0002/0x0002 0x0040000
9642968.6b30: 0000029a0b7f1000-0000029a0b7fffff 0x0001/0x0000 0x0000000
9652968.6b30: *0000029a0b800000-0000029a0b801fff 0x0004/0x0004 0x0020000
9662968.6b30: 0000029a0b802000-00007df5452dffff 0x0001/0x0000 0x0000000
9672968.6b30: *00007df5452e0000-00007df5452e0fff 0x0002/0x0002 0x0040000
9682968.6b30: 00007df5452e1000-00007df5452effff 0x0001/0x0000 0x0000000
9692968.6b30: *00007df5452f0000-00007df54686dfff 0x0000/0x0001 0x0040000
9702968.6b30: 00007df54686e000-00007df5468dafff 0x0001/0x0001 0x0040000
9712968.6b30: 00007df5468db000-00007df5470d8fff 0x0000/0x0001 0x0040000
9722968.6b30: 00007df5470d9000-00007df5470d9fff 0x0001/0x0001 0x0040000
9732968.6b30: 00007df5470da000-00007dffad5cefff 0x0000/0x0001 0x0040000
9742968.6b30: 00007dffad5cf000-00007dffad5cffff 0x0002/0x0001 0x0040000
9752968.6b30: 00007dffad5d0000-00007ff51e700fff 0x0000/0x0001 0x0040000
9762968.6b30: 00007ff51e701000-00007ff51e706fff 0x0002/0x0001 0x0040000
9772968.6b30: 00007ff51e707000-00007ff5344ebfff 0x0000/0x0001 0x0040000
9782968.6b30: 00007ff5344ec000-00007ff53816bfff 0x0001/0x0001 0x0040000
9792968.6b30: 00007ff53816c000-00007ff538174fff 0x0002/0x0001 0x0040000
9802968.6b30: 00007ff538175000-00007ff5452effff 0x0000/0x0001 0x0040000
9812968.6b30: 00007ff5452f0000-00007ff65046ffff 0x0001/0x0000 0x0000000
9822968.6b30: *00007ff650470000-00007ff650470fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
9832968.6b30: 00007ff650471000-00007ff6504dafff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
9842968.6b30: 00007ff6504db000-00007ff6504dbfff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
9852968.6b30: 00007ff6504dc000-00007ff65052efff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
9862968.6b30: 00007ff65052f000-00007ff65052ffff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
9872968.6b30: 00007ff650530000-00007ff650530fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
9882968.6b30: 00007ff650531000-00007ff650535fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
9892968.6b30: 00007ff650536000-00007ff65053bfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
9902968.6b30: 00007ff65053c000-00007ff650583fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
9912968.6b30: 00007ff650584000-00007ffcb9f0ffff 0x0001/0x0000 0x0000000
9922968.6b30: *00007ffcb9f10000-00007ffcb9f10fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
9932968.6b30: 00007ffcb9f11000-00007ffcba041fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
9942968.6b30: 00007ffcba042000-00007ffcba08ffff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
9952968.6b30: 00007ffcba090000-00007ffcba09bfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
9962968.6b30: 00007ffcba09c000-00007ffcba0aafff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
9972968.6b30: 00007ffcba0ab000-00007ffcba0abfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
9982968.6b30: 00007ffcba0ac000-00007ffcba0aefff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
9992968.6b30: 00007ffcba0af000-00007ffcba126fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
10002968.6b30: 00007ffcba127000-00007ffffffeffff 0x0001/0x0000 0x0000000
10012968.6b30: VirtualBoxVM.exe: timestamp 0x65a53a70 (rc=VINF_SUCCESS)
10022968.6b30: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe: Signature #1/2: info status: 24202
10032968.6b30: '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
10042968.6b30: VirtualBoxVM.exe: Differences in section #8 (.rsrc) between file and memory:
10052968.6b30: 00007ff6505825f4 / 0x01125f4: 00 != 50
10062968.6b30: 00007ff6505825f5 / 0x01125f5: 00 != 41
10072968.6b30: 00007ff6505825f6 / 0x01125f6: 00 != 44
10082968.6b30: 00007ff6505825f7 / 0x01125f7: 00 != 44
10092968.6b30: 00007ff6505825f8 / 0x01125f8: 00 != 49
10102968.6b30: 00007ff6505825f9 / 0x01125f9: 00 != 4e
10112968.6b30: 00007ff6505825fa / 0x01125fa: 00 != 47
10122968.6b30: 00007ff6505825fb / 0x01125fb: 00 != 58
10132968.6b30: 00007ff6505825fc / 0x01125fc: 00 != 58
10142968.6b30: 00007ff6505825fd / 0x01125fd: 00 != 50
10152968.6b30: 00007ff6505825fe / 0x01125fe: 00 != 41
10162968.6b30: 00007ff6505825ff / 0x01125ff: 00 != 44
10172968.6b30: Restored 0xa0c bytes of original file content at 00007ff6505825f4
10182968.6b30: '\Device\HarddiskVolume3\Windows\System32\ntdll.dll' has no imports
10192968.6b30: supR3HardNtChildPurify: cFixes=2 g_fSupAdversaries=0x4
10202968.6b30: supR3HardNtChildPurify: Startup delay kludge #1/1: 520 ms, 33 sleeps
10212968.6b30: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
10222968.6b30: *0000000000000000-000000007ffdffff 0x0001/0x0000 0x0000000
10232968.6b30: *000000007ffe0000-000000007ffe0fff 0x0002/0x0002 0x0020000
10242968.6b30: 000000007ffe1000-000000007ffeefff 0x0001/0x0000 0x0000000
10252968.6b30: *000000007ffef000-000000007ffeffff 0x0002/0x0002 0x0020000
10262968.6b30: 000000007fff0000-000000c34e0effff 0x0001/0x0000 0x0000000
10272968.6b30: *000000c34e0f0000-000000c34e1eafff 0x0000/0x0004 0x0020000
10282968.6b30: 000000c34e1eb000-000000c34e1edfff 0x0104/0x0004 0x0020000
10292968.6b30: 000000c34e1ee000-000000c34e1effff 0x0004/0x0004 0x0020000
10302968.6b30: 000000c34e1f0000-000000c34e1fffff 0x0001/0x0000 0x0000000
10312968.6b30: *000000c34e200000-000000c34e268fff 0x0000/0x0004 0x0020000
10322968.6b30: 000000c34e269000-000000c34e26bfff 0x0004/0x0004 0x0020000
10332968.6b30: 000000c34e26c000-000000c34e3fffff 0x0000/0x0004 0x0020000
10342968.6b30: 000000c34e400000-0000029a0b78ffff 0x0001/0x0000 0x0000000
10352968.6b30: *0000029a0b790000-0000029a0b7affff 0x0004/0x0004 0x0020000
10362968.6b30: *0000029a0b7b0000-0000029a0b7cefff 0x0002/0x0002 0x0040000
10372968.6b30: 0000029a0b7cf000-0000029a0b7dffff 0x0001/0x0000 0x0000000
10382968.6b30: *0000029a0b7e0000-0000029a0b7e3fff 0x0002/0x0002 0x0040000
10392968.6b30: 0000029a0b7e4000-0000029a0b7effff 0x0001/0x0000 0x0000000
10402968.6b30: *0000029a0b7f0000-0000029a0b7f0fff 0x0002/0x0002 0x0040000
10412968.6b30: 0000029a0b7f1000-0000029a0b7fffff 0x0001/0x0000 0x0000000
10422968.6b30: *0000029a0b800000-0000029a0b801fff 0x0004/0x0004 0x0020000
10432968.6b30: 0000029a0b802000-00007df5452dffff 0x0001/0x0000 0x0000000
10442968.6b30: *00007df5452e0000-00007df5452e0fff 0x0002/0x0002 0x0040000
10452968.6b30: 00007df5452e1000-00007df5452effff 0x0001/0x0000 0x0000000
10462968.6b30: *00007df5452f0000-00007df54686dfff 0x0000/0x0001 0x0040000
10472968.6b30: 00007df54686e000-00007df5468dafff 0x0001/0x0001 0x0040000
10482968.6b30: 00007df5468db000-00007df5470d8fff 0x0000/0x0001 0x0040000
10492968.6b30: 00007df5470d9000-00007df5470d9fff 0x0001/0x0001 0x0040000
10502968.6b30: 00007df5470da000-00007dffad5cefff 0x0000/0x0001 0x0040000
10512968.6b30: 00007dffad5cf000-00007dffad5cffff 0x0002/0x0001 0x0040000
10522968.6b30: 00007dffad5d0000-00007ff51e700fff 0x0000/0x0001 0x0040000
10532968.6b30: 00007ff51e701000-00007ff51e706fff 0x0002/0x0001 0x0040000
10542968.6b30: 00007ff51e707000-00007ff5344ebfff 0x0000/0x0001 0x0040000
10552968.6b30: 00007ff5344ec000-00007ff53816bfff 0x0001/0x0001 0x0040000
10562968.6b30: 00007ff53816c000-00007ff538174fff 0x0002/0x0001 0x0040000
10572968.6b30: 00007ff538175000-00007ff5452effff 0x0000/0x0001 0x0040000
10582968.6b30: 00007ff5452f0000-00007ff65046ffff 0x0001/0x0000 0x0000000
10592968.6b30: *00007ff650470000-00007ff650470fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
10602968.6b30: 00007ff650471000-00007ff6504dafff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
10612968.6b30: 00007ff6504db000-00007ff6504dbfff 0x0040/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
10622968.6b30: 00007ff6504dc000-00007ff65052efff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
10632968.6b30: 00007ff65052f000-00007ff65053bfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
10642968.6b30: 00007ff65053c000-00007ff650583fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
10652968.6b30: 00007ff650584000-00007ffcb9f0ffff 0x0001/0x0000 0x0000000
10662968.6b30: *00007ffcb9f10000-00007ffcb9f10fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
10672968.6b30: 00007ffcb9f11000-00007ffcba041fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
10682968.6b30: 00007ffcba042000-00007ffcba08ffff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
10692968.6b30: 00007ffcba090000-00007ffcba093fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
10702968.6b30: 00007ffcba094000-00007ffcba09bfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
10712968.6b30: 00007ffcba09c000-00007ffcba0aafff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
10722968.6b30: 00007ffcba0ab000-00007ffcba0abfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
10732968.6b30: 00007ffcba0ac000-00007ffcba0aefff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
10742968.6b30: 00007ffcba0af000-00007ffcba126fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
10752968.6b30: 00007ffcba127000-00007ffffffeffff 0x0001/0x0000 0x0000000
10762968.6b30: supR3HardNtChildPurify: Done after 1083 ms and 2 fixes (loop #1).
10774ad4.60b4: supR3HardenedVmProcessInit: uNtDllAddr=00007ffcb9f10000 g_uNtVerCombined=0xa0586700 (stack ~000000c34e1eeaa0)
10782968.6b30: supR3HardenedEarlyCompact: Removed heap 1 (0x0001a880000000 LB 0x800000)
10794ad4.60b4: ntdll.dll: timestamp 0x92b2df34 (rc=VINF_SUCCESS)
10804ad4.60b4: New simple heap: #1 0000029a0b910000 LB 0x800000 (for 2191360 allocation)
10812968.6b30: supR3HardNtEnableThreadCreationEx:
10824ad4.60b4: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox'
10834ad4.60b4: System32: \Device\HarddiskVolume3\Windows\System32
10844ad4.60b4: WinSxS: \Device\HarddiskVolume3\Windows\WinSxS
10854ad4.60b4: KnownDllPath: C:\WINDOWS\System32
10864ad4.60b4: supR3HardenedVmProcessInit: Opening vboxsup...
10874ad4.60b4: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
10884ad4.60b4: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
10894ad4.60b4: Registered Dll notification callback with NTDLL.
10904ad4.60b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\kernel32.dll)
10914ad4.60b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\kernel32.dll
10924ad4.60b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\KERNEL32.DLL (Input=KERNEL32.DLL, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000004001:<flags> [calling]
10934ad4.60b4: supR3HardenedMonitor_KiUserApcDispatcher_C: pfnRoutine=0000029a0b7d0088 enmState=4 -> supR3HardenedWinDummyApcRoutine
10944ad4.60b4: supR3HardenedWinDummyApcRoutine: pvArg1=0000029a0b7d0000 pvArg2=0000000000000000 pvArg3=0000000000000000
10954ad4.60b4: supR3HardenedDllNotificationCallback: load 00007ffcb74e0000 LB 0x003a7000 C:\WINDOWS\System32\KERNELBASE.dll [fFlags=0x0]
10964ad4.60b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\KernelBase.dll)
10974ad4.60b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\KernelBase.dll
10984ad4.60b4: supR3HardenedDllNotificationCallback: load 00007ffcb87e0000 LB 0x000c4000 C:\WINDOWS\System32\KERNEL32.DLL [fFlags=0x0]
10994ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
11004ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb87e0000 'C:\WINDOWS\System32\KERNEL32.DLL'
11014ad4.60b4: supR3HardenedDllNotificationCallback: load 00007ff650470000 LB 0x00114000 C:\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe [fFlags=0x0]
11024ad4.60b4: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe: Signature #1/2: info status: 24202
11034ad4.60b4: '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
11044ad4.60b4: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe)
11054ad4.60b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
11064ad4.60b4: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffcb9f83dc0 pvNtTerminateThread=00007ffcb9fb03a0
11072968.6b30: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 76 ms.
11084ad4.60b4: \SystemRoot\System32\ntdll.dll:
11094ad4.60b4: CreationTime: 2024-04-25T21:50:52.933474100Z
11104ad4.60b4: LastWriteTime: 2024-04-25T21:50:52.967360700Z
11114ad4.60b4: ChangeTime: 2024-04-25T22:15:47.894551900Z
11124ad4.60b4: FileAttributes: 0x20
11134ad4.60b4: Size: 0x216008
11144ad4.60b4: NT Headers: 0xe8
11154ad4.60b4: Timestamp: 0x92b2df34
11164ad4.60b4: Machine: 0x8664 - amd64
11174ad4.60b4: Timestamp: 0x92b2df34
11184ad4.60b4: Image Version: 10.0
11194ad4.60b4: SizeOfImage: 0x217000 (2191360)
11204ad4.60b4: Resource Dir: 0x1a0000 LB 0x759a8
11214ad4.60b4: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
11224ad4.60b4: [Raw version resource data: 0x1a00f0 LB 0x380, codepage 0x0 (reserved 0x0)]
11234ad4.60b4: ProductName: Microsoft® Windows® Operating System
11244ad4.60b4: ProductVersion: 10.0.22621.3527
11254ad4.60b4: FileVersion: 10.0.22621.3527 (WinBuild.160101.0800)
11264ad4.60b4: FileDescription: NT Layer DLL
11274ad4.60b4: \SystemRoot\System32\kernel32.dll:
11284ad4.60b4: CreationTime: 2024-04-25T21:50:52.649892600Z
11294ad4.60b4: LastWriteTime: 2024-04-25T21:50:52.664841500Z
11304ad4.60b4: ChangeTime: 2024-04-25T22:15:37.505042500Z
11314ad4.60b4: FileAttributes: 0x20
11324ad4.60b4: Size: 0xc7158
11334ad4.60b4: NT Headers: 0xe8
11344ad4.60b4: Timestamp: 0x6b8a5ea3
11354ad4.60b4: Machine: 0x8664 - amd64
11364ad4.60b4: Timestamp: 0x6b8a5ea3
11374ad4.60b4: Image Version: 10.0
11384ad4.60b4: SizeOfImage: 0xc4000 (802816)
11394ad4.60b4: Resource Dir: 0xc2000 LB 0x520
11404ad4.60b4: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
11414ad4.60b4: [Raw version resource data: 0xc20b0 LB 0x3a4, codepage 0x0 (reserved 0x0)]
11424ad4.60b4: ProductName: Microsoft® Windows® Operating System
11434ad4.60b4: ProductVersion: 10.0.22621.3527
11444ad4.60b4: FileVersion: 10.0.22621.3527 (WinBuild.160101.0800)
11454ad4.60b4: FileDescription: Windows NT BASE API Client DLL
11464ad4.60b4: \SystemRoot\System32\KernelBase.dll:
11474ad4.60b4: CreationTime: 2024-04-25T21:50:53.507611100Z
11484ad4.60b4: LastWriteTime: 2024-04-25T21:50:53.604794300Z
11494ad4.60b4: ChangeTime: 2024-04-25T22:15:45.722906700Z
11504ad4.60b4: FileAttributes: 0x20
11514ad4.60b4: Size: 0x3ae908
11524ad4.60b4: NT Headers: 0xf8
11534ad4.60b4: Timestamp: 0x83efbeab
11544ad4.60b4: Machine: 0x8664 - amd64
11554ad4.60b4: Timestamp: 0x83efbeab
11564ad4.60b4: Image Version: 10.0
11574ad4.60b4: SizeOfImage: 0x3a7000 (3829760)
11584ad4.60b4: Resource Dir: 0x376000 LB 0x548
11594ad4.60b4: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
11604ad4.60b4: [Raw version resource data: 0x3760b0 LB 0x3bc, codepage 0x0 (reserved 0x0)]
11614ad4.60b4: ProductName: Microsoft® Windows® Operating System
11624ad4.60b4: ProductVersion: 10.0.22621.3527
11634ad4.60b4: FileVersion: 10.0.22621.3527 (WinBuild.160101.0800)
11644ad4.60b4: FileDescription: Windows NT BASE API Client DLL
11654ad4.60b4: \SystemRoot\System32\apisetschema.dll:
11664ad4.60b4: CreationTime: 2024-04-25T21:50:27.205621000Z
11674ad4.60b4: LastWriteTime: 2024-04-25T21:50:27.208610400Z
11684ad4.60b4: ChangeTime: 2024-04-25T22:15:42.442010700Z
11694ad4.60b4: FileAttributes: 0x20
11704ad4.60b4: Size: 0x245e0
11714ad4.60b4: NT Headers: 0xc8
11724ad4.60b4: Timestamp: 0x2f79598b
11734ad4.60b4: Machine: 0x8664 - amd64
11744ad4.60b4: Timestamp: 0x2f79598b
11754ad4.60b4: Image Version: 10.0
11764ad4.60b4: SizeOfImage: 0x23000 (143360)
11774ad4.60b4: Resource Dir: 0x22000 LB 0x408
11784ad4.60b4: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
11794ad4.60b4: [Raw version resource data: 0x22060 LB 0x3a8, codepage 0x0 (reserved 0x0)]
11804ad4.60b4: ProductName: Microsoft® Windows® Operating System
11814ad4.60b4: ProductVersion: 10.0.22621.3527
11824ad4.60b4: FileVersion: 10.0.22621.3527 (WinBuild.160101.0800)
11834ad4.60b4: FileDescription: ApiSet Schema DLL
11844ad4.60b4: NtOpenDirectoryObject failed on \Driver: 0xc0000022
11854ad4.60b4: supR3HardenedWinFindAdversaries: 0x4
11864ad4.60b4: \SystemRoot\System32\drivers\aswMonFlt.sys:
11874ad4.60b4: CreationTime: 2022-11-24T10:33:09.488089900Z
11884ad4.60b4: LastWriteTime: 2024-04-12T01:45:56.269304300Z
11894ad4.60b4: ChangeTime: 2024-04-12T01:45:56.269304300Z
11904ad4.60b4: FileAttributes: 0x20
11914ad4.60b4: Size: 0x41a38
11924ad4.60b4: NT Headers: 0xf0
11934ad4.60b4: Timestamp: 0x660161d5
11944ad4.60b4: Machine: 0x8664 - amd64
11954ad4.60b4: Timestamp: 0x660161d5
11964ad4.60b4: Image Version: 10.0
11974ad4.60b4: SizeOfImage: 0x49000 (299008)
11984ad4.60b4: Resource Dir: 0x47000 LB 0x3b0
11994ad4.60b4: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
12004ad4.60b4: [Raw version resource data: 0x47058 LB 0x358, codepage 0x0 (reserved 0x0)]
12014ad4.60b4: ProductName: Antivirus
12024ad4.60b4: ProductVersion: 24.3.683.0
12034ad4.60b4: FileVersion: 24.3.683.0
12044ad4.60b4: FileDescription: Gen File System Filter
12054ad4.60b4: \SystemRoot\System32\drivers\aswRdr2.sys:
12064ad4.60b4: CreationTime: 2022-11-24T10:33:09.486096500Z
12074ad4.60b4: LastWriteTime: 2024-04-12T01:45:56.261304700Z
12084ad4.60b4: ChangeTime: 2024-04-12T01:45:56.261304700Z
12094ad4.60b4: FileAttributes: 0x20
12104ad4.60b4: Size: 0x16e38
12114ad4.60b4: NT Headers: 0xe8
12124ad4.60b4: Timestamp: 0x660161d2
12134ad4.60b4: Machine: 0x8664 - amd64
12144ad4.60b4: Timestamp: 0x660161d2
12154ad4.60b4: Image Version: 10.0
12164ad4.60b4: SizeOfImage: 0x1b000 (110592)
12174ad4.60b4: Resource Dir: 0x19000 LB 0x398
12184ad4.60b4: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
12194ad4.60b4: [Raw version resource data: 0x19058 LB 0x33c, codepage 0x0 (reserved 0x0)]
12204ad4.60b4: ProductName: Antivirus
12214ad4.60b4: ProductVersion: 24.3.683.0
12224ad4.60b4: FileVersion: 24.3.683.0
12234ad4.60b4: FileDescription: Gen Antivirus
12244ad4.60b4: \SystemRoot\System32\drivers\aswRvrt.sys:
12254ad4.60b4: CreationTime: 2022-11-24T10:33:09.489086600Z
12264ad4.60b4: LastWriteTime: 2024-04-12T01:45:56.277304500Z
12274ad4.60b4: ChangeTime: 2024-04-12T01:45:56.277304500Z
12284ad4.60b4: FileAttributes: 0x20
12294ad4.60b4: Size: 0x10e38
12304ad4.60b4: NT Headers: 0xe0
12314ad4.60b4: Timestamp: 0x660161cb
12324ad4.60b4: Machine: 0x8664 - amd64
12334ad4.60b4: Timestamp: 0x660161cb
12344ad4.60b4: Image Version: 10.0
12354ad4.60b4: SizeOfImage: 0x13000 (77824)
12364ad4.60b4: Resource Dir: 0x11000 LB 0x390
12374ad4.60b4: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
12384ad4.60b4: [Raw version resource data: 0x11058 LB 0x338, codepage 0x0 (reserved 0x0)]
12394ad4.60b4: ProductName: Antivirus
12404ad4.60b4: ProductVersion: 24.3.683.0
12414ad4.60b4: FileVersion: 24.3.683.0
12424ad4.60b4: FileDescription: Gen Revert
12434ad4.60b4: \SystemRoot\System32\drivers\aswSnx.sys:
12444ad4.60b4: CreationTime: 2022-11-24T10:33:09.480116700Z
12454ad4.60b4: LastWriteTime: 2024-04-12T01:45:53.466864800Z
12464ad4.60b4: ChangeTime: 2024-04-12T01:45:53.466864800Z
12474ad4.60b4: FileAttributes: 0x20
12484ad4.60b4: Size: 0xe4838
12494ad4.60b4: NT Headers: 0x100
12504ad4.60b4: Timestamp: 0x660161ff
12514ad4.60b4: Machine: 0x8664 - amd64
12524ad4.60b4: Timestamp: 0x660161ff
12534ad4.60b4: Image Version: 10.0
12544ad4.60b4: SizeOfImage: 0xe9000 (954368)
12554ad4.60b4: Resource Dir: 0xe6000 LB 0x3b0
12564ad4.60b4: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
12574ad4.60b4: [Raw version resource data: 0xe6058 LB 0x354, codepage 0x0 (reserved 0x0)]
12584ad4.60b4: ProductName: Antivirus
12594ad4.60b4: ProductVersion: 24.3.683.0
12604ad4.60b4: FileVersion: 24.3.683.0
12614ad4.60b4: FileDescription: Gen Virtualization Driver
12624ad4.60b4: \SystemRoot\System32\drivers\aswsp.sys:
12634ad4.60b4: CreationTime: 2022-11-24T10:33:09.490083300Z
12644ad4.60b4: LastWriteTime: 2024-04-12T01:45:56.288304000Z
12654ad4.60b4: ChangeTime: 2024-04-12T01:45:56.288304000Z
12664ad4.60b4: FileAttributes: 0x20
12674ad4.60b4: Size: 0xa9e38
12684ad4.60b4: NT Headers: 0xe8
12694ad4.60b4: Timestamp: 0x660161ed
12704ad4.60b4: Machine: 0x8664 - amd64
12714ad4.60b4: Timestamp: 0x660161ed
12724ad4.60b4: Image Version: 10.0
12734ad4.60b4: SizeOfImage: 0xb0000 (720896)
12744ad4.60b4: Resource Dir: 0xad000 LB 0x398
12754ad4.60b4: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
12764ad4.60b4: [Raw version resource data: 0xad058 LB 0x340, codepage 0x0 (reserved 0x0)]
12774ad4.60b4: ProductName: Antivirus
12784ad4.60b4: ProductVersion: 24.3.683.0
12794ad4.60b4: FileVersion: 24.3.683.0
12804ad4.60b4: FileDescription: Gen Self Protection
12814ad4.60b4: \SystemRoot\System32\drivers\aswStm.sys:
12824ad4.60b4: CreationTime: 2024-04-12T01:45:58.391309500Z
12834ad4.60b4: LastWriteTime: 2024-04-12T01:45:56.481310100Z
12844ad4.60b4: ChangeTime: 2024-04-12T01:45:56.481310100Z
12854ad4.60b4: FileAttributes: 0x20
12864ad4.60b4: Size: 0x31438
12874ad4.60b4: NT Headers: 0xf0
12884ad4.60b4: Timestamp: 0x66016201
12894ad4.60b4: Machine: 0x8664 - amd64
12904ad4.60b4: Timestamp: 0x66016201
12914ad4.60b4: Image Version: 10.0
12924ad4.60b4: SizeOfImage: 0x36000 (221184)
12934ad4.60b4: Resource Dir: 0x34000 LB 0x3a0
12944ad4.60b4: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
12954ad4.60b4: [Raw version resource data: 0x34058 LB 0x344, codepage 0x0 (reserved 0x0)]
12964ad4.60b4: ProductName: Antivirus
12974ad4.60b4: ProductVersion: 24.3.683.0
12984ad4.60b4: FileVersion: 24.3.683.0
12994ad4.60b4: FileDescription: Gen Stream Filter
13004ad4.60b4: \SystemRoot\System32\drivers\aswVmm.sys:
13014ad4.60b4: CreationTime: 2022-11-24T10:33:09.495066500Z
13024ad4.60b4: LastWriteTime: 2024-04-12T01:45:56.819309900Z
13034ad4.60b4: ChangeTime: 2024-04-12T01:45:56.819309900Z
13044ad4.60b4: FileAttributes: 0x20
13054ad4.60b4: Size: 0x4ac38
13064ad4.60b4: NT Headers: 0xe8
13074ad4.60b4: Timestamp: 0x660161d4
13084ad4.60b4: Machine: 0x8664 - amd64
13094ad4.60b4: Timestamp: 0x660161d4
13104ad4.60b4: Image Version: 10.0
13114ad4.60b4: SizeOfImage: 0x4d000 (315392)
13124ad4.60b4: Resource Dir: 0x4b000 LB 0x398
13134ad4.60b4: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
13144ad4.60b4: [Raw version resource data: 0x4b058 LB 0x340, codepage 0x0 (reserved 0x0)]
13154ad4.60b4: ProductName: Antivirus
13164ad4.60b4: ProductVersion: 24.3.683.0
13174ad4.60b4: FileVersion: 24.3.683.0
13184ad4.60b4: FileDescription: Gen VM Monitor
13194ad4.60b4: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox'
13204ad4.60b4: Calling main()
13214ad4.60b4: SUPR3HardenedMain: pszProgName=VirtualBoxVM fFlags=0x2
13224ad4.60b4: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox'
13234ad4.60b4: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe: Signature #1/2: info status: 24202
13244ad4.60b4: '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
13254ad4.60b4: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe)
13264ad4.60b4: SUPR3HardenedMain: Final process, opening VBoxDrv...
13274ad4.60b4: supR3HardenedEarlyCompact: Removed heap 1 (0x00029a0b910000 LB 0x800000)
13284ad4.60b4: supR3HardNtEnableThreadCreationEx:
13294ad4.60b4: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSupLib.dll: Signature #1/2: info status: 24202
13304ad4.60b4: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSupLib.dll)
13314ad4.60b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSupLib.dll
13324ad4.60b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
13334ad4.60b4: supR3HardenedScreenImage/NtCreateSection: cache hit (24202) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
13344ad4.60b4: supR3HardenedDllNotificationCallback: load 00007ffcb0d90000 LB 0x00005000 C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL [fFlags=0x0]
13354ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (24202) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
13364ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (24202) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
13374ad4.60b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
13384ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb0d90000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
13394ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (24202) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
13404ad4.60b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
13414ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb0d90000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
13424ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb0d90000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
13434ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
13444ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #29 'rpcrt4.dll'.
13454ad4.60b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\wintrust.dll)
13464ad4.60b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\wintrust.dll
13474ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
13484ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
13494ad4.60b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll)
13504ad4.60b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll
13514ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
13524ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
13534ad4.60b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\msvcrt.dll)
13544ad4.60b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\msvcrt.dll
13554ad4.60b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
13564ad4.60b4: supR3HardenedDllNotificationCallback: load 00007ffcb7d00000 LB 0x000a7000 C:\WINDOWS\System32\msvcrt.dll [fFlags=0x0]
13574ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
13584ad4.60b4: supR3HardenedDllNotificationCallback: load 00007ffcb8a00000 LB 0x00115000 C:\WINDOWS\System32\RPCRT4.dll [fFlags=0x0]
13594ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
13604ad4.60b4: supR3HardenedDllNotificationCallback: load 00007ffcb73a0000 LB 0x0006b000 C:\WINDOWS\System32\Wintrust.dll [fFlags=0x0]
13614ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
13624ad4.60b4: supR3HardenedDllNotificationCallback: load 00007ffcb78c0000 LB 0x00111000 C:\WINDOWS\System32\ucrtbase.dll [fFlags=0x0]
13634ad4.60b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\ucrtbase.dll)
13644ad4.60b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\ucrtbase.dll
13654ad4.60b4: supR3HardenedDllNotificationCallback: load 00007ffcb7230000 LB 0x00167000 C:\WINDOWS\System32\CRYPT32.dll [fFlags=0x0]
13664ad4.60b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\crypt32.dll)
13674ad4.60b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\crypt32.dll
13684ad4.60b4: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
13694ad4.60b4: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
13704ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb74e0000 'api-ms-win-core-synch-l1-2-0'
13714ad4.60b4: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
13724ad4.60b4: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
13734ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb74e0000 'api-ms-win-core-fibers-l1-1-1'
13744ad4.60b4: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
13754ad4.60b4: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
13764ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb74e0000 'api-ms-win-core-synch-l1-2-0'
13774ad4.60b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\msasn1.dll)
13784ad4.60b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\msasn1.dll
13794ad4.60b4: supR3HardenedDllNotificationCallback: load 00007ffcb6ec0000 LB 0x00012000 C:\WINDOWS\SYSTEM32\MSASN1.dll [fFlags=0x0]
13804ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
13814ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb73a0000 'C:\WINDOWS\system32\Wintrust.dll'
13824ad4.60b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\bcrypt.dll)
13834ad4.60b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\bcrypt.dll
13844ad4.60b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\bcrypt.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
13854ad4.60b4: supR3HardenedDllNotificationCallback: load 00007ffcb7890000 LB 0x00028000 C:\WINDOWS\System32\bcrypt.dll [fFlags=0x0]
13864ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
13874ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7890000 'C:\WINDOWS\system32\bcrypt.dll'
13884ad4.60b4: bcrypt.dll loaded at 00007ffcb7890000, BCryptOpenAlgorithmProvider at 00007ffcb7894520, preloading providers:
13894ad4.60b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\bcryptprimitives.dll)
13904ad4.60b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\bcryptprimitives.dll
13914ad4.60b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\bcryptprimitives.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
13924ad4.60b4: supR3HardenedDllNotificationCallback: load 00007ffcb7bc0000 LB 0x00079000 C:\WINDOWS\System32\bcryptprimitives.dll [fFlags=0x0]
13934ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
13944ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7bc0000 'C:\WINDOWS\system32\bcryptprimitives.dll'
13954ad4.60b4: BCryptOpenAlgorithmProvider(,'MD2',0,0) -> 0x0 (hAlgo=0000029a0c201400)
13964ad4.60b4: BCryptOpenAlgorithmProvider(,'MD4',0,0) -> 0x0 (hAlgo=0000029a0c2033b0)
13974ad4.60b4: BCryptOpenAlgorithmProvider(,'MD5',0,0) -> 0x0 (hAlgo=0000029a0c203700)
13984ad4.60b4: BCryptOpenAlgorithmProvider(,'SHA1',0,0) -> 0x0 (hAlgo=0000029a0c203a50)
13994ad4.60b4: BCryptOpenAlgorithmProvider(,'SHA256',0,0) -> 0x0 (hAlgo=0000029a0c203da0)
14004ad4.60b4: BCryptOpenAlgorithmProvider(,'SHA512',0,0) -> 0x0 (hAlgo=0000029a0c2040f0)
14014ad4.60b4: BCryptOpenAlgorithmProvider(,'RSA',0,0) -> 0x0 (hAlgo=0000029a0c204440)
14024ad4.60b4: BCryptOpenAlgorithmProvider(,'DSA',0,0) -> 0x0 (hAlgo=0000029a0c204790)
14034ad4.60b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\cryptsp.dll)
14044ad4.60b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\cryptsp.dll
14054ad4.60b4: supR3HardenedDllNotificationCallback: load 00007ffcb6a10000 LB 0x0001b000 C:\WINDOWS\SYSTEM32\CRYPTSP.dll [fFlags=0x0]
14064ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
14074ad4.60b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\rsaenh.dll)
14084ad4.60b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\rsaenh.dll
14094ad4.60b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
14104ad4.60b4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
14114ad4.60b4: supR3HardenedDllNotificationCallback: load 00007ffcb62a0000 LB 0x00035000 C:\WINDOWS\system32\rsaenh.dll [fFlags=0x0]
14124ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
14134ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
14144ad4.60b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\cryptbase.dll)
14154ad4.60b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\cryptbase.dll
14164ad4.60b4: supR3HardenedDllNotificationCallback: load 00007ffcb6a30000 LB 0x0000c000 C:\WINDOWS\SYSTEM32\CRYPTBASE.dll [fFlags=0x0]
14174ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\cryptbase.dll [lacks WinVerifyTrust]
14184ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
14194ad4.60b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
14204ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb87e0000 'C:\WINDOWS\System32\kernel32.dll'
14214ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
14224ad4.60b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\WINTRUST.DLL (Input=WINTRUST.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
14234ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb73a0000 'C:\WINDOWS\System32\WINTRUST.DLL'
14244ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
14254ad4.60b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\CRYPT32.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
14264ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\CRYPT32.dll'
14274ad4.60b4: supR3HardenedDllNotificationCallback: load 00007ffcb8c10000 LB 0x0001f000 C:\WINDOWS\System32\imagehlp.dll [fFlags=0x0]
14284ad4.60b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\imagehlp.dll)
14294ad4.60b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\imagehlp.dll
14304ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
14314ad4.60b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
14324ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
14334ad4.60b4: supR3HardenedDllNotificationCallback: load 00007ffcb8900000 LB 0x000a8000 C:\WINDOWS\System32\sechost.dll [fFlags=0x0]
14344ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #24 'bcrypt.dll'.
14354ad4.60b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\sechost.dll)
14364ad4.60b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\sechost.dll
14374ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
14384ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'rpcrt4.dll'.
14394ad4.60b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\gpapi.dll)
14404ad4.60b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\gpapi.dll
14414ad4.60b4: supR3HardenedDllNotificationCallback: load 00007ffcb6840000 LB 0x00026000 C:\WINDOWS\SYSTEM32\gpapi.dll [fFlags=0x0]
14424ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gpapi.dll [lacks WinVerifyTrust]
14434ad4.60b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\profapi.dll)
14444ad4.60b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\profapi.dll
14454ad4.60b4: supR3HardenedDllNotificationCallback: load 00007ffcb7160000 LB 0x00021000 C:\WINDOWS\SYSTEM32\profapi.dll [fFlags=0x0]
14464ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\profapi.dll [lacks WinVerifyTrust]
14474ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
14484ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'crypt32.dll'.
14494ad4.60b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\cryptnet.dll)
14504ad4.60b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\cryptnet.dll
14514ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
14524ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume3\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
14534ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
14544ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
14554ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
14564ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
14574ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
14584ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
14594ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
14604ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
14614ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
14624ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
14634ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
14644ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume3\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
14654ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
14664ad4.60b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (Input=cryptnet.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
14674ad4.60b4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
14684ad4.60b4: supR3HardenedDllNotificationCallback: load 00007ffcb14a0000 LB 0x00032000 C:\WINDOWS\System32\cryptnet.dll [fFlags=0x0]
14694ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
14704ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
14714ad4.60b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
14724ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb14a0000 'C:\WINDOWS\System32\cryptnet.dll'
14734ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
14744ad4.60b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
14754ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb14a0000 'C:\WINDOWS\System32\cryptnet.dll'
14764ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
14774ad4.60b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
14784ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb14a0000 'C:\WINDOWS\System32\cryptnet.dll'
14794ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
14804ad4.60b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
14814ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb14a0000 'C:\WINDOWS\System32\cryptnet.dll'
14824ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
14834ad4.60b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
14844ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb14a0000 'C:\WINDOWS\System32\cryptnet.dll'
14854ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
14864ad4.60b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
14874ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb14a0000 'C:\WINDOWS\System32\cryptnet.dll'
14884ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
14894ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb14a0000 'C:\WINDOWS\System32\cryptnet.dll'
14904ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
14914ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb14a0000 'C:\WINDOWS\System32\cryptnet.dll'
14924ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
14934ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb14a0000 'C:\WINDOWS\System32\cryptnet.dll'
14944ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
14954ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb14a0000 'C:\WINDOWS\System32\cryptnet.dll'
14964ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
14974ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb14a0000 'C:\WINDOWS\System32\cryptnet.dll'
14984ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb14a0000 'C:\WINDOWS\System32\cryptnet.dll'
14994ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
15004ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb14a0000 'C:\Windows\System32\cryptnet.dll'
15014ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
15024ad4.60b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
15034ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
15044ad4.60b4: supR3HardenedDllNotificationCallback: load 00007ffcb86c0000 LB 0x000b2000 C:\WINDOWS\System32\advapi32.dll [fFlags=0x0]
15054ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
15064ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'sechost.dll'.
15074ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #28 'rpcrt4.dll'.
15084ad4.60b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\advapi32.dll)
15094ad4.60b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\advapi32.dll
15104ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
15114ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
15124ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
15134ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
15144ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'sechost.dll'...
15154ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'sechost.dll' -> '\Device\HarddiskVolume3\Windows\System32\sechost.dll' [rcNtRedir=0xc0150008]
15164ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\sechost.dll [lacks WinVerifyTrust]
15174ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
15184ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
15194ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
15204ad4.60b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
15214ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
15224ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
15234ad4.60b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
15244ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
15254ad4.60b4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000000 pwszName=\SystemRoot\System32\ntdll.dll
15264ad4.60b4: supR3HardNtViCallWinVerifyTrustCatFile: New context 0000029a0c2d5010
15274ad4.60b4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000029a0c2d5010
15284ad4.60b4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B75D042783ED0B6507B52A83F7110A7FC32B1632
15294ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
15304ad4.60b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\rpcrt4.dll (Input=rpcrt4.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
15314ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb8a00000 'C:\WINDOWS\System32\rpcrt4.dll'
15324ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
15334ad4.60b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
15344ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
15354ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
15364ad4.60b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
15374ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
15384ad4.60b4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package051420~31bf3856ad364e35~amd64~~10.0.22621.3527.cat'; file='\SystemRoot\System32\ntdll.dll'
15394ad4.60b4: g_pfnWinVerifyTrust=00007ffcb73b2480
15404ad4.60b4: supR3HardenedScreenImage/preload: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll [redoing WinVerifyTrust]
15414ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
15424ad4.60b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
15434ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
15444ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
15454ad4.60b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
15464ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
15474ad4.60b4: supR3HardenedScreenImage/preload: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\crypt32.dll'
15484ad4.60b4: supR3HardenedScreenImage/preload: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wintrust.dll [redoing WinVerifyTrust]
15494ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
15504ad4.60b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
15514ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
15524ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll
15534ad4.60b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
15544ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
15554ad4.60b4: supR3HardenedScreenImage/preload: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\wintrust.dll'
15564ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
15574ad4.60b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
15584ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
15594ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
15604ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\advapi32.dll'
15614ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
15624ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
15634ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
15644ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\cryptnet.dll'
15654ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
15664ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
15674ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
15684ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\profapi.dll'
15694ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
15704ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
15714ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
15724ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\gpapi.dll'
15734ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
15744ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
15754ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
15764ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\sechost.dll'
15774ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
15784ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
15794ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
15804ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\imagehlp.dll'
15814ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
15824ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
15834ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
15844ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\cryptbase.dll'
15854ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
15864ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
15874ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll
15884ad4.60b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
15894ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
15904ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\rsaenh.dll'
15914ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll
15924ad4.60b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
15934ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
15944ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
15954ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\cryptsp.dll'
15964ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
15974ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
15984ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\bcryptprimitives.dll'
15994ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
16004ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
16014ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\bcrypt.dll'
16024ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
16034ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
16044ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\msasn1.dll'
16054ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
16064ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
16074ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\ucrtbase.dll'
16084ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
16094ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
16104ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll'
16114ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
16124ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
16134ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll'
16144ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
16154ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
16164ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 24202) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSupLib.dll'
16174ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
16184ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
16194ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 24202) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe'
16204ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
16214ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
16224ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\KernelBase.dll'
16234ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
16244ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
16254ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\kernel32.dll'
16264ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\system32\crypt32.dll'
16274ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0x100089abfea8e300 C=DE, ST=Bavaria, L=Munich, O=Oracle Deutschland B.V. & Co. KG, CN=VirtualBox for Legacy Windows Only Timestamp CA
16284ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0x5ad46780fa5df300 DC=com, DC=microsoft, CN=Microsoft Root Certificate Authority
16294ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0xea5386456178582b C=ZA, ST=Western Cape, L=Durbanville, O=Thawte, OU=Thawte Certification, CN=Thawte Timestamping CA
16304ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0x3be670c1bd02a900 OU=Copyright (c) 1997 Microsoft Corp., OU=Microsoft Corporation, CN=Microsoft Root Authority
16314ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0x643799522ed7cc00 C=EG, ST=Egypt, L=Cairo, O=esmartsoft_ca Company LTD, OU=esmartsoft_ca Certificate Authority, [email protected]
16324ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0x5056e83790a8b200 CN=Nobel
16334ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0xe991ee72b03db500 C=US, O=Symantec Corporation, CN=Symantec Enterprise Mobile Root for Microsoft
16344ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0x4d3835aa4180b200 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2011
16354ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0x646e3fe3ba08df00 C=US, O=MSFT, CN=Microsoft Authenticode(tm) Root Authority
16364ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0xd78dd5ba4b84b000 C=EG, ST=Egypt, L=Cairo, O=esmartsoft_local_CA Company LTD, OU=esmartsoft_local_CA Certificate Authority, [email protected]
16374ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0xece4e4289e08b900 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010
16384ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0xf3bb4d7e894b420 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft ECC TS Root Certificate Authority 2018
16394ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0x9eb576fc9835d500 OU=generated by Avast Antivirus for SSL/TLS scanning, O=Avast Web/Mail Shield, CN=Avast Web/Mail Shield Root
16404ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0x43a9cc371ff5385a O=Microsoft Trust Network, OU=Microsoft Corporation, OU=Microsoft Time Stamping Service Root, OU=Copyright (c) 1997 Microsoft Corp.
16414ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0x19d9a25f1933ae00 C=EG, ST=Egypt, L=Cairo, O=local-mill-CA Company LTD, OU=local-mill-CA Certificate Authority, [email protected]
16424ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0x2e2d2c7c68f0202e O=VeriSign Trust Network, OU=VeriSign, Inc., OU=VeriSign Time Stamping Service Root, OU=NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.
16434ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0xcec3d46562b9be8e C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft ECC Product Root Certificate Authority 2018
16444ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0xca58a05dd401ae00 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Time Stamp Root Certificate Authority 2014
16454ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0x670683072a91b300 C=US, O=Microsoft Corporation, CN=Microsoft Identity Verification Root Certificate Authority 2020
16464ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0x61a3a33f81aace00 C=US, ST=UT, L=Salt Lake City, O=The USERTRUST Network, OU=http://www.usertrust.com, CN=UTN-USERFirst-Object
16474ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0x3d993fde1950a700 C=US, O=IdenTrust, CN=IdenTrust Commercial Root CA 1
16484ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0x6b7bdc34cd37bb00 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root G2
16494ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0x57ba5395b561bf00 C=BM, O=QuoVadis Limited, OU=Root Certification Authority, CN=QuoVadis Root Certification Authority
16504ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0xbbde687390e6bf00 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Trusted Root G4
16514ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0x83085097e9afdf00 O=Digital Signature Trust Co., CN=DST Root CA X3
16524ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0x780679907625cc00 OU=GlobalSign Root CA - R3, O=GlobalSign, CN=GlobalSign
16534ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0x3d98ab22bb04a300 C=IE, O=Baltimore, OU=CyberTrust, CN=Baltimore CyberTrust Root
16544ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0xeae16ef49d40be00 C=GB, ST=Greater Manchester, L=Salford, O=Comodo CA Limited, CN=AAA Certificate Services
16554ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0xc6536f24d57ae723 C=US, ST=New Jersey, L=Jersey City, O=The USERTRUST Network, CN=USERTrust ECC Certification Authority
16564ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0x3714f47324e8ad00 C=US, O=Internet Security Research Group, CN=ISRG Root X1
16574ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0xd944bca189a00 C=BM, O=QuoVadis Limited, CN=QuoVadis Root CA 2
16584ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0xcb7d2ba3dd0ff900 C=US, ST=Texas, L=Houston, O=SSL Corporation, CN=SSL.com Root Certification Authority RSA
16594ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0x8ff6fc03c1edbd00 C=US, ST=Arizona, L=Scottsdale, O=Starfield Technologies, Inc., CN=Starfield Root Certificate Authority - G2
16604ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0xc6fa4243b695b600 C=US, O=Entrust, Inc., OU=www.entrust.net/CPS is incorporated by reference, OU=(c) 2006 Entrust, Inc., CN=Entrust Root Certification Authority
16614ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0xa3ce8d99e60eda00 C=BE, O=GlobalSign nv-sa, OU=Root CA, CN=GlobalSign Root CA
16624ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0x560ad29254e89100 C=GB, ST=Greater Manchester, L=Salford, O=COMODO CA Limited, CN=COMODO RSA Certification Authority
16634ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0xa671e9fec832b700 C=US, O=Starfield Technologies, Inc., OU=Starfield Class 2 Certification Authority
16644ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0xa8de7211e13be200 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root CA
16654ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0xc9edb72b684ba00 C=US, O=Entrust, Inc., OU=See www.entrust.net/legal-terms, OU=(c) 2009 Entrust, Inc. - for authorized use only, CN=Entrust Root Certification Authority - G2
16664ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0xf5cd95e581a4ab00 C=US, O=SecureTrust Corporation, CN=SecureTrust CA
16674ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0xbebef0d2217f0bfb C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root G3
16684ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0x4dd6e14065368f00 C=US, ST=Texas, L=Houston, O=SSL Corporation, CN=SSL.com EV Root Certification Authority RSA R2
16694ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0x14018a1bf29e595c C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority
16704ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0xd4fbe673e5ccc600 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA
16714ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0xb352b1523915d000 C=JP, O=SECOM Trust Systems CO.,LTD., OU=Security Communication RootCA2
16724ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0x73e85f1bda5faa00 C=DE, O=T-Systems Enterprise Services GmbH, OU=T-Systems Trust Center, CN=T-TeleSec GlobalRoot Class 2
16734ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0xb28612a94b4dad00 O=Entrust.net, OU=www.entrust.net/CPS_2048 incorp. by ref. (limits liab.), OU=(c) 1999 Entrust.net Limited, CN=Entrust.net Certification Authority (2048)
16744ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0xe87add30c52db600 C=BE, O=GlobalSign nv-sa, CN=GlobalSign Code Signing Root R45
16754ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0x357a29080824af00 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2006 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G5
16764ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0xd407c1f75ec7d700 C=NO, O=Buypass AS-983163327, CN=Buypass Class 2 Root CA
16774ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0x59faf1086271bf00 C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com, Inc., CN=Go Daddy Root Certificate Authority - G2
16784ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0x466cbc09db88c100 C=IL, O=StartCom Ltd., OU=Secure Digital Certificate Signing, CN=StartCom Certification Authority
16794ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0xb16dd37ffeb3b300 C=JP, O=SECOM Trust.net, OU=Security Communication RootCA1
16804ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0x3401b15e3761c700 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2008 VeriSign, Inc. - For authorized use only, CN=VeriSign Universal Root Certification Authority
16814ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0xc30e361765128000 C=US, ST=New Jersey, L=Jersey City, O=The USERTRUST Network, CN=USERTrust RSA Certification Authority
16824ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0x491857ead79dde00 C=US, O=The Go Daddy Group, Inc., OU=Go Daddy Class 2 Certification Authority
16834ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0xb9ff821d139e9bf OU=GlobalSign ECC Root CA - R5, O=GlobalSign, CN=GlobalSign
16844ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0xc2ba72a37dfbe300 C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Trusted Network CA
16854ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0x8043e4ce150ead00 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID Root CA
16864ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0xf2e6331af7b700 C=SE, O=AddTrust AB, OU=AddTrust External TTP Network, CN=AddTrust External CA Root
16874ad4.60b4: supR3HardenedWinIsDesiredRootCA: Adding 0x3714f47324e8ad00 C=US, O=Internet Security Research Group, CN=ISRG Root X1
16884ad4.60b4: supR3HardenedWinRetrieveTrustedRootCAs: cAdded=61
16894ad4.60b4: SUPR3HardenedMain: Load Runtime...
16904ad4.60b4: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll: Signature #1/2: info status: 24202
16914ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
16924ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
16934ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'vcruntime140.dll'.
16944ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vcruntime140_1.dll'.
16954ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcp140.dll'.
16964ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'rpcrt4.dll'.
16974ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'ws2_32.dll'.
16984ad4.60b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll) WinVerifyTrust
16994ad4.60b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll
17004ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
17014ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
17024ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
17034ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
17044ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'rpcrt4.dll'.
17054ad4.60b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\ws2_32.dll) WinVerifyTrust
17064ad4.60b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\ws2_32.dll
17074ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
17084ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
17094ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll
17104ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp140.dll'...
17114ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp140.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcp140.dll' [rcNtRedir=0xc0150008]
17124ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
17134ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
17144ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll
17154ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
17164ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
17174ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'vcruntime140.dll'.
17184ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vcruntime140_1.dll'.
17194ad4.60b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\msvcp140.dll) WinVerifyTrust
17204ad4.60b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\msvcp140.dll
17214ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140_1.dll'...
17224ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140_1.dll' -> '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rcNtRedir=0xc0150008]
17234ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140_1.dll'...
17244ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140_1.dll' -> '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rcNtRedir=0xc0150008]
17254ad4.60b4: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
17264ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vcruntime140.dll'.
17274ad4.60b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll)
17284ad4.60b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll
17294ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140.dll'...
17304ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140.dll' -> '\Device\HarddiskVolume3\Windows\System32\vcruntime140.dll' [rcNtRedir=0xc0150008]
17314ad4.60b4: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140.dll'.
17324ad4.60b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\vcruntime140.dll)
17334ad4.60b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\vcruntime140.dll
17344ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140.dll'...
17354ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140.dll' -> '\Device\HarddiskVolume3\Windows\System32\vcruntime140.dll' [rcNtRedir=0xc0150008]
17364ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\vcruntime140.dll [lacks WinVerifyTrust]
17374ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
17384ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll
17394ad4.60b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
17404ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
17414ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vcruntime140.dll'.
17424ad4.60b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll) WinVerifyTrust
17434ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140.dll'...
17444ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140.dll' -> '\Device\HarddiskVolume3\Windows\System32\vcruntime140.dll' [rcNtRedir=0xc0150008]
17454ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\vcruntime140.dll [redoing WinVerifyTrust]
17464ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140.dll'...
17474ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140.dll' -> '\Device\HarddiskVolume3\Windows\System32\vcruntime140.dll' [rcNtRedir=0xc0150008]
17484ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\vcruntime140.dll [lacks WinVerifyTrust]
17494ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
17504ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
17514ad4.60b4: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140.dll'
17524ad4.60b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000a01:<flags> [calling]
17534ad4.60b4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll
17544ad4.60b4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\vcruntime140.dll
17554ad4.60b4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll [avoiding WinVerifyTrust]
17564ad4.60b4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcp140.dll
17574ad4.60b4: supR3HardenedDllNotificationCallback: load 00007ffca1880000 LB 0x0001d000 C:\WINDOWS\SYSTEM32\VCRUNTIME140.dll [fFlags=0x0]
17584ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\vcruntime140.dll
17594ad4.60b4: supR3HardenedDllNotificationCallback: load 00007ffca1870000 LB 0x0000c000 C:\WINDOWS\SYSTEM32\VCRUNTIME140_1.dll [fFlags=0x0]
17604ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll [avoiding WinVerifyTrust]
17614ad4.60b4: supR3HardenedDllNotificationCallback: load 00007ffca1ed0000 LB 0x0008d000 C:\WINDOWS\SYSTEM32\MSVCP140.dll [fFlags=0x0]
17624ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcp140.dll
17634ad4.60b4: supR3HardenedDllNotificationCallback: load 00007ffcb8de0000 LB 0x00071000 C:\WINDOWS\System32\WS2_32.dll [fFlags=0x0]
17644ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ws2_32.dll
17654ad4.60b4: supR3HardenedDllNotificationCallback: load 00007ffc453f0000 LB 0x006f7000 C:\Program Files\Oracle\VirtualBox\VBoxRT.dll [fFlags=0x0]
17664ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll
17674ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
17684ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
17694ad4.60b4: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
17704ad4.60b4: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
17714ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb74e0000 'api-ms-win-core-synch-l1-2-0'
17724ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
17734ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
17744ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
17754ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
17764ad4.60b4: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
17774ad4.60b4: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
17784ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb74e0000 'api-ms-win-core-fibers-l1-1-1'
17794ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
17804ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
17814ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
17824ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
17834ad4.60b4: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
17844ad4.60b4: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
17854ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb74e0000 'api-ms-win-core-synch-l1-2-0'
17864ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
17874ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
17884ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
17894ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
17904ad4.60b4: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
17914ad4.60b4: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
17924ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb74e0000 'api-ms-win-core-fibers-l1-1-1'
17934ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
17944ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
17954ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
17964ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
17974ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\kernel32.dll
17984ad4.60b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\kernel32.dll (Input=kernel32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
17994ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb87e0000 'C:\WINDOWS\System32\kernel32.dll'
18004ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
18014ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
18024ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
18034ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
18044ad4.60b4: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-string-l1-1-0) -> 0x0, fPresent=1
18054ad4.60b4: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-string-l1-1-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
18064ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb74e0000 'api-ms-win-core-string-l1-1-0'
18074ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
18084ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
18094ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
18104ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
18114ad4.60b4: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-l1-2-1) -> 0x0, fPresent=1
18124ad4.60b4: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-l1-2-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
18134ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb74e0000 'api-ms-win-core-localization-l1-2-1'
18144ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
18154ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
18164ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
18174ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
18184ad4.60b4: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-datetime-l1-1-1) -> 0x0, fPresent=1
18194ad4.60b4: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-datetime-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
18204ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb74e0000 'api-ms-win-core-datetime-l1-1-1'
18214ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
18224ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
18234ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
18244ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
18254ad4.60b4: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-obsolete-l1-2-0) -> 0x0, fPresent=1
18264ad4.60b4: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-obsolete-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
18274ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb74e0000 'api-ms-win-core-localization-obsolete-l1-2-0'
18284ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
18294ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
18304ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
18314ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
18324ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll
18334ad4.60b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
18344ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc453f0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
18354ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
18364ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
18374ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
18384ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
18394ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll
18404ad4.60b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
18414ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc453f0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
18424ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
18434ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
18444ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
18454ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
18464ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll
18474ad4.60b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
18484ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc453f0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
18494ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
18504ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
18514ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
18524ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
18534ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll
18544ad4.60b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
18554ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc453f0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
18564ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
18574ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
18584ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
18594ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
18604ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll
18614ad4.60b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
18624ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc453f0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
18634ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
18644ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
18654ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
18664ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
18674ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll
18684ad4.60b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
18694ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc453f0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
18704ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
18714ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
18724ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
18734ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
18744ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc453f0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
18754ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
18764ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
18774ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
18784ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
18794ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc453f0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
18804ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
18814ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
18824ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
18834ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
18844ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc453f0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
18854ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
18864ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
18874ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
18884ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
18894ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc453f0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
18904ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
18914ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
18924ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
18934ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
18944ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc453f0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
18954ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
18964ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
18974ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
18984ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
18994ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc453f0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
19004ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
19014ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
19024ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
19034ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
19044ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc453f0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
19054ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
19064ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
19074ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
19084ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
19094ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll
19104ad4.60b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
19114ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc453f0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
19124ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
19134ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
19144ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
19154ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
19164ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc453f0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
19174ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
19184ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
19194ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
19204ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
19214ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc453f0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
19224ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
19234ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
19244ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
19254ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
19264ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc453f0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
19274ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
19284ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
19294ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
19304ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
19314ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc453f0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
19324ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
19334ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
19344ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
19354ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
19364ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc453f0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
19374ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
19384ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
19394ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
19404ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
19414ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc453f0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
19424ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
19434ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
19444ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
19454ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
19464ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc453f0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
19474ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
19484ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
19494ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
19504ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
19514ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc453f0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
19524ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
19534ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
19544ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
19554ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
19564ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc453f0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
19574ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
19584ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
19594ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
19604ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
19614ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc453f0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
19624ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
19634ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
19644ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
19654ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
19664ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc453f0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
19674ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
19684ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
19694ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
19704ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
19714ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc453f0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
19724ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
19734ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
19744ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
19754ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
19764ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc453f0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
19774ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
19784ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
19794ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
19804ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
19814ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc453f0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
19824ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
19834ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
19844ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
19854ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
19864ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc453f0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
19874ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
19884ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
19894ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
19904ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
19914ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll
19924ad4.60b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
19934ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc453f0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
19944ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
19954ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
19964ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
19974ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
19984ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc453f0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
19994ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
20004ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
20014ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
20024ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
20034ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc453f0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
20044ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'.
20054ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rescheduled]
20064ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc453f0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
20074ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll
20084ad4.60b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
20094ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
20104ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
20114ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll'
20124ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wintrust.dll
20134ad4.60b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
20144ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb73a0000 'C:\WINDOWS\system32\Wintrust.dll'
20154ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
20164ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
20174ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
20184ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
20194ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\system32\crypt32.dll'
20204ad4.60b4: SUPR3HardenedMain: Load TrustedMain...
20214ad4.6aa0: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-appmodel-runtime-l1-1-2) -> 0x0, fPresent=1
20224ad4.6aa0: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-appmodel-runtime-l1-1-2 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
20234ad4.6aa0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'msvcrt.dll'.
20244ad4.6aa0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\kernel.appcore.dll)
20254ad4.6aa0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\kernel.appcore.dll
20264ad4.6aa0: supR3HardenedDllNotificationCallback: load 00007ffcb62e0000 LB 0x00018000 C:\WINDOWS\SYSTEM32\kernel.appcore.dll [fFlags=0x0]
20274ad4.6aa0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\kernel.appcore.dll [avoiding WinVerifyTrust]
20284ad4.6aa0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62e0000 'api-ms-win-appmodel-runtime-l1-1-2'
20294ad4.6aa0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
20304ad4.6aa0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
20314ad4.6aa0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll
20324ad4.6aa0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
20334ad4.6aa0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
20344ad4.6aa0: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\kernel.appcore.dll'
20354ad4.60b4: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll: Signature #1/2: info status: 24202
20364ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
20374ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
20384ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'uicommon.dll'.
20394ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
20404ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vcruntime140.dll'.
20414ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vcruntime140_1.dll'.
20424ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qt5corevbox.dll'.
20434ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'qt5guivbox.dll'.
20444ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'qt5widgetsvbox.dll'.
20454ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'user32.dll'.
20464ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'advapi32.dll'.
20474ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'ole32.dll'.
20484ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'oleaut32.dll'.
20494ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'winmm.dll'.
20504ad4.60b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll) WinVerifyTrust
20514ad4.60b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll
20524ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
20534ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume3\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
20544ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
20554ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
20564ad4.60b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\winmm.dll) WinVerifyTrust
20574ad4.60b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\winmm.dll
20584ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
20594ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume3\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
20604ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
20614ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
20624ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
20634ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'combase.dll'.
20644ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'rpcrt4.dll'.
20654ad4.60b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\oleaut32.dll) WinVerifyTrust
20664ad4.60b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\oleaut32.dll
20674ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
20684ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
20694ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
20704ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
20714ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll
20724ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
20734ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
20744ad4.60b4: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\combase.dll'.
20754ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rpcrt4.dll'.
20764ad4.60b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\combase.dll)
20774ad4.60b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\combase.dll
20784ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
20794ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
20804ad4.60b4: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll'.
20814ad4.60b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll)
20824ad4.60b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\msvcp_win.dll
20834ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
20844ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
20854ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll
20864ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
20874ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
20884ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
20894ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #44 'gdi32.dll'.
20904ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #45 'user32.dll'.
20914ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #46 'combase.dll'.
20924ad4.60b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\ole32.dll) WinVerifyTrust
20934ad4.60b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\ole32.dll
20944ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
20954ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
20964ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\advapi32.dll
20974ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
20984ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
20994ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
21004ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
21014ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\combase.dll [lacks WinVerifyTrust]
21024ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
21034ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
21044ad4.60b4: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\user32.dll'.
21054ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'win32u.dll'.
21064ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #38 'gdi32.dll'.
21074ad4.60b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\user32.dll)
21084ad4.60b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\user32.dll
21094ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
21104ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
21114ad4.60b4: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32.dll'.
21124ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'win32u.dll'.
21134ad4.60b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\gdi32.dll)
21144ad4.60b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\gdi32.dll
21154ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
21164ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
21174ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcp_win.dll [lacks WinVerifyTrust]
21184ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
21194ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
21204ad4.60b4: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\win32u.dll'.
21214ad4.60b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\win32u.dll)
21224ad4.60b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\win32u.dll
21234ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
21244ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
21254ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
21264ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
21274ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
21284ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\win32u.dll [lacks WinVerifyTrust]
21294ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
21304ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
21314ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'win32u.dll'.
21324ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #38 'gdi32.dll'.
21334ad4.60b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\user32.dll) WinVerifyTrust
21344ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
21354ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
21364ad4.60b4: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll: Signature #1/2: info status: 24202
21374ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
21384ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
21394ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
21404ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
21414ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
21424ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\win32u.dll [lacks WinVerifyTrust]
21434ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
21444ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
21454ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'qt5guivbox.dll'.
21464ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'qt5corevbox.dll'.
21474ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'uxtheme.dll'.
21484ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'dwmapi.dll'.
21494ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'shell32.dll'.
21504ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ole32.dll'.
21514ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'gdi32.dll'.
21524ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'user32.dll'.
21534ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'msvcp140.dll'.
21544ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'msvcp140_1.dll'.
21554ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'vcruntime140.dll'.
21564ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'vcruntime140_1.dll'.
21574ad4.60b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll) WinVerifyTrust
21584ad4.60b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll
21594ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
21604ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
21614ad4.60b4: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll: Signature #1/2: info status: 24202
21624ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140_1.dll'...
21634ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140_1.dll' -> '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rcNtRedir=0xc0150008]
21644ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll
21654ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140.dll'...
21664ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140.dll' -> '\Device\HarddiskVolume3\Windows\System32\vcruntime140.dll' [rcNtRedir=0xc0150008]
21674ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\vcruntime140.dll
21684ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp140_1.dll'...
21694ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp140_1.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcp140_1.dll' [rcNtRedir=0xc0150008]
21704ad4.60b4: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\msvcp140_1.dll'.
21714ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp140.dll'.
21724ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vcruntime140.dll'.
21734ad4.60b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\msvcp140_1.dll)
21744ad4.60b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\msvcp140_1.dll
21754ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp140.dll'...
21764ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp140.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcp140.dll' [rcNtRedir=0xc0150008]
21774ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcp140.dll
21784ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
21794ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
21804ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\user32.dll [lacks WinVerifyTrust]
21814ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
21824ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
21834ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
21844ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
21854ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
21864ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ole32.dll
21874ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
21884ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume3\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
21894ad4.60b4: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\shell32.dll'.
21904ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
21914ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #72 'user32.dll'.
21924ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #74 'gdi32.dll'.
21934ad4.60b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\shell32.dll)
21944ad4.60b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\shell32.dll
21954ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dwmapi.dll'...
21964ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'dwmapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\dwmapi.dll' [rcNtRedir=0xc0150008]
21974ad4.60b4: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\dwmapi.dll'.
21984ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #24 'win32u.dll'.
21994ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'user32.dll'.
22004ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'gdi32.dll'.
22014ad4.60b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\dwmapi.dll)
22024ad4.60b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\dwmapi.dll
22034ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'uxtheme.dll'...
22044ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'uxtheme.dll' -> '\Device\HarddiskVolume3\Windows\System32\uxtheme.dll' [rcNtRedir=0xc0150008]
22054ad4.60b4: Detected WinVerifyTrust recursion: rc=22900 '\Device\HarddiskVolume3\Windows\System32\uxtheme.dll'.
22064ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #39 'gdi32.dll'.
22074ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #40 'user32.dll'.
22084ad4.60b4: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\uxtheme.dll)
22094ad4.60b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\uxtheme.dll
22104ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
22114ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
22124ad4.60b4: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll: Signature #1/2: info status: 24202
22134ad4.60b4: Detected WinVerifyTrust recursion: rc=24202 '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll'.
22144ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'mpr.dll'.
22154ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'userenv.dll'.
22164ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'version.dll'.
22174ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'netapi32.dll'.
22184ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ws2_32.dll'.
22194ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'advapi32.dll'.
22204ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'ole32.dll'.
22214ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'shell32.dll'.
22224ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'user32.dll'.
22234ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'winmm.dll'.
22244ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'msvcp140.dll'.
22254ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'msvcp140_1.dll'.
22264ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'vcruntime140.dll'.
22274ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'vcruntime140_1.dll'.
22284ad4.60b4: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll)
22294ad4.60b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
22304ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
22314ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
22324ad4.60b4: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll: Signature #1/2: info status: 24202
22334ad4.60b4: Detected WinVerifyTrust recursion: rc=24202 '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll'.
22344ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'd3d11.dll'.
22354ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'dxgi.dll'.
22364ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5corevbox.dll'.
22374ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ole32.dll'.
22384ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'opengl32.dll'.
22394ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
22404ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
22414ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'msvcp140.dll'.
22424ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'vcruntime140.dll'.
22434ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'vcruntime140_1.dll'.
22444ad4.60b4: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll)
22454ad4.60b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
22464ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140_1.dll'...
22474ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140_1.dll' -> '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rcNtRedir=0xc0150008]
22484ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll
22494ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140.dll'...
22504ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140.dll' -> '\Device\HarddiskVolume3\Windows\System32\vcruntime140.dll' [rcNtRedir=0xc0150008]
22514ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\vcruntime140.dll
22524ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp140.dll'...
22534ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp140.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcp140.dll' [rcNtRedir=0xc0150008]
22544ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcp140.dll
22554ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
22564ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
22574ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\user32.dll [lacks WinVerifyTrust]
22584ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
22594ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
22604ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
22614ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
22624ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume3\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
22634ad4.60b4: Detected WinVerifyTrust recursion: rc=22900 '\Device\HarddiskVolume3\Windows\System32\opengl32.dll'.
22644ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
22654ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
22664ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
22674ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'gdi32.dll'.
22684ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'glu32.dll'.
22694ad4.60b4: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\opengl32.dll)
22704ad4.60b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\opengl32.dll
22714ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
22724ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
22734ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ole32.dll
22744ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
22754ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
22764ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (24202) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [lacks WinVerifyTrust]
22774ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dxgi.dll'...
22784ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'dxgi.dll' -> '\Device\HarddiskVolume3\Windows\System32\dxgi.dll' [rcNtRedir=0xc0150008]
22794ad4.60b4: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\dxgi.dll'.
22804ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
22814ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'win32u.dll'.
22824ad4.60b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\dxgi.dll)
22834ad4.60b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\dxgi.dll
22844ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'd3d11.dll'...
22854ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'd3d11.dll' -> '\Device\HarddiskVolume3\Windows\System32\d3d11.dll' [rcNtRedir=0xc0150008]
22864ad4.60b4: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\d3d11.dll'.
22874ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
22884ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #28 'dxgi.dll'.
22894ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #30 'win32u.dll'.
22904ad4.60b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\d3d11.dll)
22914ad4.60b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\d3d11.dll
22924ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140_1.dll'...
22934ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140_1.dll' -> '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rcNtRedir=0xc0150008]
22944ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll
22954ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140.dll'...
22964ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140.dll' -> '\Device\HarddiskVolume3\Windows\System32\vcruntime140.dll' [rcNtRedir=0xc0150008]
22974ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\vcruntime140.dll
22984ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp140_1.dll'...
22994ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp140_1.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcp140_1.dll' [rcNtRedir=0xc0150008]
23004ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcp140_1.dll [lacks WinVerifyTrust]
23014ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp140.dll'...
23024ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp140.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcp140.dll' [rcNtRedir=0xc0150008]
23034ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcp140.dll
23044ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
23054ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume3\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
23064ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winmm.dll
23074ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
23084ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
23094ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\user32.dll [lacks WinVerifyTrust]
23104ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
23114ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume3\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
23124ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shell32.dll [lacks WinVerifyTrust]
23134ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
23144ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
23154ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ole32.dll
23164ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
23174ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
23184ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\advapi32.dll
23194ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
23204ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
23214ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ws2_32.dll
23224ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'netapi32.dll'...
23234ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'netapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\netapi32.dll' [rcNtRedir=0xc0150008]
23244ad4.60b4: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\netapi32.dll'.
23254ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
23264ad4.60b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\netapi32.dll)
23274ad4.60b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\netapi32.dll
23284ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'version.dll'...
23294ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'version.dll' -> '\Device\HarddiskVolume3\Windows\System32\version.dll' [rcNtRedir=0xc0150008]
23304ad4.60b4: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\version.dll'.
23314ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
23324ad4.60b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\version.dll)
23334ad4.60b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\version.dll
23344ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'userenv.dll'...
23354ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'userenv.dll' -> '\Device\HarddiskVolume3\Windows\System32\userenv.dll' [rcNtRedir=0xc0150008]
23364ad4.60b4: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\userenv.dll'.
23374ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #15 'rpcrt4.dll'.
23384ad4.60b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\userenv.dll)
23394ad4.60b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\userenv.dll
23404ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mpr.dll'...
23414ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'mpr.dll' -> '\Device\HarddiskVolume3\Windows\System32\mpr.dll' [rcNtRedir=0xc0150008]
23424ad4.60b4: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\mpr.dll'.
23434ad4.60b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\mpr.dll)
23444ad4.60b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\mpr.dll
23454ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
23464ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
23474ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\user32.dll [lacks WinVerifyTrust]
23484ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
23494ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
23504ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
23514ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
23524ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
23534ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
23544ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
23554ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
23564ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\user32.dll [lacks WinVerifyTrust]
23574ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
23584ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
23594ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\win32u.dll [lacks WinVerifyTrust]
23604ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
23614ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
23624ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
23634ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
23644ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
23654ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\user32.dll [lacks WinVerifyTrust]
23664ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
23674ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
23684ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcp_win.dll [lacks WinVerifyTrust]
23694ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140.dll'...
23704ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140.dll' -> '\Device\HarddiskVolume3\Windows\System32\vcruntime140.dll' [rcNtRedir=0xc0150008]
23714ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp140.dll'...
23724ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp140.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcp140.dll' [rcNtRedir=0xc0150008]
23734ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcp140.dll
23744ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
23754ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
23764ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
23774ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
23784ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll
23794ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
23804ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
23814ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll
23824ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
23834ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
23844ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\win32u.dll [lacks WinVerifyTrust]
23854ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dxgi.dll'...
23864ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'dxgi.dll' -> '\Device\HarddiskVolume3\Windows\System32\dxgi.dll' [rcNtRedir=0xc0150008]
23874ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dxgi.dll [lacks WinVerifyTrust]
23884ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
23894ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
23904ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcp_win.dll [lacks WinVerifyTrust]
23914ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
23924ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
23934ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\win32u.dll [lacks WinVerifyTrust]
23944ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
23954ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
23964ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcp_win.dll [lacks WinVerifyTrust]
23974ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'glu32.dll'...
23984ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'glu32.dll' -> '\Device\HarddiskVolume3\Windows\System32\glu32.dll' [rcNtRedir=0xc0150008]
23994ad4.60b4: Detected WinVerifyTrust recursion: rc=22900 '\Device\HarddiskVolume3\Windows\System32\glu32.dll'.
24004ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
24014ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
24024ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'opengl32.dll'.
24034ad4.60b4: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\glu32.dll)
24044ad4.60b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\glu32.dll
24054ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
24064ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
24074ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
24084ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
24094ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
24104ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\user32.dll [lacks WinVerifyTrust]
24114ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
24124ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
24134ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\advapi32.dll
24144ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
24154ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
24164ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll
24174ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
24184ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume3\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
24194ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (22900) on \Device\HarddiskVolume3\Windows\System32\opengl32.dll [lacks WinVerifyTrust]
24204ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
24214ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
24224ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\user32.dll [lacks WinVerifyTrust]
24234ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
24244ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
24254ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
24264ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
24274ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'd3d11.dll'.
24284ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'dxgi.dll'.
24294ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5corevbox.dll'.
24304ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ole32.dll'.
24314ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'opengl32.dll'.
24324ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
24334ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
24344ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'msvcp140.dll'.
24354ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'vcruntime140.dll'.
24364ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'vcruntime140_1.dll'.
24374ad4.60b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll) WinVerifyTrust
24384ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
24394ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
24404ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (24202) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [redoing WinVerifyTrust]
24414ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140_1.dll'...
24424ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140_1.dll' -> '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rcNtRedir=0xc0150008]
24434ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll
24444ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140.dll'...
24454ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140.dll' -> '\Device\HarddiskVolume3\Windows\System32\vcruntime140.dll' [rcNtRedir=0xc0150008]
24464ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp140.dll'...
24474ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp140.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcp140.dll' [rcNtRedir=0xc0150008]
24484ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcp140.dll
24494ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
24504ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
24514ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\user32.dll [lacks WinVerifyTrust]
24524ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
24534ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
24544ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
24554ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
24564ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume3\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
24574ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (22900) on \Device\HarddiskVolume3\Windows\System32\opengl32.dll [lacks WinVerifyTrust]
24584ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
24594ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
24604ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ole32.dll
24614ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
24624ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
24634ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (24202) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [lacks WinVerifyTrust]
24644ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dxgi.dll'...
24654ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'dxgi.dll' -> '\Device\HarddiskVolume3\Windows\System32\dxgi.dll' [rcNtRedir=0xc0150008]
24664ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dxgi.dll [lacks WinVerifyTrust]
24674ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'd3d11.dll'...
24684ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'd3d11.dll' -> '\Device\HarddiskVolume3\Windows\System32\d3d11.dll' [rcNtRedir=0xc0150008]
24694ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\d3d11.dll [lacks WinVerifyTrust]
24704ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
24714ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
24724ad4.60b4: supR3HardenedScreenImage/Imports: 0 (was 24202) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll'
24734ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140_1.dll'...
24744ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140_1.dll' -> '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rcNtRedir=0xc0150008]
24754ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll
24764ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140.dll'...
24774ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140.dll' -> '\Device\HarddiskVolume3\Windows\System32\vcruntime140.dll' [rcNtRedir=0xc0150008]
24784ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
24794ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
24804ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'uicommon.dll'...
24814ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'uicommon.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\uicommon.dll' [rcNtRedir=0xc0150008]
24824ad4.60b4: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\UICommon.dll: Signature #1/2: info status: 24202
24834ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
24844ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
24854ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'vboxrt.dll'.
24864ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vcruntime140.dll'.
24874ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vcruntime140_1.dll'.
24884ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qt5corevbox.dll'.
24894ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qt5guivbox.dll'.
24904ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'qt5widgetsvbox.dll'.
24914ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'qt5helpvbox.dll'.
24924ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'user32.dll'.
24934ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'advapi32.dll'.
24944ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #15 'ole32.dll'.
24954ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'oleaut32.dll'.
24964ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'rpcrt4.dll'.
24974ad4.60b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\UICommon.dll) WinVerifyTrust
24984ad4.60b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\UICommon.dll
24994ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
25004ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
25014ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
25024ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume3\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
25034ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\oleaut32.dll
25044ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
25054ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
25064ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ole32.dll
25074ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
25084ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
25094ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\advapi32.dll
25104ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
25114ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
25124ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\user32.dll [redoing WinVerifyTrust]
25134ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
25144ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
25154ad4.60b4: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\user32.dll'
25164ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5helpvbox.dll'...
25174ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5helpvbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5helpvbox.dll' [rcNtRedir=0xc0150008]
25184ad4.60b4: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5HelpVBox.dll: Signature #1/2: info status: 24202
25194ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
25204ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
25214ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'qt5widgetsvbox.dll'.
25224ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'qt5guivbox.dll'.
25234ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5sqlvbox.dll'.
25244ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qt5corevbox.dll'.
25254ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'vcruntime140.dll'.
25264ad4.60b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5HelpVBox.dll) WinVerifyTrust
25274ad4.60b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5HelpVBox.dll
25284ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
25294ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
25304ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll
25314ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
25324ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
25334ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (24202) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll [redoing WinVerifyTrust]
25344ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140.dll'...
25354ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140.dll' -> '\Device\HarddiskVolume3\Windows\System32\vcruntime140.dll' [rcNtRedir=0xc0150008]
25364ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
25374ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
25384ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
25394ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5sqlvbox.dll'...
25404ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5sqlvbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5sqlvbox.dll' [rcNtRedir=0xc0150008]
25414ad4.60b4: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5SqlVBox.dll: Signature #1/2: info status: 24202
25424ad4.60b4: Detected WinVerifyTrust recursion: rc=24202 '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5SqlVBox.dll'.
25434ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'qt5corevbox.dll'.
25444ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vcruntime140.dll'.
25454ad4.60b4: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5SqlVBox.dll)
25464ad4.60b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5SqlVBox.dll
25474ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
25484ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
25494ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (24202) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll [lacks WinVerifyTrust]
25504ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
25514ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
25524ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll
25534ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140.dll'...
25544ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140.dll' -> '\Device\HarddiskVolume3\Windows\System32\vcruntime140.dll' [rcNtRedir=0xc0150008]
25554ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
25564ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
25574ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
25584ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
25594ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
25604ad4.60b4: supR3HardenedScreenImage/Imports: 0 (was 24202) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll'
25614ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
25624ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
25634ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
25644ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140_1.dll'...
25654ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140_1.dll' -> '\Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll' [rcNtRedir=0xc0150008]
25664ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\vcruntime140_1.dll
25674ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140.dll'...
25684ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140.dll' -> '\Device\HarddiskVolume3\Windows\System32\vcruntime140.dll' [rcNtRedir=0xc0150008]
25694ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
25704ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
25714ad4.60b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000a01:<flags> [calling]
25724ad4.60b4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll
25734ad4.60b4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\UICommon.dll
25744ad4.60b4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
25754ad4.60b4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
25764ad4.60b4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll
25774ad4.60b4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winmm.dll
25784ad4.60b4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5HelpVBox.dll
25794ad4.60b4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\mpr.dll [avoiding WinVerifyTrust]
25804ad4.60b4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\userenv.dll [avoiding WinVerifyTrust]
25814ad4.60b4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\version.dll [avoiding WinVerifyTrust]
25824ad4.60b4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\netapi32.dll [avoiding WinVerifyTrust]
25834ad4.60b4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcp140_1.dll [avoiding WinVerifyTrust]
25844ad4.60b4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\d3d11.dll [avoiding WinVerifyTrust]
25854ad4.60b4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dxgi.dll [avoiding WinVerifyTrust]
25864ad4.60b4: supR3HardenedScreenImage/NtCreateSection: cache hit (22900) on \Device\HarddiskVolume3\Windows\System32\opengl32.dll [avoiding WinVerifyTrust]
25874ad4.60b4: supR3HardenedScreenImage/NtCreateSection: cache hit (22900) on \Device\HarddiskVolume3\Windows\System32\uxtheme.dll [avoiding WinVerifyTrust]
25884ad4.60b4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dwmapi.dll [avoiding WinVerifyTrust]
25894ad4.60b4: supR3HardenedScreenImage/NtCreateSection: cache hit (24202) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5SqlVBox.dll [avoiding WinVerifyTrust]
25904ad4.60b4: supR3HardenedScreenImage/NtCreateSection: cache hit (22900) on \Device\HarddiskVolume3\Windows\System32\glu32.dll [avoiding WinVerifyTrust]
25914ad4.60b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\netutils.dll)
25924ad4.60b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\netutils.dll
25934ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
25944ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'win32u.dll'.
25954ad4.60b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\DXCore.dll)
25964ad4.60b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\DXCore.dll
25974ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rpcrt4.dll'.
25984ad4.60b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\srvcli.dll)
25994ad4.60b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\srvcli.dll
26004ad4.60b4: supR3HardenedDllNotificationCallback: load 00007ffca7d40000 LB 0x0001e000 C:\WINDOWS\SYSTEM32\MPR.dll [fFlags=0x0]
26014ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\mpr.dll [avoiding WinVerifyTrust]
26024ad4.60b4: supR3HardenedDllNotificationCallback: load 00007ffcb68b0000 LB 0x00028000 C:\WINDOWS\SYSTEM32\USERENV.dll [fFlags=0x0]
26034ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\userenv.dll [avoiding WinVerifyTrust]
26044ad4.60b4: supR3HardenedDllNotificationCallback: load 00007ffcb14e0000 LB 0x0000a000 C:\WINDOWS\SYSTEM32\VERSION.dll [fFlags=0x0]
26054ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\version.dll [avoiding WinVerifyTrust]
26064ad4.60b4: supR3HardenedDllNotificationCallback: load 00007ffcaa490000 LB 0x00019000 C:\WINDOWS\SYSTEM32\NETAPI32.dll [fFlags=0x0]
26074ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\netapi32.dll [avoiding WinVerifyTrust]
26084ad4.60b4: supR3HardenedDllNotificationCallback: load 00007ffcb7410000 LB 0x0009a000 C:\WINDOWS\System32\msvcp_win.dll [fFlags=0x0]
26094ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcp_win.dll [avoiding WinVerifyTrust]
26104ad4.60b4: supR3HardenedDllNotificationCallback: load 00007ffcb74b0000 LB 0x00026000 C:\WINDOWS\System32\win32u.dll [fFlags=0x0]
26114ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\win32u.dll [avoiding WinVerifyTrust]
26124ad4.60b4: supR3HardenedDllNotificationCallback: load 00007ffcb8c30000 LB 0x001ae000 C:\WINDOWS\System32\USER32.dll [fFlags=0x0]
26134ad4.60b4: supR3HardenedDllNotificationCallback: load 00007ffcb7aa0000 LB 0x00119000 C:\WINDOWS\System32\gdi32full.dll [fFlags=0x0]
26144ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
26154ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #39 'gdi32.dll'.
26164ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #42 'user32.dll'.
26174ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #43 'win32u.dll'.
26184ad4.60b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\gdi32full.dll)
26194ad4.60b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\gdi32full.dll
26204ad4.60b4: supR3HardenedDllNotificationCallback: load 00007ffcb7db0000 LB 0x00029000 C:\WINDOWS\System32\GDI32.dll [fFlags=0x0]
26214ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [avoiding WinVerifyTrust]
26224ad4.60b4: supR3HardenedDllNotificationCallback: load 00007ffcb9850000 LB 0x00388000 C:\WINDOWS\System32\combase.dll [fFlags=0x0]
26234ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\combase.dll [avoiding WinVerifyTrust]
26244ad4.60b4: supR3HardenedDllNotificationCallback: load 00007ffcb9d20000 LB 0x001a5000 C:\WINDOWS\System32\ole32.dll [fFlags=0x0]
26254ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ole32.dll
26264ad4.60b4: supR3HardenedDllNotificationCallback: load 00007ffcb8e60000 LB 0x0085c000 C:\WINDOWS\System32\SHELL32.dll [fFlags=0x0]
26274ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shell32.dll [avoiding WinVerifyTrust]
26284ad4.60b4: supR3HardenedDllNotificationCallback: load 00007ffcadda0000 LB 0x00034000 C:\WINDOWS\SYSTEM32\WINMM.dll [fFlags=0x0]
26294ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winmm.dll
26304ad4.60b4: supR3HardenedDllNotificationCallback: load 00007ffcb0f90000 LB 0x00009000 C:\WINDOWS\SYSTEM32\MSVCP140_1.dll [fFlags=0x0]
26314ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcp140_1.dll [avoiding WinVerifyTrust]
26324ad4.60b4: supR3HardenedDllNotificationCallback: load 00007ffcb5d40000 LB 0x0000c000 C:\WINDOWS\SYSTEM32\NETUTILS.DLL [fFlags=0x0]
26334ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\netutils.dll [avoiding WinVerifyTrust]
26344ad4.60b4: supR3HardenedDllNotificationCallback: load 00007ffcaa460000 LB 0x00028000 C:\WINDOWS\SYSTEM32\SRVCLI.DLL [fFlags=0x0]
26354ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\srvcli.dll [avoiding WinVerifyTrust]
26364ad4.60b4: supR3HardenedDllNotificationCallback: load 00007ffc5e390000 LB 0x005c6000 C:\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [fFlags=0x0]
26374ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
26384ad4.60b4: supR3HardenedDllNotificationCallback: load 00007ffcb49c0000 LB 0x000f7000 C:\WINDOWS\SYSTEM32\dxgi.dll [fFlags=0x0]
26394ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dxgi.dll [avoiding WinVerifyTrust]
26404ad4.60b4: supR3HardenedDllNotificationCallback: load 00007ffcb25d0000 LB 0x00257000 C:\WINDOWS\SYSTEM32\d3d11.dll [fFlags=0x0]
26414ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\d3d11.dll [avoiding WinVerifyTrust]
26424ad4.60b4: supR3HardenedDllNotificationCallback: load 00007ffcb4890000 LB 0x00039000 C:\WINDOWS\SYSTEM32\dxcore.dll [fFlags=0x0]
26434ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\DXCore.dll [avoiding WinVerifyTrust]
26444ad4.60b4: supR3HardenedDllNotificationCallback: load 00007ffc570b0000 LB 0x0002d000 C:\WINDOWS\SYSTEM32\GLU32.dll [fFlags=0x0]
26454ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (22900) on \Device\HarddiskVolume3\Windows\System32\glu32.dll [avoiding WinVerifyTrust]
26464ad4.60b4: supR3HardenedDllNotificationCallback: load 00007ffc3a3b0000 LB 0x00100000 C:\WINDOWS\SYSTEM32\OPENGL32.dll [fFlags=0x0]
26474ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (22900) on \Device\HarddiskVolume3\Windows\System32\opengl32.dll [avoiding WinVerifyTrust]
26484ad4.60b4: supR3HardenedDllNotificationCallback: load 00007ffc5dd10000 LB 0x0067c000 C:\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll [fFlags=0x0]
26494ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
26504ad4.60b4: supR3HardenedDllNotificationCallback: load 00007ffcb47b0000 LB 0x000ab000 C:\WINDOWS\SYSTEM32\UxTheme.dll [fFlags=0x0]
26514ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (22900) on \Device\HarddiskVolume3\Windows\System32\uxtheme.dll [avoiding WinVerifyTrust]
26524ad4.60b4: supR3HardenedDllNotificationCallback: load 00007ffcb4bc0000 LB 0x0002b000 C:\WINDOWS\SYSTEM32\dwmapi.dll [fFlags=0x0]
26534ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dwmapi.dll [avoiding WinVerifyTrust]
26544ad4.60b4: supR3HardenedDllNotificationCallback: load 00007ffc5d400000 LB 0x00541000 C:\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll [fFlags=0x0]
26554ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll
26564ad4.60b4: supR3HardenedDllNotificationCallback: load 00007ffc958b0000 LB 0x00036000 C:\Program Files\Oracle\VirtualBox\Qt5SqlVBox.dll [fFlags=0x0]
26574ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (24202) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5SqlVBox.dll [avoiding WinVerifyTrust]
26584ad4.60b4: supR3HardenedDllNotificationCallback: load 00007ffc69c00000 LB 0x0006a000 C:\Program Files\Oracle\VirtualBox\Qt5HelpVBox.dll [fFlags=0x0]
26594ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5HelpVBox.dll
26604ad4.60b4: supR3HardenedDllNotificationCallback: load 00007ffcb9be0000 LB 0x000d7000 C:\WINDOWS\System32\OLEAUT32.dll [fFlags=0x0]
26614ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\oleaut32.dll
26624ad4.60b4: supR3HardenedDllNotificationCallback: load 00007ffc58e10000 LB 0x01bde000 C:\Program Files\Oracle\VirtualBox\UICommon.dll [fFlags=0x0]
26634ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\UICommon.dll
26644ad4.60b4: supR3HardenedDllNotificationCallback: load 00007ffc5dbc0000 LB 0x00147000 C:\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll [fFlags=0x0]
26654ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll
26664ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'win32u.dll'.
26674ad4.60b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\imm32.dll)
26684ad4.60b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\imm32.dll
26694ad4.60b4: supR3HardenedMonitor_NtCreateSection: NtMapViewOfSection failed on 000000000000059c (hFile=0000000000000508) with 0xc0000022 -> STATUS_TRUST_FAILURE
26704ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\imm32.dll'.
26714ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\imm32.dll' [rescheduled]
26724ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll'.
26734ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll' [rescheduled]
26744ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\srvcli.dll'.
26754ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\srvcli.dll' [rescheduled]
26764ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\DXCore.dll'.
26774ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\DXCore.dll' [rescheduled]
26784ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\netutils.dll'.
26794ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\netutils.dll' [rescheduled]
26804ad4.60b4: Detected loader lock ownership: rc=24202 '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5SqlVBox.dll'.
26814ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5SqlVBox.dll' [rescheduled]
26824ad4.60b4: Detected loader lock ownership: rc=22900 '\Device\HarddiskVolume3\Windows\System32\glu32.dll'.
26834ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\glu32.dll' [rescheduled]
26844ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\mpr.dll'.
26854ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\mpr.dll' [rescheduled]
26864ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\userenv.dll'.
26874ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\userenv.dll' [rescheduled]
26884ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\version.dll'.
26894ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\version.dll' [rescheduled]
26904ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\netapi32.dll'.
26914ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\netapi32.dll' [rescheduled]
26924ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\d3d11.dll'.
26934ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\d3d11.dll' [rescheduled]
26944ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\dxgi.dll'.
26954ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\dxgi.dll' [rescheduled]
26964ad4.60b4: Detected loader lock ownership: rc=22900 '\Device\HarddiskVolume3\Windows\System32\opengl32.dll'.
26974ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\opengl32.dll' [rescheduled]
26984ad4.60b4: Detected loader lock ownership: rc=22900 '\Device\HarddiskVolume3\Windows\System32\uxtheme.dll'.
26994ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\uxtheme.dll' [rescheduled]
27004ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\dwmapi.dll'.
27014ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\dwmapi.dll' [rescheduled]
27024ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\shell32.dll'.
27034ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\shell32.dll' [rescheduled]
27044ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\msvcp140_1.dll'.
27054ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\msvcp140_1.dll' [rescheduled]
27064ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\win32u.dll'.
27074ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rescheduled]
27084ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32.dll'.
27094ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rescheduled]
27104ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll'.
27114ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rescheduled]
27124ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\combase.dll'.
27134ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rescheduled]
27144ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\imm32.dll [redoing WinVerifyTrust]
27154ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\imm32.dll'.
27164ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume3\Windows\System32\imm32.dll
27174ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
27184ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
27194ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\win32u.dll [redoing WinVerifyTrust]
27204ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\win32u.dll'.
27214ad4.60b4: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume3\Windows\System32\win32u.dll
27224ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
27234ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
27244ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\win32u.dll [redoing WinVerifyTrust]
27254ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\win32u.dll'.
27264ad4.60b4: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume3\Windows\System32\win32u.dll
27274ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
27284ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
27294ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
27304ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
27314ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [redoing WinVerifyTrust]
27324ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32.dll'.
27334ad4.60b4: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume3\Windows\System32\gdi32.dll
27344ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
27354ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
27364ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcp_win.dll [redoing WinVerifyTrust]
27374ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll'.
27384ad4.60b4: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume3\Windows\System32\msvcp_win.dll
27394ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
27404ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
27414ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
27424ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
27434ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\win32u.dll [redoing WinVerifyTrust]
27444ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\win32u.dll'.
27454ad4.60b4: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume3\Windows\System32\win32u.dll
27464ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
27474ad4.60b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
27484ad4.60b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcp_win.dll [redoing WinVerifyTrust]
27494ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll'.
27504ad4.60b4: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume3\Windows\System32\msvcp_win.dll
27514ad4.60b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\IMM32.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
27524ad4.60b4: supR3HardenedDllNotificationCallback: load 00007ffcb88c0000 LB 0x00031000 C:\WINDOWS\System32\IMM32.DLL [fFlags=0x0]
27534ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\imm32.dll [avoiding WinVerifyTrust]
27544ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb88c0000 'C:\WINDOWS\system32\IMM32.DLL'
27554ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\imm32.dll'.
27564ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\imm32.dll' [rescheduled]
27574ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll'.
27584ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll' [rescheduled]
27594ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\srvcli.dll'.
27604ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\srvcli.dll' [rescheduled]
27614ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\DXCore.dll'.
27624ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\DXCore.dll' [rescheduled]
27634ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\netutils.dll'.
27644ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\netutils.dll' [rescheduled]
27654ad4.60b4: Detected loader lock ownership: rc=24202 '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5SqlVBox.dll'.
27664ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5SqlVBox.dll' [rescheduled]
27674ad4.60b4: Detected loader lock ownership: rc=22900 '\Device\HarddiskVolume3\Windows\System32\glu32.dll'.
27684ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\glu32.dll' [rescheduled]
27694ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\mpr.dll'.
27704ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\mpr.dll' [rescheduled]
27714ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\userenv.dll'.
27724ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\userenv.dll' [rescheduled]
27734ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\version.dll'.
27744ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\version.dll' [rescheduled]
27754ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\netapi32.dll'.
27764ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\netapi32.dll' [rescheduled]
27774ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\d3d11.dll'.
27784ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\d3d11.dll' [rescheduled]
27794ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\dxgi.dll'.
27804ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\dxgi.dll' [rescheduled]
27814ad4.60b4: Detected loader lock ownership: rc=22900 '\Device\HarddiskVolume3\Windows\System32\opengl32.dll'.
27824ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\opengl32.dll' [rescheduled]
27834ad4.60b4: Detected loader lock ownership: rc=22900 '\Device\HarddiskVolume3\Windows\System32\uxtheme.dll'.
27844ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\uxtheme.dll' [rescheduled]
27854ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\dwmapi.dll'.
27864ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\dwmapi.dll' [rescheduled]
27874ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\shell32.dll'.
27884ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\shell32.dll' [rescheduled]
27894ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\msvcp140_1.dll'.
27904ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\msvcp140_1.dll' [rescheduled]
27914ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\win32u.dll'.
27924ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rescheduled]
27934ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32.dll'.
27944ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rescheduled]
27954ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll'.
27964ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rescheduled]
27974ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\combase.dll'.
27984ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rescheduled]
27994ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\imm32.dll'.
28004ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\imm32.dll' [rescheduled]
28014ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll'.
28024ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll' [rescheduled]
28034ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\srvcli.dll'.
28044ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\srvcli.dll' [rescheduled]
28054ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\DXCore.dll'.
28064ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\DXCore.dll' [rescheduled]
28074ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\netutils.dll'.
28084ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\netutils.dll' [rescheduled]
28094ad4.60b4: Detected loader lock ownership: rc=24202 '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5SqlVBox.dll'.
28104ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5SqlVBox.dll' [rescheduled]
28114ad4.60b4: Detected loader lock ownership: rc=22900 '\Device\HarddiskVolume3\Windows\System32\glu32.dll'.
28124ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\glu32.dll' [rescheduled]
28134ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\mpr.dll'.
28144ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\mpr.dll' [rescheduled]
28154ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\userenv.dll'.
28164ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\userenv.dll' [rescheduled]
28174ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\version.dll'.
28184ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\version.dll' [rescheduled]
28194ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\netapi32.dll'.
28204ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\netapi32.dll' [rescheduled]
28214ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\d3d11.dll'.
28224ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\d3d11.dll' [rescheduled]
28234ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\dxgi.dll'.
28244ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\dxgi.dll' [rescheduled]
28254ad4.60b4: Detected loader lock ownership: rc=22900 '\Device\HarddiskVolume3\Windows\System32\opengl32.dll'.
28264ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\opengl32.dll' [rescheduled]
28274ad4.60b4: Detected loader lock ownership: rc=22900 '\Device\HarddiskVolume3\Windows\System32\uxtheme.dll'.
28284ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\uxtheme.dll' [rescheduled]
28294ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\dwmapi.dll'.
28304ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\dwmapi.dll' [rescheduled]
28314ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\shell32.dll'.
28324ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\shell32.dll' [rescheduled]
28334ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\msvcp140_1.dll'.
28344ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\msvcp140_1.dll' [rescheduled]
28354ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\win32u.dll'.
28364ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rescheduled]
28374ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32.dll'.
28384ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rescheduled]
28394ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll'.
28404ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rescheduled]
28414ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\combase.dll'.
28424ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rescheduled]
28434ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [redoing WinVerifyTrust]
28444ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32.dll'.
28454ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume3\Windows\System32\gdi32.dll
28464ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7db0000 'C:\WINDOWS\System32\gdi32.dll'
28474ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\imm32.dll'.
28484ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\imm32.dll' [rescheduled]
28494ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll'.
28504ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll' [rescheduled]
28514ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\srvcli.dll'.
28524ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\srvcli.dll' [rescheduled]
28534ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\DXCore.dll'.
28544ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\DXCore.dll' [rescheduled]
28554ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\netutils.dll'.
28564ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\netutils.dll' [rescheduled]
28574ad4.60b4: Detected loader lock ownership: rc=24202 '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5SqlVBox.dll'.
28584ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5SqlVBox.dll' [rescheduled]
28594ad4.60b4: Detected loader lock ownership: rc=22900 '\Device\HarddiskVolume3\Windows\System32\glu32.dll'.
28604ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\glu32.dll' [rescheduled]
28614ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\mpr.dll'.
28624ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\mpr.dll' [rescheduled]
28634ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\userenv.dll'.
28644ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\userenv.dll' [rescheduled]
28654ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\version.dll'.
28664ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\version.dll' [rescheduled]
28674ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\netapi32.dll'.
28684ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\netapi32.dll' [rescheduled]
28694ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\d3d11.dll'.
28704ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\d3d11.dll' [rescheduled]
28714ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\dxgi.dll'.
28724ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\dxgi.dll' [rescheduled]
28734ad4.60b4: Detected loader lock ownership: rc=22900 '\Device\HarddiskVolume3\Windows\System32\opengl32.dll'.
28744ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\opengl32.dll' [rescheduled]
28754ad4.60b4: Detected loader lock ownership: rc=22900 '\Device\HarddiskVolume3\Windows\System32\uxtheme.dll'.
28764ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\uxtheme.dll' [rescheduled]
28774ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\dwmapi.dll'.
28784ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\dwmapi.dll' [rescheduled]
28794ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\shell32.dll'.
28804ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\shell32.dll' [rescheduled]
28814ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\msvcp140_1.dll'.
28824ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\msvcp140_1.dll' [rescheduled]
28834ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\win32u.dll'.
28844ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rescheduled]
28854ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32.dll'.
28864ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rescheduled]
28874ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll'.
28884ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rescheduled]
28894ad4.60b4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\combase.dll'.
28904ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rescheduled]
28914ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc5dbc0000 'C:\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll'
28924ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
28934ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
28944ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\imm32.dll'
28954ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
28964ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
28974ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll'
28984ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
28994ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
29004ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\srvcli.dll'
29014ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
29024ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
29034ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\DXCore.dll'
29044ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
29054ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
29064ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\netutils.dll'
29074ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
29084ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
29094ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 24202) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5SqlVBox.dll'
29104ad4.60b4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000005bc pwszName=\Device\HarddiskVolume3\Windows\System32\glu32.dll
29114ad4.60b4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000029a0c2d5010
29124ad4.60b4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000029a0c2d5010
29134ad4.60b4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=E282E8708D3F395DD885A51198AB92FC954FEB93
29144ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
29154ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
29164ad4.60b4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0212~31bf3856ad364e35~amd64~~10.0.22621.3374.cat'; file='\Device\HarddiskVolume3\Windows\System32\glu32.dll'
29174ad4.60b4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
29184ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\glu32.dll'
29194ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
29204ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
29214ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\mpr.dll'
29224ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
29234ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
29244ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\userenv.dll'
29254ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
29264ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
29274ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\version.dll'
29284ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
29294ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
29304ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\netapi32.dll'
29314ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
29324ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
29334ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\d3d11.dll'
29344ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
29354ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
29364ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\dxgi.dll'
29374ad4.60b4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000005a8 pwszName=\Device\HarddiskVolume3\Windows\System32\opengl32.dll
29384ad4.60b4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000029a0c2d5010
29394ad4.60b4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000029a0c2d5010
29404ad4.60b4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=FA8479AEB25E866D14EB613903E2F9C454CD5B68
29414ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
29424ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll
29434ad4.60b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
29444ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
29454ad4.60b4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0212~31bf3856ad364e35~amd64~~10.0.22621.3527.cat'; file='\Device\HarddiskVolume3\Windows\System32\opengl32.dll'
29464ad4.60b4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
29474ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\opengl32.dll'
29484ad4.60b4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000514 pwszName=\Device\HarddiskVolume3\Windows\System32\uxtheme.dll
29494ad4.60b4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000029a0c2d5010
29504ad4.60b4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000029a0c2d5010
29514ad4.60b4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=D2E8973F51705FD020BE190A582194F512EF093F
29524ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
29534ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
29544ad4.60b4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package05~31bf3856ad364e35~amd64~~10.0.22621.3527.cat'; file='\Device\HarddiskVolume3\Windows\System32\uxtheme.dll'
29554ad4.60b4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
29564ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\uxtheme.dll'
29574ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
29584ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
29594ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\dwmapi.dll'
29604ad4.60b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll
29614ad4.60b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
29624ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
29634ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
29644ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\shell32.dll'
29654ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
29664ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
29674ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\msvcp140_1.dll'
29684ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
29694ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
29704ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\win32u.dll'
29714ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
29724ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
29734ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\gdi32.dll'
29744ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
29754ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
29764ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll'
29774ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
29784ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
29794ad4.60b4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\combase.dll'
29804ad4.60b4: SUPR3HardenedMain: Calling TrustedMain (00007ffc5dbc1c90)...
29814ad4.60b4: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\platforms\qwindows.dll: Signature #1/2: info status: 24202
29824ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb62a0000 'C:\WINDOWS\system32\rsaenh.dll'
29834ad4.60b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7230000 'C:\WINDOWS\System32\crypt32.dll'
29844ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'dwmapi.dll'.
29854ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'imm32.dll'.
29864ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'oleaut32.dll'.
29874ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'wtsapi32.dll'.
29884ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ole32.dll'.
29894ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
29904ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
29914ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'qt5guivbox.dll'.
29924ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'qt5corevbox.dll'.
29934ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'shell32.dll'.
29944ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'winmm.dll'.
29954ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'msvcp140.dll'.
29964ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'vcruntime140.dll'.
29974ad4.60b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'vcruntime140_1.dll'.
29984ad4.60b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\platforms\qwindows.dll) WinVerifyTrust
29994ad4.60b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\platforms\qwindows.dll

© 2024 Oracle Support Privacy / Do Not Sell My Info Terms of Use Trademark Policy Automated Access Etiquette