VirtualBox

Ticket #13580: VBoxStartup.2.log

File VBoxStartup.2.log, 346.4 KB (added by Frank Breitling, 9 years ago)
Line 
11ab0.c84: Log file opened: 5.0.0r101573 g_hStartupLog=0000000000000014 g_uNtVerCombined=0x611db110
21ab0.c84: \SystemRoot\System32\ntdll.dll:
31ab0.c84: CreationTime: 2015-06-09T21:45:47.268968200Z
41ab0.c84: LastWriteTime: 2015-05-25T18:21:21.289963400Z
51ab0.c84: ChangeTime: 2015-06-11T18:22:33.480821100Z
61ab0.c84: FileAttributes: 0x20
71ab0.c84: Size: 0x1a61c0
81ab0.c84: NT Headers: 0xe0
91ab0.c84: Timestamp: 0x556366f2
101ab0.c84: Machine: 0x8664 - amd64
111ab0.c84: Timestamp: 0x556366f2
121ab0.c84: Image Version: 6.1
131ab0.c84: SizeOfImage: 0x1a9000 (1740800)
141ab0.c84: Resource Dir: 0x14d000 LB 0x5a028
151ab0.c84: ProductName: Microsoft® Windows® Operating System
161ab0.c84: ProductVersion: 6.1.7601.18869
171ab0.c84: FileVersion: 6.1.7601.18869 (win7sp1_gdr.150525-0603)
181ab0.c84: FileDescription: NT Layer DLL
191ab0.c84: \SystemRoot\System32\kernel32.dll:
201ab0.c84: CreationTime: 2015-06-09T21:45:49.707107700Z
211ab0.c84: LastWriteTime: 2015-05-25T18:19:02.585000000Z
221ab0.c84: ChangeTime: 2015-06-11T18:22:33.714821500Z
231ab0.c84: FileAttributes: 0x20
241ab0.c84: Size: 0x11be00
251ab0.c84: NT Headers: 0xe8
261ab0.c84: Timestamp: 0x556366fc
271ab0.c84: Machine: 0x8664 - amd64
281ab0.c84: Timestamp: 0x556366fc
291ab0.c84: Image Version: 6.1
301ab0.c84: SizeOfImage: 0x11f000 (1175552)
311ab0.c84: Resource Dir: 0x116000 LB 0x528
321ab0.c84: ProductName: Microsoft® Windows® Operating System
331ab0.c84: ProductVersion: 6.1.7601.18869
341ab0.c84: FileVersion: 6.1.7601.18869 (win7sp1_gdr.150525-0603)
351ab0.c84: FileDescription: Windows NT BASE API Client DLL
361ab0.c84: \SystemRoot\System32\KernelBase.dll:
371ab0.c84: CreationTime: 2015-06-09T21:45:50.668162600Z
381ab0.c84: LastWriteTime: 2015-05-25T18:19:02.585000000Z
391ab0.c84: ChangeTime: 2015-06-11T18:22:33.714821500Z
401ab0.c84: FileAttributes: 0x20
411ab0.c84: Size: 0x67c00
421ab0.c84: NT Headers: 0xe8
431ab0.c84: Timestamp: 0x556366fd
441ab0.c84: Machine: 0x8664 - amd64
451ab0.c84: Timestamp: 0x556366fd
461ab0.c84: Image Version: 6.1
471ab0.c84: SizeOfImage: 0x6c000 (442368)
481ab0.c84: Resource Dir: 0x6a000 LB 0x530
491ab0.c84: ProductName: Microsoft® Windows® Operating System
501ab0.c84: ProductVersion: 6.1.7601.18869
511ab0.c84: FileVersion: 6.1.7601.18869 (win7sp1_gdr.150525-0603)
521ab0.c84: FileDescription: Windows NT BASE API Client DLL
531ab0.c84: \SystemRoot\System32\apisetschema.dll:
541ab0.c84: CreationTime: 2015-06-09T21:45:40.574585300Z
551ab0.c84: LastWriteTime: 2015-05-25T18:11:40.254000000Z
561ab0.c84: ChangeTime: 2015-06-11T18:22:33.449621000Z
571ab0.c84: FileAttributes: 0x20
581ab0.c84: Size: 0x1a00
591ab0.c84: NT Headers: 0xc0
601ab0.c84: Timestamp: 0x55636622
611ab0.c84: Machine: 0x8664 - amd64
621ab0.c84: Timestamp: 0x55636622
631ab0.c84: Image Version: 6.1
641ab0.c84: SizeOfImage: 0x50000 (327680)
651ab0.c84: Resource Dir: 0x30000 LB 0x3f8
661ab0.c84: ProductName: Microsoft® Windows® Operating System
671ab0.c84: ProductVersion: 6.1.7601.18869
681ab0.c84: FileVersion: 6.1.7601.18869 (win7sp1_gdr.150525-0603)
691ab0.c84: FileDescription: ApiSet Schema DLL
701ab0.c84: NtOpenDirectoryObject failed on \Driver: 0xc0000022
711ab0.c84: supR3HardenedWinFindAdversaries: 0x0
721ab0.c84: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
731ab0.c84: Calling main()
741ab0.c84: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
751ab0.c84: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
761ab0.c84: SUPR3HardenedMain: Respawn #1
771ab0.c84: System32: \Device\HarddiskVolume2\WINDOWS\System32
781ab0.c84: WinSxS: \Device\HarddiskVolume2\WINDOWS\winsxs
791ab0.c84: KnownDllPath: C:\Windows\system32
801ab0.c84: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
811ab0.c84: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe)
821ab0.c84: supR3HardNtEnableThreadCreation:
831ab0.c84: supR3HardNtDisableThreadCreation: pvLdrInitThunk=0000000077c9b780 pvNtTerminateThread=0000000077cbe0e0
841ab0.c84: supR3HardenedWinDoReSpawn(1): New child 1948.d38 [kernel32].
851ab0.c84: supR3HardNtChildGatherData: PebBaseAddress=000007fffffdb000 cbPeb=0x380
861ab0.c84: supR3HardNtPuChFindNtdll: uNtDllParentAddr=0000000077c70000 uNtDllChildAddr=0000000077c70000
871ab0.c84: supR3HardenedWinSetupChildInit: uLdrInitThunk=0000000077c9b780
881ab0.c84: supR3HardenedWinSetupChildInit: Start child.
891ab0.c84: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
901ab0.c84: supR3HardNtChildPurify: Startup delay kludge #1/0: 265 ms, 17 sleeps
911ab0.c84: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
921ab0.c84: *0000000000000000-fffffffffffeffff 0x0001/0x0000 0x0000000
931ab0.c84: *0000000000010000-fffffffffffeffff 0x0004/0x0004 0x0020000
941ab0.c84: *0000000000030000-000000000002bfff 0x0002/0x0002 0x0040000
951ab0.c84: 0000000000034000-0000000000027fff 0x0001/0x0000 0x0000000
961ab0.c84: *0000000000040000-000000000003efff 0x0004/0x0004 0x0020000
971ab0.c84: 0000000000041000-fffffffffff21fff 0x0001/0x0000 0x0000000
981ab0.c84: *0000000000160000-0000000000063fff 0x0000/0x0004 0x0020000
991ab0.c84: 000000000025c000-0000000000258fff 0x0104/0x0004 0x0020000
1001ab0.c84: 000000000025f000-000000000025dfff 0x0004/0x0004 0x0020000
1011ab0.c84: 0000000000260000-ffffffff8884ffff 0x0001/0x0000 0x0000000
1021ab0.c84: *0000000077c70000-0000000077c70fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\WINDOWS\System32\ntdll.dll
1031ab0.c84: 0000000077c71000-0000000077d6efff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\WINDOWS\System32\ntdll.dll
1041ab0.c84: 0000000077d6f000-0000000077d9dfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\WINDOWS\System32\ntdll.dll
1051ab0.c84: 0000000077d9e000-0000000077da5fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\WINDOWS\System32\ntdll.dll
1061ab0.c84: 0000000077da6000-0000000077da6fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\WINDOWS\System32\ntdll.dll
1071ab0.c84: 0000000077da7000-0000000077da9fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\WINDOWS\System32\ntdll.dll
1081ab0.c84: 0000000077daa000-0000000077e18fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\WINDOWS\System32\ntdll.dll
1091ab0.c84: 0000000077e19000-0000000070c51fff 0x0001/0x0000 0x0000000
1101ab0.c84: *000000007efe0000-000000007dfdffff 0x0000/0x0002 0x0020000
1111ab0.c84: *000000007ffe0000-000000007ffdefff 0x0002/0x0002 0x0020000
1121ab0.c84: 000000007ffe1000-000000007ffd1fff 0x0000/0x0002 0x0020000
1131ab0.c84: 000000007fff0000-ffffffffc079ffff 0x0001/0x0000 0x0000000
1141ab0.c84: *000000013f840000-000000013f840fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
1151ab0.c84: 000000013f841000-000000013f8c6fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
1161ab0.c84: 000000013f8c7000-000000013f8c7fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
1171ab0.c84: 000000013f8c8000-000000013f911fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
1181ab0.c84: 000000013f912000-000000013f912fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
1191ab0.c84: 000000013f913000-000000013f913fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
1201ab0.c84: 000000013f914000-000000013f915fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
1211ab0.c84: 000000013f916000-000000013f916fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
1221ab0.c84: 000000013f917000-000000013f917fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
1231ab0.c84: 000000013f918000-000000013f91bfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
1241ab0.c84: 000000013f91c000-000000013f965fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
1251ab0.c84: 000000013f966000-fffff8037f33bfff 0x0001/0x0000 0x0000000
1261ab0.c84: *000007fefff90000-000007fefff90fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\WINDOWS\System32\apisetschema.dll
1271ab0.c84: 000007fefff91000-000007fdfff71fff 0x0001/0x0000 0x0000000
1281ab0.c84: *000007fffffb0000-000007fffff8cfff 0x0002/0x0002 0x0040000
1291ab0.c84: 000007fffffd3000-000007fffffcafff 0x0001/0x0000 0x0000000
1301ab0.c84: *000007fffffdb000-000007fffffd9fff 0x0004/0x0004 0x0020000
1311ab0.c84: 000007fffffdc000-000007fffffd9fff 0x0001/0x0000 0x0000000
1321ab0.c84: *000007fffffde000-000007fffffdbfff 0x0004/0x0004 0x0020000
1331ab0.c84: *000007fffffe0000-000007fffffcffff 0x0001/0x0002 0x0020000
1341ab0.c84: apisetschema.dll: timestamp 0x55636622 (rc=VINF_SUCCESS)
1351ab0.c84: VirtualBox.exe: timestamp 0x559e485f (rc=VINF_SUCCESS)
1361ab0.c84: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
1371ab0.c84: '\Device\HarddiskVolume2\WINDOWS\System32\apisetschema.dll' has no imports
1381ab0.c84: '\Device\HarddiskVolume2\WINDOWS\System32\ntdll.dll' has no imports
1391ab0.c84: supR3HardNtChildPurify: Done after 296 ms and 0 fixes (loop #0).
1401ab0.c84: supR3HardNtEnableThreadCreation:
1411948.d38: Log file opened: 5.0.0r101573 g_hStartupLog=0000000000000004 g_uNtVerCombined=0x611db110
1421948.d38: supR3HardenedVmProcessInit: uNtDllAddr=0000000077c70000
1431948.d38: ntdll.dll: timestamp 0x556366f2 (rc=VINF_SUCCESS)
1441948.d38: New simple heap: #1 0000000000260000 LB 0x400000 (for 1740800 allocation)
1451948.d38: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
1461948.d38: System32: \Device\HarddiskVolume2\WINDOWS\System32
1471948.d38: WinSxS: \Device\HarddiskVolume2\WINDOWS\winsxs
1481948.d38: KnownDllPath: C:\Windows\system32
1491948.d38: supR3HardenedVmProcessInit: Opening vboxdrv stub...
1501948.d38: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
1511948.d38: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
1521948.d38: Registered Dll notification callback with NTDLL.
1531948.d38: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\WINDOWS\System32\kernel32.dll)
1541948.d38: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\kernel32.dll
1551948.d38: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
1561948.d38: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\kernel32.dll [lacks WinVerifyTrust]
1571948.d38: supR3HardenedDllNotificationCallback: load 0000000077b50000 LB 0x0011f000 C:\Windows\system32\kernel32.dll [fFlags=0x0]
1581948.d38: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\kernel32.dll [lacks WinVerifyTrust]
1591948.d38: supR3HardenedDllNotificationCallback: load 000007fefdd20000 LB 0x0006c000 C:\Windows\system32\KERNELBASE.dll [fFlags=0x0]
1601948.d38: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\WINDOWS\System32\KernelBase.dll)
1611948.d38: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\KernelBase.dll
1621948.d38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077b50000 'C:\Windows\system32\kernel32.dll'
1631948.d38: supR3HardNtDisableThreadCreation: pvLdrInitThunk=0000000077c9b780 pvNtTerminateThread=0000000077cbe0e0
1641ab0.c84: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 46 ms.
1651948.d38: \SystemRoot\System32\ntdll.dll:
1661948.d38: CreationTime: 2015-06-09T21:45:47.268968200Z
1671948.d38: LastWriteTime: 2015-05-25T18:21:21.289963400Z
1681948.d38: ChangeTime: 2015-06-11T18:22:33.480821100Z
1691948.d38: FileAttributes: 0x20
1701948.d38: Size: 0x1a61c0
1711948.d38: NT Headers: 0xe0
1721948.d38: Timestamp: 0x556366f2
1731948.d38: Machine: 0x8664 - amd64
1741948.d38: Timestamp: 0x556366f2
1751948.d38: Image Version: 6.1
1761948.d38: SizeOfImage: 0x1a9000 (1740800)
1771948.d38: Resource Dir: 0x14d000 LB 0x5a028
1781948.d38: ProductName: Microsoft® Windows® Operating System
1791948.d38: ProductVersion: 6.1.7601.18869
1801948.d38: FileVersion: 6.1.7601.18869 (win7sp1_gdr.150525-0603)
1811948.d38: FileDescription: NT Layer DLL
1821948.d38: \SystemRoot\System32\kernel32.dll:
1831948.d38: CreationTime: 2015-06-09T21:45:49.707107700Z
1841948.d38: LastWriteTime: 2015-05-25T18:19:02.585000000Z
1851948.d38: ChangeTime: 2015-06-11T18:22:33.714821500Z
1861948.d38: FileAttributes: 0x20
1871948.d38: Size: 0x11be00
1881948.d38: NT Headers: 0xe8
1891948.d38: Timestamp: 0x556366fc
1901948.d38: Machine: 0x8664 - amd64
1911948.d38: Timestamp: 0x556366fc
1921948.d38: Image Version: 6.1
1931948.d38: SizeOfImage: 0x11f000 (1175552)
1941948.d38: Resource Dir: 0x116000 LB 0x528
1951948.d38: ProductName: Microsoft® Windows® Operating System
1961948.d38: ProductVersion: 6.1.7601.18869
1971948.d38: FileVersion: 6.1.7601.18869 (win7sp1_gdr.150525-0603)
1981948.d38: FileDescription: Windows NT BASE API Client DLL
1991948.d38: \SystemRoot\System32\KernelBase.dll:
2001948.d38: CreationTime: 2015-06-09T21:45:50.668162600Z
2011948.d38: LastWriteTime: 2015-05-25T18:19:02.585000000Z
2021948.d38: ChangeTime: 2015-06-11T18:22:33.714821500Z
2031948.d38: FileAttributes: 0x20
2041948.d38: Size: 0x67c00
2051948.d38: NT Headers: 0xe8
2061948.d38: Timestamp: 0x556366fd
2071948.d38: Machine: 0x8664 - amd64
2081948.d38: Timestamp: 0x556366fd
2091948.d38: Image Version: 6.1
2101948.d38: SizeOfImage: 0x6c000 (442368)
2111948.d38: Resource Dir: 0x6a000 LB 0x530
2121948.d38: ProductName: Microsoft® Windows® Operating System
2131948.d38: ProductVersion: 6.1.7601.18869
2141948.d38: FileVersion: 6.1.7601.18869 (win7sp1_gdr.150525-0603)
2151948.d38: FileDescription: Windows NT BASE API Client DLL
2161948.d38: \SystemRoot\System32\apisetschema.dll:
2171948.d38: CreationTime: 2015-06-09T21:45:40.574585300Z
2181948.d38: LastWriteTime: 2015-05-25T18:11:40.254000000Z
2191948.d38: ChangeTime: 2015-06-11T18:22:33.449621000Z
2201948.d38: FileAttributes: 0x20
2211948.d38: Size: 0x1a00
2221948.d38: NT Headers: 0xc0
2231948.d38: Timestamp: 0x55636622
2241948.d38: Machine: 0x8664 - amd64
2251948.d38: Timestamp: 0x55636622
2261948.d38: Image Version: 6.1
2271948.d38: SizeOfImage: 0x50000 (327680)
2281948.d38: Resource Dir: 0x30000 LB 0x3f8
2291948.d38: ProductName: Microsoft® Windows® Operating System
2301948.d38: ProductVersion: 6.1.7601.18869
2311948.d38: FileVersion: 6.1.7601.18869 (win7sp1_gdr.150525-0603)
2321948.d38: FileDescription: ApiSet Schema DLL
2331948.d38: NtOpenDirectoryObject failed on \Driver: 0xc0000022
2341948.d38: supR3HardenedWinFindAdversaries: 0x0
2351948.d38: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
2361948.d38: Calling main()
2371948.d38: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
2381948.d38: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
2391948.d38: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
2401948.d38: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe)
2411948.d38: SUPR3HardenedMain: Respawn #2
2421948.d38: supR3HardNtEnableThreadCreation:
2431948.d38: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\WINDOWS\System32\apphelp.dll)
2441948.d38: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\apphelp.dll
2451948.d38: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\apphelp.dll (rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
2461948.d38: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\apphelp.dll [lacks WinVerifyTrust]
2471948.d38: supR3HardenedDllNotificationCallback: load 000007fefd860000 LB 0x00057000 C:\Windows\system32\apphelp.dll [fFlags=0x0]
2481948.d38: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\apphelp.dll [lacks WinVerifyTrust]
2491948.d38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd860000 'C:\Windows\system32\apphelp.dll'
2501948.d38: supR3HardNtDisableThreadCreation: pvLdrInitThunk=0000000077c9b780 pvNtTerminateThread=0000000077cbe0e0
2511948.d38: supR3HardenedWinDoReSpawn(2): New child 1b0c.192c [kernel32].
2521948.d38: supR3HardNtChildGatherData: PebBaseAddress=000007fffffd5000 cbPeb=0x380
2531948.d38: supR3HardNtPuChFindNtdll: uNtDllParentAddr=0000000077c70000 uNtDllChildAddr=0000000077c70000
2541948.d38: supR3HardenedWinSetupChildInit: uLdrInitThunk=0000000077c9b780
2551948.d38: supR3HardenedWinSetupChildInit: Start child.
2561948.d38: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
2571948.d38: supR3HardNtChildPurify: Startup delay kludge #1/0: 257 ms, 32 sleeps
2581948.d38: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
2591948.d38: *0000000000000000-fffffffffffeffff 0x0001/0x0000 0x0000000
2601948.d38: *0000000000010000-fffffffffffeffff 0x0004/0x0004 0x0020000
2611948.d38: *0000000000030000-000000000002bfff 0x0002/0x0002 0x0040000
2621948.d38: 0000000000034000-0000000000027fff 0x0001/0x0000 0x0000000
2631948.d38: *0000000000040000-000000000003efff 0x0004/0x0004 0x0020000
2641948.d38: 0000000000041000-fffffffffff31fff 0x0001/0x0000 0x0000000
2651948.d38: *0000000000150000-0000000000053fff 0x0000/0x0004 0x0020000
2661948.d38: 000000000024c000-0000000000248fff 0x0104/0x0004 0x0020000
2671948.d38: 000000000024f000-000000000024dfff 0x0004/0x0004 0x0020000
2681948.d38: 0000000000250000-ffffffff8882ffff 0x0001/0x0000 0x0000000
2691948.d38: *0000000077c70000-0000000077c70fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\WINDOWS\System32\ntdll.dll
2701948.d38: 0000000077c71000-0000000077d6efff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\WINDOWS\System32\ntdll.dll
2711948.d38: 0000000077d6f000-0000000077d9dfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\WINDOWS\System32\ntdll.dll
2721948.d38: 0000000077d9e000-0000000077da5fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\WINDOWS\System32\ntdll.dll
2731948.d38: 0000000077da6000-0000000077da6fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\WINDOWS\System32\ntdll.dll
2741948.d38: 0000000077da7000-0000000077da9fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\WINDOWS\System32\ntdll.dll
2751948.d38: 0000000077daa000-0000000077e18fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\WINDOWS\System32\ntdll.dll
2761948.d38: 0000000077e19000-0000000070c51fff 0x0001/0x0000 0x0000000
2771948.d38: *000000007efe0000-000000007dfdffff 0x0000/0x0002 0x0020000
2781948.d38: *000000007ffe0000-000000007ffdefff 0x0002/0x0002 0x0020000
2791948.d38: 000000007ffe1000-000000007ffd1fff 0x0000/0x0002 0x0020000
2801948.d38: 000000007fff0000-ffffffffc079ffff 0x0001/0x0000 0x0000000
2811948.d38: *000000013f840000-000000013f840fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
2821948.d38: 000000013f841000-000000013f8c6fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
2831948.d38: 000000013f8c7000-000000013f8c7fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
2841948.d38: 000000013f8c8000-000000013f911fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
2851948.d38: 000000013f912000-000000013f912fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
2861948.d38: 000000013f913000-000000013f913fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
2871948.d38: 000000013f914000-000000013f915fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
2881948.d38: 000000013f916000-000000013f916fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
2891948.d38: 000000013f917000-000000013f917fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
2901948.d38: 000000013f918000-000000013f91bfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
2911948.d38: 000000013f91c000-000000013f965fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
2921948.d38: 000000013f966000-fffff8037f33bfff 0x0001/0x0000 0x0000000
2931948.d38: *000007fefff90000-000007fefff90fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\WINDOWS\System32\apisetschema.dll
2941948.d38: 000007fefff91000-000007fdfff71fff 0x0001/0x0000 0x0000000
2951948.d38: *000007fffffb0000-000007fffff8cfff 0x0002/0x0002 0x0040000
2961948.d38: 000007fffffd3000-000007fffffd0fff 0x0001/0x0000 0x0000000
2971948.d38: *000007fffffd5000-000007fffffd3fff 0x0004/0x0004 0x0020000
2981948.d38: 000007fffffd6000-000007fffffcdfff 0x0001/0x0000 0x0000000
2991948.d38: *000007fffffde000-000007fffffdbfff 0x0004/0x0004 0x0020000
3001948.d38: *000007fffffe0000-000007fffffcffff 0x0001/0x0002 0x0020000
3011948.d38: apisetschema.dll: timestamp 0x55636622 (rc=VINF_SUCCESS)
3021948.d38: VirtualBox.exe: timestamp 0x559e485f (rc=VINF_SUCCESS)
3031948.d38: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
3041948.d38: '\Device\HarddiskVolume2\WINDOWS\System32\apisetschema.dll' has no imports
3051948.d38: '\Device\HarddiskVolume2\WINDOWS\System32\ntdll.dll' has no imports
3061948.d38: supR3HardNtChildPurify: Done after 296 ms and 0 fixes (loop #0).
3071948.d38: supR3HardenedEarlyCompact: Removed heap 1 (0x00000000260000 LB 0x400000)
3081948.d38: supR3HardNtEnableThreadCreation:
3091b0c.192c: Log file opened: 5.0.0r101573 g_hStartupLog=0000000000000004 g_uNtVerCombined=0x611db110
3101b0c.192c: supR3HardenedVmProcessInit: uNtDllAddr=0000000077c70000
3111b0c.192c: ntdll.dll: timestamp 0x556366f2 (rc=VINF_SUCCESS)
3121b0c.192c: New simple heap: #1 0000000000250000 LB 0x400000 (for 1740800 allocation)
3131b0c.192c: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
3141b0c.192c: System32: \Device\HarddiskVolume2\WINDOWS\System32
3151b0c.192c: WinSxS: \Device\HarddiskVolume2\WINDOWS\winsxs
3161b0c.192c: KnownDllPath: C:\Windows\system32
3171b0c.192c: supR3HardenedVmProcessInit: Opening vboxdrv...
3181b0c.192c: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
3191b0c.192c: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
3201b0c.192c: Registered Dll notification callback with NTDLL.
3211b0c.192c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\WINDOWS\System32\kernel32.dll)
3221b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\kernel32.dll
3231b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
3241b0c.192c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\kernel32.dll [lacks WinVerifyTrust]
3251b0c.192c: supR3HardenedDllNotificationCallback: load 0000000077b50000 LB 0x0011f000 C:\Windows\system32\kernel32.dll [fFlags=0x0]
3261b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\kernel32.dll [lacks WinVerifyTrust]
3271b0c.192c: supR3HardenedDllNotificationCallback: load 000007fefdd20000 LB 0x0006c000 C:\Windows\system32\KERNELBASE.dll [fFlags=0x0]
3281b0c.192c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\WINDOWS\System32\KernelBase.dll)
3291b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\KernelBase.dll
3301b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077b50000 'C:\Windows\system32\kernel32.dll'
3311b0c.192c: supR3HardNtDisableThreadCreation: pvLdrInitThunk=0000000077c9b780 pvNtTerminateThread=0000000077cbe0e0
3321948.d38: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 39 ms.
3331b0c.192c: \SystemRoot\System32\ntdll.dll:
3341b0c.192c: CreationTime: 2015-06-09T21:45:47.268968200Z
3351b0c.192c: LastWriteTime: 2015-05-25T18:21:21.289963400Z
3361b0c.192c: ChangeTime: 2015-06-11T18:22:33.480821100Z
3371b0c.192c: FileAttributes: 0x20
3381b0c.192c: Size: 0x1a61c0
3391b0c.192c: NT Headers: 0xe0
3401b0c.192c: Timestamp: 0x556366f2
3411b0c.192c: Machine: 0x8664 - amd64
3421b0c.192c: Timestamp: 0x556366f2
3431b0c.192c: Image Version: 6.1
3441b0c.192c: SizeOfImage: 0x1a9000 (1740800)
3451b0c.192c: Resource Dir: 0x14d000 LB 0x5a028
3461b0c.192c: ProductName: Microsoft® Windows® Operating System
3471b0c.192c: ProductVersion: 6.1.7601.18869
3481b0c.192c: FileVersion: 6.1.7601.18869 (win7sp1_gdr.150525-0603)
3491b0c.192c: FileDescription: NT Layer DLL
3501b0c.192c: \SystemRoot\System32\kernel32.dll:
3511b0c.192c: CreationTime: 2015-06-09T21:45:49.707107700Z
3521b0c.192c: LastWriteTime: 2015-05-25T18:19:02.585000000Z
3531b0c.192c: ChangeTime: 2015-06-11T18:22:33.714821500Z
3541b0c.192c: FileAttributes: 0x20
3551b0c.192c: Size: 0x11be00
3561b0c.192c: NT Headers: 0xe8
3571b0c.192c: Timestamp: 0x556366fc
3581b0c.192c: Machine: 0x8664 - amd64
3591b0c.192c: Timestamp: 0x556366fc
3601b0c.192c: Image Version: 6.1
3611b0c.192c: SizeOfImage: 0x11f000 (1175552)
3621b0c.192c: Resource Dir: 0x116000 LB 0x528
3631b0c.192c: ProductName: Microsoft® Windows® Operating System
3641b0c.192c: ProductVersion: 6.1.7601.18869
3651b0c.192c: FileVersion: 6.1.7601.18869 (win7sp1_gdr.150525-0603)
3661b0c.192c: FileDescription: Windows NT BASE API Client DLL
3671b0c.192c: \SystemRoot\System32\KernelBase.dll:
3681b0c.192c: CreationTime: 2015-06-09T21:45:50.668162600Z
3691b0c.192c: LastWriteTime: 2015-05-25T18:19:02.585000000Z
3701b0c.192c: ChangeTime: 2015-06-11T18:22:33.714821500Z
3711b0c.192c: FileAttributes: 0x20
3721b0c.192c: Size: 0x67c00
3731b0c.192c: NT Headers: 0xe8
3741b0c.192c: Timestamp: 0x556366fd
3751b0c.192c: Machine: 0x8664 - amd64
3761b0c.192c: Timestamp: 0x556366fd
3771b0c.192c: Image Version: 6.1
3781b0c.192c: SizeOfImage: 0x6c000 (442368)
3791b0c.192c: Resource Dir: 0x6a000 LB 0x530
3801b0c.192c: ProductName: Microsoft® Windows® Operating System
3811b0c.192c: ProductVersion: 6.1.7601.18869
3821b0c.192c: FileVersion: 6.1.7601.18869 (win7sp1_gdr.150525-0603)
3831b0c.192c: FileDescription: Windows NT BASE API Client DLL
3841b0c.192c: \SystemRoot\System32\apisetschema.dll:
3851b0c.192c: CreationTime: 2015-06-09T21:45:40.574585300Z
3861b0c.192c: LastWriteTime: 2015-05-25T18:11:40.254000000Z
3871b0c.192c: ChangeTime: 2015-06-11T18:22:33.449621000Z
3881b0c.192c: FileAttributes: 0x20
3891b0c.192c: Size: 0x1a00
3901b0c.192c: NT Headers: 0xc0
3911b0c.192c: Timestamp: 0x55636622
3921b0c.192c: Machine: 0x8664 - amd64
3931b0c.192c: Timestamp: 0x55636622
3941b0c.192c: Image Version: 6.1
3951b0c.192c: SizeOfImage: 0x50000 (327680)
3961b0c.192c: Resource Dir: 0x30000 LB 0x3f8
3971b0c.192c: ProductName: Microsoft® Windows® Operating System
3981b0c.192c: ProductVersion: 6.1.7601.18869
3991b0c.192c: FileVersion: 6.1.7601.18869 (win7sp1_gdr.150525-0603)
4001b0c.192c: FileDescription: ApiSet Schema DLL
4011b0c.192c: NtOpenDirectoryObject failed on \Driver: 0xc0000022
4021b0c.192c: supR3HardenedWinFindAdversaries: 0x0
4031b0c.192c: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
4041b0c.192c: Calling main()
4051b0c.192c: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
4061b0c.192c: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
4071b0c.192c: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
4081b0c.192c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe)
4091b0c.192c: SUPR3HardenedMain: Final process, opening VBoxDrv...
4101b0c.192c: supR3HardenedEarlyCompact: Removed heap 1 (0x00000000250000 LB 0x400000)
4111b0c.192c: supR3HardNtEnableThreadCreation:
4121b0c.192c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll)
4131b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll
4141b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c4390:C:\Windows\system32 [calling]
4151b0c.192c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
4161b0c.192c: supR3HardenedDllNotificationCallback: load 000007feec210000 LB 0x00005000 C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL [fFlags=0x0]
4171b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
4181b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
4191b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c4cb0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Dell\Dell Wireless WLAN Card;c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;c:\Program Files\WIDCOMM\Bluetooth Software\;c:\Program Files\WIDCOMM\Bluetooth Software\syswow64;c:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;U:\Windows\software\MPlayer;C:\Program Files (x86)\Skype\Phone\;U:\Windows\software\ffmpeg-20150803-git-5750d6c-win64-static\bin;U:\Windows\software\libav-i686-w64-mingw32-11.2\usr\bin;U:\Windows\software\MPlayer-extra [calling]
4201b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec210000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
4211b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
4221b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c4cb0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Dell\Dell Wireless WLAN Card;c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;c:\Program Files\WIDCOMM\Bluetooth Software\;c:\Program Files\WIDCOMM\Bluetooth Software\syswow64;c:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;U:\Windows\software\MPlayer;C:\Program Files (x86)\Skype\Phone\;U:\Windows\software\ffmpeg-20150803-git-5750d6c-win64-static\bin;U:\Windows\software\libav-i686-w64-mingw32-11.2\usr\bin;U:\Windows\software\MPlayer-extra [calling]
4231b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec210000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
4241b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec210000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
4251b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
4261b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'crypt32.dll'.
4271b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msasn1.dll'.
4281b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
4291b0c.192c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\WINDOWS\System32\wintrust.dll)
4301b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\wintrust.dll
4311b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
4321b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
4331b0c.192c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\WINDOWS\System32\rpcrt4.dll)
4341b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\rpcrt4.dll
4351b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
4361b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\msasn1.dll' [rcNtRedir=0xc0150008]
4371b0c.192c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\WINDOWS\System32\msasn1.dll)
4381b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\msasn1.dll
4391b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
4401b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\crypt32.dll' [rcNtRedir=0xc0150008]
4411b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
4421b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msasn1.dll'.
4431b0c.192c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\WINDOWS\System32\crypt32.dll)
4441b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\crypt32.dll
4451b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
4461b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
4471b0c.192c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll)
4481b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll
4491b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
4501b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\msasn1.dll' [rcNtRedir=0xc0150008]
4511b0c.192c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\msasn1.dll [lacks WinVerifyTrust]
4521b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
4531b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
4541b0c.192c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll [lacks WinVerifyTrust]
4551b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c4390:C:\Windows\system32 [calling]
4561b0c.192c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\wintrust.dll [lacks WinVerifyTrust]
4571b0c.192c: supR3HardenedDllNotificationCallback: load 000007fefdb30000 LB 0x0003b000 C:\Windows\system32\Wintrust.dll [fFlags=0x0]
4581b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\wintrust.dll [lacks WinVerifyTrust]
4591b0c.192c: supR3HardenedDllNotificationCallback: load 000007fefdde0000 LB 0x0009f000 C:\Windows\system32\msvcrt.dll [fFlags=0x0]
4601b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll [lacks WinVerifyTrust]
4611b0c.192c: supR3HardenedDllNotificationCallback: load 000007fefdba0000 LB 0x0016d000 C:\Windows\system32\CRYPT32.dll [fFlags=0x0]
4621b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\crypt32.dll [lacks WinVerifyTrust]
4631b0c.192c: supR3HardenedDllNotificationCallback: load 000007fefda30000 LB 0x0000f000 C:\Windows\system32\MSASN1.dll [fFlags=0x0]
4641b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\msasn1.dll [lacks WinVerifyTrust]
4651b0c.192c: supR3HardenedDllNotificationCallback: load 000007fefe370000 LB 0x0012d000 C:\Windows\system32\RPCRT4.dll [fFlags=0x0]
4661b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\rpcrt4.dll [lacks WinVerifyTrust]
4671b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdb30000 'C:\Windows\system32\Wintrust.dll'
4681b0c.192c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\WINDOWS\System32\bcrypt.dll)
4691b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\bcrypt.dll
4701b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcrypt.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000839b60:C:\Windows\system32 [calling]
4711b0c.192c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\bcrypt.dll [lacks WinVerifyTrust]
4721b0c.192c: supR3HardenedDllNotificationCallback: load 000007fefd3e0000 LB 0x00022000 C:\Windows\system32\bcrypt.dll [fFlags=0x0]
4731b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\bcrypt.dll [lacks WinVerifyTrust]
4741b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd3e0000 'C:\Windows\system32\bcrypt.dll'
4751b0c.192c: bcrypt.dll loaded at 000007fefd3e0000, BCryptOpenAlgorithmProvider at 000007fefd3e2640, preloading providers:
4761b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
4771b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'bcrypt.dll'.
4781b0c.192c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\bcryptprimitives.dll)
4791b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\bcryptprimitives.dll
4801b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
4811b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
4821b0c.192c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\bcrypt.dll [lacks WinVerifyTrust]
4831b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
4841b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\advapi32.dll' [rcNtRedir=0xc0150008]
4851b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
4861b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'rpcrt4.dll'.
4871b0c.192c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\WINDOWS\System32\advapi32.dll)
4881b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\advapi32.dll
4891b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
4901b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
4911b0c.192c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\rpcrt4.dll [lacks WinVerifyTrust]
4921b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
4931b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
4941b0c.192c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll [lacks WinVerifyTrust]
4951b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcryptprimitives.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c4cb0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Dell\Dell Wireless WLAN Card;c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;c:\Program Files\WIDCOMM\Bluetooth Software\;c:\Program Files\WIDCOMM\Bluetooth Software\syswow64;c:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;U:\Windows\software\MPlayer;C:\Program Files (x86)\Skype\Phone\;U:\Windows\software\ffmpeg-20150803-git-5750d6c-win64-static\bin;U:\Windows\software\libav-i686-w64-mingw32-11.2\usr\bin;U:\Windows\software\MPlayer-extra [calling]
4961b0c.192c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
4971b0c.192c: supR3HardenedDllNotificationCallback: load 000007fefcef0000 LB 0x0004c000 C:\Windows\system32\bcryptprimitives.dll [fFlags=0x0]
4981b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
4991b0c.192c: supR3HardenedDllNotificationCallback: load 000007feffa90000 LB 0x000db000 C:\Windows\system32\ADVAPI32.dll [fFlags=0x0]
5001b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\advapi32.dll [lacks WinVerifyTrust]
5011b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msvcrt.dll'.
5021b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'rpcrt4.dll'.
5031b0c.192c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\WINDOWS\System32\sechost.dll)
5041b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\sechost.dll
5051b0c.192c: supR3HardenedDllNotificationCallback: load 000007fefeb00000 LB 0x0001f000 C:\Windows\SYSTEM32\sechost.dll [fFlags=0x0]
5061b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\sechost.dll [lacks WinVerifyTrust]
5071b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcef0000 'C:\Windows\system32\bcryptprimitives.dll'
5081b0c.192c: BCryptOpenAlgorithmProvider(,'MD2',0,0) -> 0x0 (hAlgo=000000000083b240)
5091b0c.192c: BCryptOpenAlgorithmProvider(,'MD4',0,0) -> 0x0 (hAlgo=000000000083ca20)
5101b0c.192c: BCryptOpenAlgorithmProvider(,'MD5',0,0) -> 0x0 (hAlgo=000000000083dcb0)
5111b0c.192c: BCryptOpenAlgorithmProvider(,'SHA1',0,0) -> 0x0 (hAlgo=000000000083e420)
5121b0c.192c: BCryptOpenAlgorithmProvider(,'SHA256',0,0) -> 0x0 (hAlgo=000000000083e540)
5131b0c.192c: BCryptOpenAlgorithmProvider(,'SHA512',0,0) -> 0x0 (hAlgo=000000000083e660)
5141b0c.192c: BCryptOpenAlgorithmProvider(,'RSA',0,0) -> 0x0 (hAlgo=000000000083e8a0)
5151b0c.192c: BCryptOpenAlgorithmProvider(,'DSA',0,0) -> 0x0 (hAlgo=000000000083e9c0)
5161b0c.192c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\WINDOWS\System32\cryptsp.dll)
5171b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\cryptsp.dll
5181b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
5191b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
5201b0c.192c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\rpcrt4.dll [lacks WinVerifyTrust]
5211b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
5221b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
5231b0c.192c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll [lacks WinVerifyTrust]
5241b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTSP.dll (Input=CRYPTSP.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c4cb0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Dell\Dell Wireless WLAN Card;c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;c:\Program Files\WIDCOMM\Bluetooth Software\;c:\Program Files\WIDCOMM\Bluetooth Software\syswow64;c:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;U:\Windows\software\MPlayer;C:\Program Files (x86)\Skype\Phone\;U:\Windows\software\ffmpeg-20150803-git-5750d6c-win64-static\bin;U:\Windows\software\libav-i686-w64-mingw32-11.2\usr\bin;U:\Windows\software\MPlayer-extra [calling]
5251b0c.192c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\cryptsp.dll [lacks WinVerifyTrust]
5261b0c.192c: supR3HardenedDllNotificationCallback: load 000007fefd440000 LB 0x00018000 C:\Windows\system32\CRYPTSP.dll [fFlags=0x0]
5271b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\cryptsp.dll [lacks WinVerifyTrust]
5281b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd440000 'C:\Windows\system32\CRYPTSP.dll'
5291b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
5301b0c.192c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\rsaenh.dll)
5311b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\rsaenh.dll
5321b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
5331b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
5341b0c.192c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll [lacks WinVerifyTrust]
5351b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c4cb0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Dell\Dell Wireless WLAN Card;c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;c:\Program Files\WIDCOMM\Bluetooth Software\;c:\Program Files\WIDCOMM\Bluetooth Software\syswow64;c:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;U:\Windows\software\MPlayer;C:\Program Files (x86)\Skype\Phone\;U:\Windows\software\ffmpeg-20150803-git-5750d6c-win64-static\bin;U:\Windows\software\libav-i686-w64-mingw32-11.2\usr\bin;U:\Windows\software\MPlayer-extra [calling]
5361b0c.192c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\rsaenh.dll [lacks WinVerifyTrust]
5371b0c.192c: supR3HardenedDllNotificationCallback: load 000007fefcfa0000 LB 0x00047000 C:\Windows\system32\rsaenh.dll [fFlags=0x0]
5381b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\rsaenh.dll [lacks WinVerifyTrust]
5391b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcfa0000 'C:\Windows\system32\rsaenh.dll'
5401b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\advapi32.dll [lacks WinVerifyTrust]
5411b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ADVAPI32.dll (Input=ADVAPI32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c4cb0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Dell\Dell Wireless WLAN Card;c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;c:\Program Files\WIDCOMM\Bluetooth Software\;c:\Program Files\WIDCOMM\Bluetooth Software\syswow64;c:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;U:\Windows\software\MPlayer;C:\Program Files (x86)\Skype\Phone\;U:\Windows\software\ffmpeg-20150803-git-5750d6c-win64-static\bin;U:\Windows\software\libav-i686-w64-mingw32-11.2\usr\bin;U:\Windows\software\MPlayer-extra [calling]
5421b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feffa90000 'C:\Windows\system32\ADVAPI32.dll'
5431b0c.192c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\WINDOWS\System32\cryptbase.dll)
5441b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\cryptbase.dll
5451b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTBASE.dll (Input=CRYPTBASE.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c4cb0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Dell\Dell Wireless WLAN Card;c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;c:\Program Files\WIDCOMM\Bluetooth Software\;c:\Program Files\WIDCOMM\Bluetooth Software\syswow64;c:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;U:\Windows\software\MPlayer;C:\Program Files (x86)\Skype\Phone\;U:\Windows\software\ffmpeg-20150803-git-5750d6c-win64-static\bin;U:\Windows\software\libav-i686-w64-mingw32-11.2\usr\bin;U:\Windows\software\MPlayer-extra [calling]
5461b0c.192c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\cryptbase.dll [lacks WinVerifyTrust]
5471b0c.192c: supR3HardenedDllNotificationCallback: load 000007fefd8c0000 LB 0x0000f000 C:\Windows\system32\CRYPTBASE.dll [fFlags=0x0]
5481b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\cryptbase.dll [lacks WinVerifyTrust]
5491b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd8c0000 'C:\Windows\system32\CRYPTBASE.dll'
5501b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\kernel32.dll [lacks WinVerifyTrust]
5511b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c4cb0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Dell\Dell Wireless WLAN Card;c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;c:\Program Files\WIDCOMM\Bluetooth Software\;c:\Program Files\WIDCOMM\Bluetooth Software\syswow64;c:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;U:\Windows\software\MPlayer;C:\Program Files (x86)\Skype\Phone\;U:\Windows\software\ffmpeg-20150803-git-5750d6c-win64-static\bin;U:\Windows\software\libav-i686-w64-mingw32-11.2\usr\bin;U:\Windows\software\MPlayer-extra [calling]
5521b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077b50000 'C:\Windows\system32\kernel32.dll'
5531b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\wintrust.dll [lacks WinVerifyTrust]
5541b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\WINTRUST.DLL (Input=WINTRUST.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c4cb0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Dell\Dell Wireless WLAN Card;c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;c:\Program Files\WIDCOMM\Bluetooth Software\;c:\Program Files\WIDCOMM\Bluetooth Software\syswow64;c:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;U:\Windows\software\MPlayer;C:\Program Files (x86)\Skype\Phone\;U:\Windows\software\ffmpeg-20150803-git-5750d6c-win64-static\bin;U:\Windows\software\libav-i686-w64-mingw32-11.2\usr\bin;U:\Windows\software\MPlayer-extra [calling]
5551b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdb30000 'C:\Windows\system32\WINTRUST.DLL'
5561b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\crypt32.dll [lacks WinVerifyTrust]
5571b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPT32.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00000000007c4cb0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Dell\Dell Wireless WLAN Card;c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;c:\Program Files\WIDCOMM\Bluetooth Software\;c:\Program Files\WIDCOMM\Bluetooth Software\syswow64;c:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;U:\Windows\software\MPlayer;C:\Program Files (x86)\Skype\Phone\;U:\Windows\software\ffmpeg-20150803-git-5750d6c-win64-static\bin;U:\Windows\software\libav-i686-w64-mingw32-11.2\usr\bin;U:\Windows\software\MPlayer-extra [calling]
5581b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdba0000 'C:\Windows\system32\CRYPT32.dll'
5591b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
5601b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'advapi32.dll'.
5611b0c.192c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\WINDOWS\System32\imagehlp.dll)
5621b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\imagehlp.dll
5631b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
5641b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\advapi32.dll' [rcNtRedir=0xc0150008]
5651b0c.192c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\advapi32.dll [lacks WinVerifyTrust]
5661b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
5671b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
5681b0c.192c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll [lacks WinVerifyTrust]
5691b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\imagehlp.dll (Input=imagehlp.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c4cb0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Dell\Dell Wireless WLAN Card;c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;c:\Program Files\WIDCOMM\Bluetooth Software\;c:\Program Files\WIDCOMM\Bluetooth Software\syswow64;c:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;U:\Windows\software\MPlayer;C:\Program Files (x86)\Skype\Phone\;U:\Windows\software\ffmpeg-20150803-git-5750d6c-win64-static\bin;U:\Windows\software\libav-i686-w64-mingw32-11.2\usr\bin;U:\Windows\software\MPlayer-extra [calling]
5701b0c.192c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\imagehlp.dll [lacks WinVerifyTrust]
5711b0c.192c: supR3HardenedDllNotificationCallback: load 000007feffc80000 LB 0x00019000 C:\Windows\system32\imagehlp.dll [fFlags=0x0]
5721b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\imagehlp.dll [lacks WinVerifyTrust]
5731b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feffc80000 'C:\Windows\system32\imagehlp.dll'
5741b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\cryptsp.dll [lacks WinVerifyTrust]
5751b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTSP.dll (Input=CRYPTSP.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c4cb0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Dell\Dell Wireless WLAN Card;c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;c:\Program Files\WIDCOMM\Bluetooth Software\;c:\Program Files\WIDCOMM\Bluetooth Software\syswow64;c:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;U:\Windows\software\MPlayer;C:\Program Files (x86)\Skype\Phone\;U:\Windows\software\ffmpeg-20150803-git-5750d6c-win64-static\bin;U:\Windows\software\libav-i686-w64-mingw32-11.2\usr\bin;U:\Windows\software\MPlayer-extra [calling]
5761b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd440000 'C:\Windows\system32\CRYPTSP.dll'
5771b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
5781b0c.192c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\WINDOWS\System32\user32.dll)
5791b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\user32.dll
5801b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
5811b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\gdi32.dll' [rcNtRedir=0xc0150008]
5821b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
5831b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'lpk.dll'.
5841b0c.192c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\WINDOWS\System32\gdi32.dll)
5851b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\gdi32.dll
5861b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'lpk.dll'...
5871b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'lpk.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\lpk.dll' [rcNtRedir=0xc0150008]
5881b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'gdi32.dll'.
5891b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'user32.dll'.
5901b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'usp10.dll'.
5911b0c.192c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\WINDOWS\System32\lpk.dll)
5921b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\lpk.dll
5931b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
5941b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\user32.dll' [rcNtRedir=0xc0150008]
5951b0c.192c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\user32.dll [lacks WinVerifyTrust]
5961b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'usp10.dll'...
5971b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'usp10.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\usp10.dll' [rcNtRedir=0xc0150008]
5981b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
5991b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
6001b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'gdi32.dll'.
6011b0c.192c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\WINDOWS\System32\usp10.dll)
6021b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\usp10.dll
6031b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
6041b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\user32.dll' [rcNtRedir=0xc0150008]
6051b0c.192c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\user32.dll [lacks WinVerifyTrust]
6061b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
6071b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\gdi32.dll' [rcNtRedir=0xc0150008]
6081b0c.192c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\gdi32.dll [lacks WinVerifyTrust]
6091b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
6101b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\gdi32.dll' [rcNtRedir=0xc0150008]
6111b0c.192c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\gdi32.dll [lacks WinVerifyTrust]
6121b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
6131b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\user32.dll' [rcNtRedir=0xc0150008]
6141b0c.192c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\user32.dll [lacks WinVerifyTrust]
6151b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
6161b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
6171b0c.192c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll [lacks WinVerifyTrust]
6181b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\USER32.dll (Input=USER32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c4cb0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Dell\Dell Wireless WLAN Card;c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;c:\Program Files\WIDCOMM\Bluetooth Software\;c:\Program Files\WIDCOMM\Bluetooth Software\syswow64;c:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;U:\Windows\software\MPlayer;C:\Program Files (x86)\Skype\Phone\;U:\Windows\software\ffmpeg-20150803-git-5750d6c-win64-static\bin;U:\Windows\software\libav-i686-w64-mingw32-11.2\usr\bin;U:\Windows\software\MPlayer-extra [calling]
6191b0c.192c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\user32.dll [lacks WinVerifyTrust]
6201b0c.192c: supR3HardenedDllNotificationCallback: load 0000000077a50000 LB 0x000fa000 C:\Windows\system32\USER32.dll [fFlags=0x0]
6211b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\user32.dll [lacks WinVerifyTrust]
6221b0c.192c: supR3HardenedDllNotificationCallback: load 000007fefe570000 LB 0x00067000 C:\Windows\system32\GDI32.dll [fFlags=0x0]
6231b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\gdi32.dll [lacks WinVerifyTrust]
6241b0c.192c: supR3HardenedDllNotificationCallback: load 000007fefeaf0000 LB 0x0000e000 C:\Windows\system32\LPK.dll [fFlags=0x0]
6251b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\lpk.dll [lacks WinVerifyTrust]
6261b0c.192c: supR3HardenedDllNotificationCallback: load 000007fefe2a0000 LB 0x000c9000 C:\Windows\system32\USP10.dll [fFlags=0x0]
6271b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\usp10.dll [lacks WinVerifyTrust]
6281b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\gdi32.dll [lacks WinVerifyTrust]
6291b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\gdi32.dll (Input=gdi32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c4cb0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Dell\Dell Wireless WLAN Card;c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;c:\Program Files\WIDCOMM\Bluetooth Software\;c:\Program Files\WIDCOMM\Bluetooth Software\syswow64;c:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;U:\Windows\software\MPlayer;C:\Program Files (x86)\Skype\Phone\;U:\Windows\software\ffmpeg-20150803-git-5750d6c-win64-static\bin;U:\Windows\software\libav-i686-w64-mingw32-11.2\usr\bin;U:\Windows\software\MPlayer-extra [calling]
6301b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe570000 'C:\Windows\system32\gdi32.dll'
6311b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'user32.dll'.
6321b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
6331b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msctf.dll'.
6341b0c.192c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\WINDOWS\System32\imm32.dll)
6351b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\imm32.dll
6361b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msctf.dll'...
6371b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msctf.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\msctf.dll' [rcNtRedir=0xc0150008]
6381b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
6391b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
6401b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'gdi32.dll'.
6411b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'imm32.dll'.
6421b0c.192c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\WINDOWS\System32\msctf.dll)
6431b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\msctf.dll
6441b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
6451b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\gdi32.dll' [rcNtRedir=0xc0150008]
6461b0c.192c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\gdi32.dll [lacks WinVerifyTrust]
6471b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
6481b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\user32.dll' [rcNtRedir=0xc0150008]
6491b0c.192c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\user32.dll [lacks WinVerifyTrust]
6501b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
6511b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\imm32.dll' [rcNtRedir=0xc0150008]
6521b0c.192c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\imm32.dll [lacks WinVerifyTrust]
6531b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
6541b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\gdi32.dll' [rcNtRedir=0xc0150008]
6551b0c.192c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\gdi32.dll [lacks WinVerifyTrust]
6561b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
6571b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\user32.dll' [rcNtRedir=0xc0150008]
6581b0c.192c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\user32.dll [lacks WinVerifyTrust]
6591b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
6601b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
6611b0c.192c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll [lacks WinVerifyTrust]
6621b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\IMM32.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c4cb0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Dell\Dell Wireless WLAN Card;c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;c:\Program Files\WIDCOMM\Bluetooth Software\;c:\Program Files\WIDCOMM\Bluetooth Software\syswow64;c:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;U:\Windows\software\MPlayer;C:\Program Files (x86)\Skype\Phone\;U:\Windows\software\ffmpeg-20150803-git-5750d6c-win64-static\bin;U:\Windows\software\libav-i686-w64-mingw32-11.2\usr\bin;U:\Windows\software\MPlayer-extra [calling]
6631b0c.192c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\imm32.dll [lacks WinVerifyTrust]
6641b0c.192c: supR3HardenedDllNotificationCallback: load 000007feffc50000 LB 0x0002e000 C:\Windows\system32\IMM32.DLL [fFlags=0x0]
6651b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\imm32.dll [lacks WinVerifyTrust]
6661b0c.192c: supR3HardenedDllNotificationCallback: load 000007fefe090000 LB 0x00109000 C:\Windows\system32\MSCTF.dll [fFlags=0x0]
6671b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\msctf.dll [lacks WinVerifyTrust]
6681b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feffc50000 'C:\Windows\system32\IMM32.DLL'
6691b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077a50000 'C:\Windows\system32\USER32.dll'
6701b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'bcrypt.dll'.
6711b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
6721b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msasn1.dll'.
6731b0c.192c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\WINDOWS\System32\ncrypt.dll)
6741b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\ncrypt.dll
6751b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
6761b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\msasn1.dll' [rcNtRedir=0xc0150008]
6771b0c.192c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\msasn1.dll [lacks WinVerifyTrust]
6781b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
6791b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
6801b0c.192c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll [lacks WinVerifyTrust]
6811b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
6821b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
6831b0c.192c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\bcrypt.dll [lacks WinVerifyTrust]
6841b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ncrypt.dll (Input=ncrypt.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c4cb0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Dell\Dell Wireless WLAN Card;c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;c:\Program Files\WIDCOMM\Bluetooth Software\;c:\Program Files\WIDCOMM\Bluetooth Software\syswow64;c:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;U:\Windows\software\MPlayer;C:\Program Files (x86)\Skype\Phone\;U:\Windows\software\ffmpeg-20150803-git-5750d6c-win64-static\bin;U:\Windows\software\libav-i686-w64-mingw32-11.2\usr\bin;U:\Windows\software\MPlayer-extra [calling]
6851b0c.192c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\ncrypt.dll [lacks WinVerifyTrust]
6861b0c.192c: supR3HardenedDllNotificationCallback: load 000007fefd310000 LB 0x00050000 C:\Windows\system32\ncrypt.dll [fFlags=0x0]
6871b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\ncrypt.dll [lacks WinVerifyTrust]
6881b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd310000 'C:\Windows\system32\ncrypt.dll'
6891b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\bcrypt.dll [lacks WinVerifyTrust]
6901b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcrypt.dll (Input=bcrypt.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c4cb0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Dell\Dell Wireless WLAN Card;c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;c:\Program Files\WIDCOMM\Bluetooth Software\;c:\Program Files\WIDCOMM\Bluetooth Software\syswow64;c:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;U:\Windows\software\MPlayer;C:\Program Files (x86)\Skype\Phone\;U:\Windows\software\ffmpeg-20150803-git-5750d6c-win64-static\bin;U:\Windows\software\libav-i686-w64-mingw32-11.2\usr\bin;U:\Windows\software\MPlayer-extra [calling]
6911b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd3e0000 'C:\Windows\system32\bcrypt.dll'
6921b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
6931b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'rpcrt4.dll'.
6941b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'profapi.dll'.
6951b0c.192c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\WINDOWS\System32\userenv.dll)
6961b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\userenv.dll
6971b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'profapi.dll'...
6981b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'profapi.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\profapi.dll' [rcNtRedir=0xc0150008]
6991b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
7001b0c.192c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\WINDOWS\System32\profapi.dll)
7011b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\profapi.dll
7021b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
7031b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
7041b0c.192c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\rpcrt4.dll [lacks WinVerifyTrust]
7051b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
7061b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
7071b0c.192c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll [lacks WinVerifyTrust]
7081b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
7091b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
7101b0c.192c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll [lacks WinVerifyTrust]
7111b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\USERENV.dll (Input=USERENV.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c4cb0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Dell\Dell Wireless WLAN Card;c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;c:\Program Files\WIDCOMM\Bluetooth Software\;c:\Program Files\WIDCOMM\Bluetooth Software\syswow64;c:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;U:\Windows\software\MPlayer;C:\Program Files (x86)\Skype\Phone\;U:\Windows\software\ffmpeg-20150803-git-5750d6c-win64-static\bin;U:\Windows\software\libav-i686-w64-mingw32-11.2\usr\bin;U:\Windows\software\MPlayer-extra [calling]
7121b0c.192c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\userenv.dll [lacks WinVerifyTrust]
7131b0c.192c: supR3HardenedDllNotificationCallback: load 000007fefdb00000 LB 0x0001e000 C:\Windows\system32\USERENV.dll [fFlags=0x0]
7141b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\userenv.dll [lacks WinVerifyTrust]
7151b0c.192c: supR3HardenedDllNotificationCallback: load 000007fefda20000 LB 0x0000f000 C:\Windows\system32\profapi.dll [fFlags=0x0]
7161b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\profapi.dll [lacks WinVerifyTrust]
7171b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdb00000 'C:\Windows\system32\USERENV.dll'
7181b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007c4cb0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Dell\Dell Wireless WLAN Card;c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;c:\Program Files\WIDCOMM\Bluetooth Software\;c:\Program Files\WIDCOMM\Bluetooth Software\syswow64;c:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;U:\Windows\software\MPlayer;C:\Program Files (x86)\Skype\Phone\;U:\Windows\software\ffmpeg-20150803-git-5750d6c-win64-static\bin;U:\Windows\software\libav-i686-w64-mingw32-11.2\usr\bin;U:\Windows\software\MPlayer-extra [calling]
7191b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefeb00000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
7201b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007c4cb0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Dell\Dell Wireless WLAN Card;c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;c:\Program Files\WIDCOMM\Bluetooth Software\;c:\Program Files\WIDCOMM\Bluetooth Software\syswow64;c:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;U:\Windows\software\MPlayer;C:\Program Files (x86)\Skype\Phone\;U:\Windows\software\ffmpeg-20150803-git-5750d6c-win64-static\bin;U:\Windows\software\libav-i686-w64-mingw32-11.2\usr\bin;U:\Windows\software\MPlayer-extra [calling]
7211b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefeb00000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
7221b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
7231b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'rpcrt4.dll'.
7241b0c.192c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\WINDOWS\System32\gpapi.dll)
7251b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\gpapi.dll
7261b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
7271b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
7281b0c.192c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\rpcrt4.dll [lacks WinVerifyTrust]
7291b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
7301b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
7311b0c.192c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll [lacks WinVerifyTrust]
7321b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\GPAPI.dll (Input=GPAPI.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c4cb0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Dell\Dell Wireless WLAN Card;c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;c:\Program Files\WIDCOMM\Bluetooth Software\;c:\Program Files\WIDCOMM\Bluetooth Software\syswow64;c:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;U:\Windows\software\MPlayer;C:\Program Files (x86)\Skype\Phone\;U:\Windows\software\ffmpeg-20150803-git-5750d6c-win64-static\bin;U:\Windows\software\libav-i686-w64-mingw32-11.2\usr\bin;U:\Windows\software\MPlayer-extra [calling]
7331b0c.192c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\gpapi.dll [lacks WinVerifyTrust]
7341b0c.192c: supR3HardenedDllNotificationCallback: load 000007fefccd0000 LB 0x0001b000 C:\Windows\system32\GPAPI.dll [fFlags=0x0]
7351b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\gpapi.dll [lacks WinVerifyTrust]
7361b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefccd0000 'C:\Windows\system32\GPAPI.dll'
7371b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-Management-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007c4cb0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Dell\Dell Wireless WLAN Card;c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;c:\Program Files\WIDCOMM\Bluetooth Software\;c:\Program Files\WIDCOMM\Bluetooth Software\syswow64;c:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;U:\Windows\software\MPlayer;C:\Program Files (x86)\Skype\Phone\;U:\Windows\software\ffmpeg-20150803-git-5750d6c-win64-static\bin;U:\Windows\software\libav-i686-w64-mingw32-11.2\usr\bin;U:\Windows\software\MPlayer-extra [calling]
7381b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefeb00000 'API-MS-WIN-Service-Management-L1-1-0.dll'
7391b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\rpcrt4.dll [lacks WinVerifyTrust]
7401b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rpcrt4.dll (Input=rpcrt4.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c4cb0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Dell\Dell Wireless WLAN Card;c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;c:\Program Files\WIDCOMM\Bluetooth Software\;c:\Program Files\WIDCOMM\Bluetooth Software\syswow64;c:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;U:\Windows\software\MPlayer;C:\Program Files (x86)\Skype\Phone\;U:\Windows\software\ffmpeg-20150803-git-5750d6c-win64-static\bin;U:\Windows\software\libav-i686-w64-mingw32-11.2\usr\bin;U:\Windows\software\MPlayer-extra [calling]
7411b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe370000 'C:\Windows\system32\rpcrt4.dll'
7421b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-Management-L2-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007c4cb0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Dell\Dell Wireless WLAN Card;c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;c:\Program Files\WIDCOMM\Bluetooth Software\;c:\Program Files\WIDCOMM\Bluetooth Software\syswow64;c:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;U:\Windows\software\MPlayer;C:\Program Files (x86)\Skype\Phone\;U:\Windows\software\ffmpeg-20150803-git-5750d6c-win64-static\bin;U:\Windows\software\libav-i686-w64-mingw32-11.2\usr\bin;U:\Windows\software\MPlayer-extra [calling]
7431b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefeb00000 'API-MS-WIN-Service-Management-L2-1-0.dll'
7441b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007c4cb0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Dell\Dell Wireless WLAN Card;c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;c:\Program Files\WIDCOMM\Bluetooth Software\;c:\Program Files\WIDCOMM\Bluetooth Software\syswow64;c:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;U:\Windows\software\MPlayer;C:\Program Files (x86)\Skype\Phone\;U:\Windows\software\ffmpeg-20150803-git-5750d6c-win64-static\bin;U:\Windows\software\libav-i686-w64-mingw32-11.2\usr\bin;U:\Windows\software\MPlayer-extra [calling]
7451b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefeb00000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
7461b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
7471b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'advapi32.dll'.
7481b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'crypt32.dll'.
7491b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'wldap32.dll'.
7501b0c.192c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\WINDOWS\System32\cryptnet.dll)
7511b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\cryptnet.dll
7521b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wldap32.dll'...
7531b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'wldap32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\wldap32.dll' [rcNtRedir=0xc0150008]
7541b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
7551b0c.192c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\WINDOWS\System32\Wldap32.dll)
7561b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\Wldap32.dll
7571b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
7581b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\crypt32.dll' [rcNtRedir=0xc0150008]
7591b0c.192c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\crypt32.dll [lacks WinVerifyTrust]
7601b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
7611b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\advapi32.dll' [rcNtRedir=0xc0150008]
7621b0c.192c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\advapi32.dll [lacks WinVerifyTrust]
7631b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
7641b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
7651b0c.192c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll [lacks WinVerifyTrust]
7661b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
7671b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
7681b0c.192c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll [lacks WinVerifyTrust]
7691b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (Input=cryptnet.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c4cb0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Dell\Dell Wireless WLAN Card;c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;c:\Program Files\WIDCOMM\Bluetooth Software\;c:\Program Files\WIDCOMM\Bluetooth Software\syswow64;c:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;U:\Windows\software\MPlayer;C:\Program Files (x86)\Skype\Phone\;U:\Windows\software\ffmpeg-20150803-git-5750d6c-win64-static\bin;U:\Windows\software\libav-i686-w64-mingw32-11.2\usr\bin;U:\Windows\software\MPlayer-extra [calling]
7701b0c.192c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\cryptnet.dll [lacks WinVerifyTrust]
7711b0c.192c: supR3HardenedDllNotificationCallback: load 000007fef7a40000 LB 0x00027000 C:\Windows\system32\cryptnet.dll [fFlags=0x0]
7721b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\cryptnet.dll [lacks WinVerifyTrust]
7731b0c.192c: supR3HardenedDllNotificationCallback: load 000007fefe1a0000 LB 0x00052000 C:\Windows\system32\WLDAP32.dll [fFlags=0x0]
7741b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\Wldap32.dll [lacks WinVerifyTrust]
7751b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\cryptnet.dll [lacks WinVerifyTrust]
7761b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00000000007c4cb0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Dell\Dell Wireless WLAN Card;c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;c:\Program Files\WIDCOMM\Bluetooth Software\;c:\Program Files\WIDCOMM\Bluetooth Software\syswow64;c:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;U:\Windows\software\MPlayer;C:\Program Files (x86)\Skype\Phone\;U:\Windows\software\ffmpeg-20150803-git-5750d6c-win64-static\bin;U:\Windows\software\libav-i686-w64-mingw32-11.2\usr\bin;U:\Windows\software\MPlayer-extra [calling]
7771b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef7a40000 'C:\Windows\system32\cryptnet.dll'
7781b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\cryptnet.dll [lacks WinVerifyTrust]
7791b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00000000007c4cb0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Dell\Dell Wireless WLAN Card;c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;c:\Program Files\WIDCOMM\Bluetooth Software\;c:\Program Files\WIDCOMM\Bluetooth Software\syswow64;c:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;U:\Windows\software\MPlayer;C:\Program Files (x86)\Skype\Phone\;U:\Windows\software\ffmpeg-20150803-git-5750d6c-win64-static\bin;U:\Windows\software\libav-i686-w64-mingw32-11.2\usr\bin;U:\Windows\software\MPlayer-extra [calling]
7801b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef7a40000 'C:\Windows\system32\cryptnet.dll'
7811b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\cryptnet.dll [lacks WinVerifyTrust]
7821b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00000000007c4cb0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Dell\Dell Wireless WLAN Card;c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;c:\Program Files\WIDCOMM\Bluetooth Software\;c:\Program Files\WIDCOMM\Bluetooth Software\syswow64;c:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;U:\Windows\software\MPlayer;C:\Program Files (x86)\Skype\Phone\;U:\Windows\software\ffmpeg-20150803-git-5750d6c-win64-static\bin;U:\Windows\software\libav-i686-w64-mingw32-11.2\usr\bin;U:\Windows\software\MPlayer-extra [calling]
7831b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef7a40000 'C:\Windows\system32\cryptnet.dll'
7841b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\cryptnet.dll [lacks WinVerifyTrust]
7851b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00000000007c4cb0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Dell\Dell Wireless WLAN Card;c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;c:\Program Files\WIDCOMM\Bluetooth Software\;c:\Program Files\WIDCOMM\Bluetooth Software\syswow64;c:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;U:\Windows\software\MPlayer;C:\Program Files (x86)\Skype\Phone\;U:\Windows\software\ffmpeg-20150803-git-5750d6c-win64-static\bin;U:\Windows\software\libav-i686-w64-mingw32-11.2\usr\bin;U:\Windows\software\MPlayer-extra [calling]
7861b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef7a40000 'C:\Windows\system32\cryptnet.dll'
7871b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\cryptnet.dll [lacks WinVerifyTrust]
7881b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00000000007c4cb0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Dell\Dell Wireless WLAN Card;c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;c:\Program Files\WIDCOMM\Bluetooth Software\;c:\Program Files\WIDCOMM\Bluetooth Software\syswow64;c:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;U:\Windows\software\MPlayer;C:\Program Files (x86)\Skype\Phone\;U:\Windows\software\ffmpeg-20150803-git-5750d6c-win64-static\bin;U:\Windows\software\libav-i686-w64-mingw32-11.2\usr\bin;U:\Windows\software\MPlayer-extra [calling]
7891b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef7a40000 'C:\Windows\system32\cryptnet.dll'
7901b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\cryptnet.dll [lacks WinVerifyTrust]
7911b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00000000007c4cb0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Dell\Dell Wireless WLAN Card;c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;c:\Program Files\WIDCOMM\Bluetooth Software\;c:\Program Files\WIDCOMM\Bluetooth Software\syswow64;c:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;U:\Windows\software\MPlayer;C:\Program Files (x86)\Skype\Phone\;U:\Windows\software\ffmpeg-20150803-git-5750d6c-win64-static\bin;U:\Windows\software\libav-i686-w64-mingw32-11.2\usr\bin;U:\Windows\software\MPlayer-extra [calling]
7921b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef7a40000 'C:\Windows\system32\cryptnet.dll'
7931b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\cryptnet.dll [lacks WinVerifyTrust]
7941b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef7a40000 'C:\Windows\system32\cryptnet.dll'
7951b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\cryptnet.dll [lacks WinVerifyTrust]
7961b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef7a40000 'C:\Windows\system32\cryptnet.dll'
7971b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\cryptnet.dll [lacks WinVerifyTrust]
7981b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef7a40000 'C:\Windows\system32\cryptnet.dll'
7991b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\cryptnet.dll [lacks WinVerifyTrust]
8001b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef7a40000 'C:\Windows\system32\cryptnet.dll'
8011b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\cryptnet.dll [lacks WinVerifyTrust]
8021b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef7a40000 'C:\Windows\system32\cryptnet.dll'
8031b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef7a40000 'C:\Windows\system32\cryptnet.dll'
8041b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\cryptnet.dll [lacks WinVerifyTrust]
8051b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef7a40000 'C:\Windows\system32\cryptnet.dll'
8061b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007c4cb0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Dell\Dell Wireless WLAN Card;c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;c:\Program Files\WIDCOMM\Bluetooth Software\;c:\Program Files\WIDCOMM\Bluetooth Software\syswow64;c:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;U:\Windows\software\MPlayer;C:\Program Files (x86)\Skype\Phone\;U:\Windows\software\ffmpeg-20150803-git-5750d6c-win64-static\bin;U:\Windows\software\libav-i686-w64-mingw32-11.2\usr\bin;U:\Windows\software\MPlayer-extra [calling]
8071b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefeb00000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
8081b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\profapi.dll [lacks WinVerifyTrust]
8091b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\profapi.dll (Input=profapi.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c4cb0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Dell\Dell Wireless WLAN Card;c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;c:\Program Files\WIDCOMM\Bluetooth Software\;c:\Program Files\WIDCOMM\Bluetooth Software\syswow64;c:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;U:\Windows\software\MPlayer;C:\Program Files (x86)\Skype\Phone\;U:\Windows\software\ffmpeg-20150803-git-5750d6c-win64-static\bin;U:\Windows\software\libav-i686-w64-mingw32-11.2\usr\bin;U:\Windows\software\MPlayer-extra [calling]
8101b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefda20000 'C:\Windows\system32\profapi.dll'
8111b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
8121b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
8131b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msvcrt.dll'.
8141b0c.192c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\WINDOWS\System32\shlwapi.dll)
8151b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\shlwapi.dll
8161b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
8171b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
8181b0c.192c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll [lacks WinVerifyTrust]
8191b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
8201b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\user32.dll' [rcNtRedir=0xc0150008]
8211b0c.192c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\user32.dll [lacks WinVerifyTrust]
8221b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
8231b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\gdi32.dll' [rcNtRedir=0xc0150008]
8241b0c.192c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\gdi32.dll [lacks WinVerifyTrust]
8251b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\SHLWAPI.dll (Input=SHLWAPI.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c4cb0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Dell\Dell Wireless WLAN Card;c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;c:\Program Files\WIDCOMM\Bluetooth Software\;c:\Program Files\WIDCOMM\Bluetooth Software\syswow64;c:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;U:\Windows\software\MPlayer;C:\Program Files (x86)\Skype\Phone\;U:\Windows\software\ffmpeg-20150803-git-5750d6c-win64-static\bin;U:\Windows\software\libav-i686-w64-mingw32-11.2\usr\bin;U:\Windows\software\MPlayer-extra [calling]
8261b0c.192c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\shlwapi.dll [lacks WinVerifyTrust]
8271b0c.192c: supR3HardenedDllNotificationCallback: load 000007fefe4a0000 LB 0x00071000 C:\Windows\system32\SHLWAPI.dll [fFlags=0x0]
8281b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\shlwapi.dll [lacks WinVerifyTrust]
8291b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe4a0000 'C:\Windows\system32\SHLWAPI.dll'
8301b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000000 pwszName=\SystemRoot\System32\ntdll.dll
8311b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: New context 0000000000860f20
8321b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
8331b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=EDC3F71C5551972E1510D1BCC6D436D5B6B426E8
8341b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007c4cb0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Dell\Dell Wireless WLAN Card;c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;c:\Program Files\WIDCOMM\Bluetooth Software\;c:\Program Files\WIDCOMM\Bluetooth Software\syswow64;c:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;U:\Windows\software\MPlayer;C:\Program Files (x86)\Skype\Phone\;U:\Windows\software\ffmpeg-20150803-git-5750d6c-win64-static\bin;U:\Windows\software\libav-i686-w64-mingw32-11.2\usr\bin;U:\Windows\software\MPlayer-extra [calling]
8351b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefeb00000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
8361b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-Management-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007c4cb0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Dell\Dell Wireless WLAN Card;c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;c:\Program Files\WIDCOMM\Bluetooth Software\;c:\Program Files\WIDCOMM\Bluetooth Software\syswow64;c:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;U:\Windows\software\MPlayer;C:\Program Files (x86)\Skype\Phone\;U:\Windows\software\ffmpeg-20150803-git-5750d6c-win64-static\bin;U:\Windows\software\libav-i686-w64-mingw32-11.2\usr\bin;U:\Windows\software\MPlayer-extra [calling]
8371b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefeb00000 'API-MS-WIN-Service-Management-L1-1-0.dll'
8381b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-winsvc-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007c4cb0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Dell\Dell Wireless WLAN Card;c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;c:\Program Files\WIDCOMM\Bluetooth Software\;c:\Program Files\WIDCOMM\Bluetooth Software\syswow64;c:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;U:\Windows\software\MPlayer;C:\Program Files (x86)\Skype\Phone\;U:\Windows\software\ffmpeg-20150803-git-5750d6c-win64-static\bin;U:\Windows\software\libav-i686-w64-mingw32-11.2\usr\bin;U:\Windows\software\MPlayer-extra [calling]
8391b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefeb00000 'API-MS-WIN-Service-winsvc-L1-1-0.dll'
8401b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\advapi32.dll [lacks WinVerifyTrust]
8411b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ADVAPI32.dll (Input=ADVAPI32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c4cb0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Dell\Dell Wireless WLAN Card;c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;c:\Program Files\WIDCOMM\Bluetooth Software\;c:\Program Files\WIDCOMM\Bluetooth Software\syswow64;c:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;U:\Windows\software\MPlayer;C:\Program Files (x86)\Skype\Phone\;U:\Windows\software\ffmpeg-20150803-git-5750d6c-win64-static\bin;U:\Windows\software\libav-i686-w64-mingw32-11.2\usr\bin;U:\Windows\software\MPlayer-extra [calling]
8421b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feffa90000 'C:\Windows\system32\ADVAPI32.dll'
8431b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-LSALookup-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007c4cb0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Dell\Dell Wireless WLAN Card;c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;c:\Program Files\WIDCOMM\Bluetooth Software\;c:\Program Files\WIDCOMM\Bluetooth Software\syswow64;c:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;U:\Windows\software\MPlayer;C:\Program Files (x86)\Skype\Phone\;U:\Windows\software\ffmpeg-20150803-git-5750d6c-win64-static\bin;U:\Windows\software\libav-i686-w64-mingw32-11.2\usr\bin;U:\Windows\software\MPlayer-extra [calling]
8441b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefeb00000 'API-MS-Win-Security-LSALookup-L1-1-0.dll'
8451b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-LSALookup-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007c4cb0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Dell\Dell Wireless WLAN Card;c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;c:\Program Files\WIDCOMM\Bluetooth Software\;c:\Program Files\WIDCOMM\Bluetooth Software\syswow64;c:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;U:\Windows\software\MPlayer;C:\Program Files (x86)\Skype\Phone\;U:\Windows\software\ffmpeg-20150803-git-5750d6c-win64-static\bin;U:\Windows\software\libav-i686-w64-mingw32-11.2\usr\bin;U:\Windows\software\MPlayer-extra [calling]
8461b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefeb00000 'API-MS-Win-Security-LSALookup-L1-1-0.dll'
8471b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_85_for_KB3068708~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\SystemRoot\System32\ntdll.dll'
8481b0c.192c: g_pfnWinVerifyTrust=000007fefdb31010
8491b0c.192c: supR3HardenedScreenImage/preload: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\crypt32.dll [redoing WinVerifyTrust]
8501b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000e0 pwszName=\Device\HarddiskVolume2\WINDOWS\System32\crypt32.dll
8511b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
8521b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
8531b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=BFD41401EDEBD4D914977D62B588ECABEE60CFD3
8541b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_112_for_KB3040272~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\WINDOWS\System32\crypt32.dll'
8551b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
8561b0c.192c: supR3HardenedScreenImage/preload: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\WINDOWS\System32\crypt32.dll'
8571b0c.192c: supR3HardenedScreenImage/preload: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\wintrust.dll [redoing WinVerifyTrust]
8581b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000d4 pwszName=\Device\HarddiskVolume2\WINDOWS\System32\wintrust.dll
8591b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
8601b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
8611b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=E1BBE4EB6D114F50142F24E2E2749EFD81021486
8621b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_75_for_KB3040272~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\WINDOWS\System32\wintrust.dll'
8631b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
8641b0c.192c: supR3HardenedScreenImage/preload: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\WINDOWS\System32\wintrust.dll'
8651b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000003bc pwszName=\Device\HarddiskVolume2\WINDOWS\System32\shlwapi.dll
8661b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
8671b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
8681b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=0AB8D9C9D3E1FC95D01F9A984B16ED031BB40CD8
8691b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\WINDOWS\System32\shlwapi.dll'
8701b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
8711b0c.192c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\WINDOWS\System32\shlwapi.dll'
8721b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000003b4 pwszName=\Device\HarddiskVolume2\WINDOWS\System32\Wldap32.dll
8731b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
8741b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
8751b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=87E73086F2528CF31D3AD5F0D71E04F8B942D5D8
8761b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\WINDOWS\System32\Wldap32.dll'
8771b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
8781b0c.192c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\WINDOWS\System32\Wldap32.dll'
8791b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000003b0 pwszName=\Device\HarddiskVolume2\WINDOWS\System32\cryptnet.dll
8801b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
8811b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
8821b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=756DC088EE40CF9369C990D71B200F3CB59FC35D
8831b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_75_for_KB3040272~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\WINDOWS\System32\cryptnet.dll'
8841b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
8851b0c.192c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\WINDOWS\System32\cryptnet.dll'
8861b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000026c pwszName=\Device\HarddiskVolume2\WINDOWS\System32\gpapi.dll
8871b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
8881b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
8891b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=470795C189226F7BDB8E50F42104CC34488B9340
8901b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\WINDOWS\System32\gpapi.dll'
8911b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
8921b0c.192c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\WINDOWS\System32\gpapi.dll'
8931b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000001d8 pwszName=\Device\HarddiskVolume2\WINDOWS\System32\profapi.dll
8941b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
8951b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
8961b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2449672745D9BA339420451D13FA0380AA768231
8971b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\WINDOWS\System32\profapi.dll'
8981b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
8991b0c.192c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\WINDOWS\System32\profapi.dll'
9001b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000001d4 pwszName=\Device\HarddiskVolume2\WINDOWS\System32\userenv.dll
9011b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
9021b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
9031b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=D3E1A2CC7367F751C19EBF4E6EDF5E9A10E47313
9041b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\WINDOWS\System32\userenv.dll'
9051b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
9061b0c.192c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\WINDOWS\System32\userenv.dll'
9071b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000001c0 pwszName=\Device\HarddiskVolume2\WINDOWS\System32\ncrypt.dll
9081b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
9091b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
9101b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=327561BCBADC135831FD13C5C67C5E26F4E2B805
9111b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_53_for_KB3057154~31bf3856ad364e35~amd64~~6.1.1.3.cat'; file='\Device\HarddiskVolume2\WINDOWS\System32\ncrypt.dll'
9121b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
9131b0c.192c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\WINDOWS\System32\ncrypt.dll'
9141b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000001a4 pwszName=\Device\HarddiskVolume2\WINDOWS\System32\msctf.dll
9151b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
9161b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
9171b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=03916BC73EE5A0E312E3D3100D0ACE1B78E93BB1
9181b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3033889~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\WINDOWS\System32\msctf.dll'
9191b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
9201b0c.192c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\WINDOWS\System32\msctf.dll'
9211b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000001a0 pwszName=\Device\HarddiskVolume2\WINDOWS\System32\imm32.dll
9221b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
9231b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
9241b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=6EEE1AB3B6D79AFF857940FF5F51ED27698153EC
9251b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\WINDOWS\System32\imm32.dll'
9261b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
9271b0c.192c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\WINDOWS\System32\imm32.dll'
9281b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000019c pwszName=\Device\HarddiskVolume2\WINDOWS\System32\usp10.dll
9291b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
9301b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
9311b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=1F1AA8340DE02FC1B6341EE2706E55D56EDF63B8
9321b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB2957509~31bf3856ad364e35~amd64~~6.1.1.2.cat'; file='\Device\HarddiskVolume2\WINDOWS\System32\usp10.dll'
9331b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
9341b0c.192c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\WINDOWS\System32\usp10.dll'
9351b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000198 pwszName=\Device\HarddiskVolume2\WINDOWS\System32\lpk.dll
9361b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
9371b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
9381b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=DF72C9DFDFB7D1CBA26FE4829B56F7B244C8A875
9391b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3079904~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\WINDOWS\System32\lpk.dll'
9401b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
9411b0c.192c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\WINDOWS\System32\lpk.dll'
9421b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000194 pwszName=\Device\HarddiskVolume2\WINDOWS\System32\gdi32.dll
9431b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
9441b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
9451b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=EB178841F5FFC6B05E668168217B0AC222A62955
9461b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3069392~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\WINDOWS\System32\gdi32.dll'
9471b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
9481b0c.192c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\WINDOWS\System32\gdi32.dll'
9491b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000190 pwszName=\Device\HarddiskVolume2\WINDOWS\System32\user32.dll
9501b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
9511b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
9521b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B723D1B8AD72750B0CF5F6BEC66171B1254ED879
9531b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\WINDOWS\System32\user32.dll'
9541b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
9551b0c.192c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\WINDOWS\System32\user32.dll'
9561b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000018c pwszName=\Device\HarddiskVolume2\WINDOWS\System32\imagehlp.dll
9571b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
9581b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
9591b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2702EE05F1B717B0F2CE0FBE32784A47B8419DCA
9601b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_2_for_KB2893294~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\WINDOWS\System32\imagehlp.dll'
9611b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
9621b0c.192c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\WINDOWS\System32\imagehlp.dll'
9631b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000130 pwszName=\Device\HarddiskVolume2\WINDOWS\System32\cryptbase.dll
9641b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
9651b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
9661b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=950A18CED6C5D5CAB1335676119FFFE11307EF04
9671b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_53_for_KB3057154~31bf3856ad364e35~amd64~~6.1.1.3.cat'; file='\Device\HarddiskVolume2\WINDOWS\System32\cryptbase.dll'
9681b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
9691b0c.192c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\WINDOWS\System32\cryptbase.dll'
9701b0c.192c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\WINDOWS\System32\rsaenh.dll'
9711b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000012c pwszName=\Device\HarddiskVolume2\WINDOWS\System32\cryptsp.dll
9721b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
9731b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
9741b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=BA7AC4A7E8ADDFEA90AC951ECB6D6546E4873613
9751b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_115_for_KB3033929~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\WINDOWS\System32\cryptsp.dll'
9761b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
9771b0c.192c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\WINDOWS\System32\cryptsp.dll'
9781b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000120 pwszName=\Device\HarddiskVolume2\WINDOWS\System32\sechost.dll
9791b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
9801b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
9811b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=CB669FA8DB80F8E50A29D055BB8D558E10E5E6B4
9821b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_85_for_KB3068708~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\WINDOWS\System32\sechost.dll'
9831b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
9841b0c.192c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\WINDOWS\System32\sechost.dll'
9851b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000011c pwszName=\Device\HarddiskVolume2\WINDOWS\System32\advapi32.dll
9861b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
9871b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
9881b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=9BBB1FC4DED54F17702B287B63F8FE24EE5D7844
9891b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_85_for_KB3068708~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\WINDOWS\System32\advapi32.dll'
9901b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
9911b0c.192c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\WINDOWS\System32\advapi32.dll'
9921b0c.192c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\WINDOWS\System32\bcryptprimitives.dll'
9931b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000104 pwszName=\Device\HarddiskVolume2\WINDOWS\System32\bcrypt.dll
9941b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
9951b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
9961b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=62E377A1F0AD0C2EDC0A73CB3EFF841FF18D00D2
9971b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\WINDOWS\System32\bcrypt.dll'
9981b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
9991b0c.192c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\WINDOWS\System32\bcrypt.dll'
10001b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000e4 pwszName=\Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll
10011b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
10021b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
10031b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2CA2FD632B264C063162F71474266E3615B6420C
10041b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB2654428~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll'
10051b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
10061b0c.192c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll'
10071b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000dc pwszName=\Device\HarddiskVolume2\WINDOWS\System32\msasn1.dll
10081b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
10091b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
10101b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F2FF57DC30D774F93061607060DAA0DD15E39CCE
10111b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\WINDOWS\System32\msasn1.dll'
10121b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
10131b0c.192c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\WINDOWS\System32\msasn1.dll'
10141b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000d8 pwszName=\Device\HarddiskVolume2\WINDOWS\System32\rpcrt4.dll
10151b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
10161b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
10171b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=E38DB7758ACD985E98AD6101CED724203843D038
10181b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_53_for_KB3057154~31bf3856ad364e35~amd64~~6.1.1.3.cat'; file='\Device\HarddiskVolume2\WINDOWS\System32\rpcrt4.dll'
10191b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
10201b0c.192c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\WINDOWS\System32\rpcrt4.dll'
10211b0c.192c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll'
10221b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000028 pwszName=\Device\HarddiskVolume2\WINDOWS\System32\KernelBase.dll
10231b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
10241b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
10251b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=FD34F960ED54F1FB26E76A32FB91273E3093869E
10261b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_85_for_KB3068708~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\WINDOWS\System32\KernelBase.dll'
10271b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
10281b0c.192c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\WINDOWS\System32\KernelBase.dll'
10291b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000020 pwszName=\Device\HarddiskVolume2\WINDOWS\System32\kernel32.dll
10301b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
10311b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
10321b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=1C47BBB61CB0D4D781B3BEC602422D40A0784762
10331b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_85_for_KB3068708~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\WINDOWS\System32\kernel32.dll'
10341b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
10351b0c.192c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\WINDOWS\System32\kernel32.dll'
10361b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\crypt32.dll
10371b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\crypt32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000027813c0:C:\Windows\system32 [calling]
10381b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdba0000 'C:\Windows\system32\crypt32.dll'
10391b0c.192c: supR3HardenedWinIsDesiredRootCA: Adding 0x5ad46780fa5df300 DC=com, DC=microsoft, CN=Microsoft Root Certificate Authority
10401b0c.192c: supR3HardenedWinIsDesiredRootCA: Adding 0xea5386456178582b C=ZA, ST=Western Cape, L=Durbanville, O=Thawte, OU=Thawte Certification, CN=Thawte Timestamping CA
10411b0c.192c: supR3HardenedWinIsDesiredRootCA: Adding 0x3be670c1bd02a900 OU=Copyright (c) 1997 Microsoft Corp., OU=Microsoft Corporation, CN=Microsoft Root Authority
10421b0c.192c: supR3HardenedWinIsDesiredRootCA: Adding 0x4d3835aa4180b200 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2011
10431b0c.192c: supR3HardenedWinIsDesiredRootCA: Adding 0x646e3fe3ba08df00 C=US, O=MSFT, CN=Microsoft Authenticode(tm) Root Authority
10441b0c.192c: supR3HardenedWinIsDesiredRootCA: Adding 0xece4e4289e08b900 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010
10451b0c.192c: supR3HardenedWinIsDesiredRootCA: Adding 0x43a9cc371ff5385a O=Microsoft Trust Network, OU=Microsoft Corporation, OU=Microsoft Time Stamping Service Root, OU=Copyright (c) 1997 Microsoft Corp.
10461b0c.192c: supR3HardenedWinIsDesiredRootCA: Adding 0x2e2d2c7c68f0202e O=VeriSign Trust Network, OU=VeriSign, Inc., OU=VeriSign Time Stamping Service Root, OU=NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.
10471b0c.192c: supR3HardenedWinIsDesiredRootCA: Adding 0xd8dbfb2c27bfb200 C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2008 thawte, Inc. - For authorized use only, CN=thawte Primary Root CA - G3
10481b0c.192c: supR3HardenedWinIsDesiredRootCA: Adding 0x61a3a33f81aace00 C=US, ST=UT, L=Salt Lake City, O=The USERTRUST Network, OU=http://www.usertrust.com, CN=UTN-USERFirst-Object
10491b0c.192c: supR3HardenedWinIsDesiredRootCA: Adding 0xf4fd306318ccda00 C=US, O=GeoTrust Inc., CN=GeoTrust Global CA
10501b0c.192c: supR3HardenedWinIsDesiredRootCA: Adding 0x3d98ab22bb04a300 C=IE, O=Baltimore, OU=CyberTrust, CN=Baltimore CyberTrust Root
10511b0c.192c: supR3HardenedWinIsDesiredRootCA: Adding 0xa0ee62086758b15d C=US, O=Equifax, OU=Equifax Secure Certificate Authority
10521b0c.192c: supR3HardenedWinIsDesiredRootCA: Adding 0x8ff6fc03c1edbd00 C=US, ST=Arizona, L=Scottsdale, O=Starfield Technologies, Inc., CN=Starfield Root Certificate Authority - G2
10531b0c.192c: supR3HardenedWinIsDesiredRootCA: Adding 0xa3ce8d99e60eda00 C=BE, O=GlobalSign nv-sa, OU=Root CA, CN=GlobalSign Root CA
10541b0c.192c: supR3HardenedWinIsDesiredRootCA: Adding 0xa8de7211e13be200 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root CA
10551b0c.192c: supR3HardenedWinIsDesiredRootCA: Adding 0xff3891b54348328 C=US, O=Entrust.net, OU=www.entrust.net/CPS incorp. by ref. (limits liab.), OU=(c) 1999 Entrust.net Limited, CN=Entrust.net Secure Server Certification Authority
10561b0c.192c: supR3HardenedWinIsDesiredRootCA: Adding 0x7ae89c50f0b6a00f C=US, O=GTE Corporation, OU=GTE CyberTrust Solutions, Inc., CN=GTE CyberTrust Global Root
10571b0c.192c: supR3HardenedWinIsDesiredRootCA: Adding 0xd45980fbf0a0ac00 C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2006 thawte, Inc. - For authorized use only, CN=thawte Primary Root CA
10581b0c.192c: supR3HardenedWinIsDesiredRootCA: Adding 0x4d3835aa4180b200 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2011
10591b0c.192c: supR3HardenedWinIsDesiredRootCA: Adding 0x298be035a30bab00 C=DE, O=Deutsche Telekom AG, OU=T-TeleSec Trust Center, CN=Deutsche Telekom Root CA 2
10601b0c.192c: supR3HardenedWinIsDesiredRootCA: Adding 0xabd0695c5d11d15e C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority - G2, OU=(c) 1998 VeriSign, Inc. - For authorized use only, OU=VeriSign Trust Network
10611b0c.192c: supR3HardenedWinIsDesiredRootCA: Adding 0x14018a1bf29e595c C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority
10621b0c.192c: supR3HardenedWinIsDesiredRootCA: Adding 0x9e5bc2d78b6a3636 C=ZA, ST=Western Cape, L=Cape Town, O=Thawte Consulting cc, OU=Certification Services Division, CN=Thawte Premium Server CA, Email=premium-server@thawte.com
10631b0c.192c: supR3HardenedWinIsDesiredRootCA: Adding 0x7c4fd32ec1b1ce00 C=PL, O=Unizeto Sp. z o.o., CN=Certum CA
10641b0c.192c: supR3HardenedWinIsDesiredRootCA: Adding 0xd4fbe673e5ccc600 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA
10651b0c.192c: supR3HardenedWinIsDesiredRootCA: Adding 0x16e64d2a56ccf200 C=US, ST=Arizona, L=Scottsdale, O=Starfield Technologies, Inc., OU=http://certificates.starfieldtech.com/repository/, CN=Starfield Services Root Certificate Authority
10661b0c.192c: supR3HardenedWinIsDesiredRootCA: Adding 0x6e2ba21058eedf00 C=US, ST=UT, L=Salt Lake City, O=The USERTRUST Network, OU=http://www.usertrust.com, CN=UTN - DATACorp SGC
10671b0c.192c: supR3HardenedWinIsDesiredRootCA: Adding 0xb28612a94b4dad00 O=Entrust.net, OU=www.entrust.net/CPS_2048 incorp. by ref. (limits liab.), OU=(c) 1999 Entrust.net Limited, CN=Entrust.net Certification Authority (2048)
10681b0c.192c: supR3HardenedWinIsDesiredRootCA: Adding 0x357a29080824af00 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2006 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G5
10691b0c.192c: supR3HardenedWinIsDesiredRootCA: Adding 0x59faf1086271bf00 C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com, Inc., CN=Go Daddy Root Certificate Authority - G2
10701b0c.192c: supR3HardenedWinIsDesiredRootCA: Adding 0x466cbc09db88c100 C=IL, O=StartCom Ltd., OU=Secure Digital Certificate Signing, CN=StartCom Certification Authority
10711b0c.192c: supR3HardenedWinIsDesiredRootCA: Adding 0x491857ead79dde00 C=US, O=The Go Daddy Group, Inc., OU=Go Daddy Class 2 Certification Authority
10721b0c.192c: supR3HardenedWinIsDesiredRootCA: Adding 0xe66b56ffc86e50a4 C=ZA, ST=Western Cape, L=Cape Town, O=Thawte Consulting cc, OU=Certification Services Division, CN=Thawte Server CA, Email=server-certs@thawte.com
10731b0c.192c: supR3HardenedWinIsDesiredRootCA: Adding 0x1f78fc529cbacb00 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 1999 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G3
10741b0c.192c: supR3HardenedWinIsDesiredRootCA: Adding 0x8043e4ce150ead00 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID Root CA
10751b0c.192c: supR3HardenedWinIsDesiredRootCA: Adding 0xa8b43f38c3f7b100 C=US, ST=UT, L=Salt Lake City, O=The USERTRUST Network, OU=http://www.usertrust.com, CN=UTN-USERFirst-Hardware
10761b0c.192c: supR3HardenedWinIsDesiredRootCA: Adding 0xf2e6331af7b700 C=SE, O=AddTrust AB, OU=AddTrust External TTP Network, CN=AddTrust External CA Root
10771b0c.192c: supR3HardenedWinRetrieveTrustedRootCAs: cAdded=38
10781b0c.192c: SUPR3HardenedMain: Load Runtime...
10791b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
10801b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
10811b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ws2_32.dll'.
10821b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'rpcrt4.dll'.
10831b0c.192c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll)WinVerifyTrust
10841b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
10851b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
10861b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
10871b0c.192c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\rpcrt4.dll
10881b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
10891b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
10901b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000444 pwszName=\Device\HarddiskVolume2\WINDOWS\System32\ws2_32.dll
10911b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
10921b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
10931b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=3EF3BDC1E84DFA17EA056313214EE88EC3E66F79
10941b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\WINDOWS\System32\ws2_32.dll'
10951b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
10961b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
10971b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'rpcrt4.dll'.
10981b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'nsi.dll'.
10991b0c.192c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\ws2_32.dll)WinVerifyTrust
11001b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\ws2_32.dll
11011b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
11021b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
11031b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
11041b0c.192c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll)WinVerifyTrust
11051b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
11061b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
11071b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
11081b0c.192c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll)WinVerifyTrust
11091b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
11101b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
11111b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
11121b0c.192c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
11131b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
11141b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\nsi.dll' [rcNtRedir=0xc0150008]
11151b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000464 pwszName=\Device\HarddiskVolume2\WINDOWS\System32\nsi.dll
11161b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
11171b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
11181b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=7AFD8538945F2D05BC1AF949B9B19B7D2D9FBBF8
11191b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\WINDOWS\System32\nsi.dll'
11201b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
11211b0c.192c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\nsi.dll)WinVerifyTrust
11221b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\nsi.dll
11231b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
11241b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
11251b0c.192c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\rpcrt4.dll
11261b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
11271b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
11281b0c.192c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll
11291b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000086e0f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
11301b0c.192c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
11311b0c.192c: supR3HardenedDllNotificationCallback: load 000007fee4dd0000 LB 0x00543000 C:\Program Files\Oracle\VirtualBox\VBoxRT.dll [fFlags=0x0]
11321b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
11331b0c.192c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
11341b0c.192c: supR3HardenedDllNotificationCallback: load 000000005dce0000 LB 0x000d2000 C:\Program Files\Oracle\VirtualBox\MSVCR100.dll [fFlags=0x0]
11351b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
11361b0c.192c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
11371b0c.192c: supR3HardenedDllNotificationCallback: load 000000005dc40000 LB 0x00098000 C:\Program Files\Oracle\VirtualBox\MSVCP100.dll [fFlags=0x0]
11381b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
11391b0c.192c: supR3HardenedDllNotificationCallback: load 000007fefe520000 LB 0x0004d000 C:\Windows\system32\WS2_32.dll [fFlags=0x0]
11401b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\ws2_32.dll
11411b0c.192c: supR3HardenedDllNotificationCallback: load 000007fefff70000 LB 0x00008000 C:\Windows\system32\NSI.dll [fFlags=0x0]
11421b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\nsi.dll
11431b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
11441b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c4cb0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Dell\Dell Wireless WLAN Card;c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;c:\Program Files\WIDCOMM\Bluetooth Software\;c:\Program Files\WIDCOMM\Bluetooth Software\syswow64;c:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;U:\Windows\software\MPlayer;C:\Program Files (x86)\Skype\Phone\;U:\Windows\software\ffmpeg-20150803-git-5750d6c-win64-static\bin;U:\Windows\software\libav-i686-w64-mingw32-11.2\usr\bin;U:\Windows\software\MPlayer-extra [calling]
11451b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4dd0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11461b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
11471b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c4cb0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Dell\Dell Wireless WLAN Card;c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;c:\Program Files\WIDCOMM\Bluetooth Software\;c:\Program Files\WIDCOMM\Bluetooth Software\syswow64;c:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;U:\Windows\software\MPlayer;C:\Program Files (x86)\Skype\Phone\;U:\Windows\software\ffmpeg-20150803-git-5750d6c-win64-static\bin;U:\Windows\software\libav-i686-w64-mingw32-11.2\usr\bin;U:\Windows\software\MPlayer-extra [calling]
11481b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4dd0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11491b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
11501b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c4cb0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Dell\Dell Wireless WLAN Card;c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;c:\Program Files\WIDCOMM\Bluetooth Software\;c:\Program Files\WIDCOMM\Bluetooth Software\syswow64;c:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;U:\Windows\software\MPlayer;C:\Program Files (x86)\Skype\Phone\;U:\Windows\software\ffmpeg-20150803-git-5750d6c-win64-static\bin;U:\Windows\software\libav-i686-w64-mingw32-11.2\usr\bin;U:\Windows\software\MPlayer-extra [calling]
11511b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4dd0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11521b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
11531b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c4cb0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Dell\Dell Wireless WLAN Card;c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;c:\Program Files\WIDCOMM\Bluetooth Software\;c:\Program Files\WIDCOMM\Bluetooth Software\syswow64;c:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;U:\Windows\software\MPlayer;C:\Program Files (x86)\Skype\Phone\;U:\Windows\software\ffmpeg-20150803-git-5750d6c-win64-static\bin;U:\Windows\software\libav-i686-w64-mingw32-11.2\usr\bin;U:\Windows\software\MPlayer-extra [calling]
11541b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4dd0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11551b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
11561b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c4cb0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Dell\Dell Wireless WLAN Card;c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;c:\Program Files\WIDCOMM\Bluetooth Software\;c:\Program Files\WIDCOMM\Bluetooth Software\syswow64;c:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;U:\Windows\software\MPlayer;C:\Program Files (x86)\Skype\Phone\;U:\Windows\software\ffmpeg-20150803-git-5750d6c-win64-static\bin;U:\Windows\software\libav-i686-w64-mingw32-11.2\usr\bin;U:\Windows\software\MPlayer-extra [calling]
11571b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4dd0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11581b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
11591b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c4cb0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Dell\Dell Wireless WLAN Card;c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;c:\Program Files\WIDCOMM\Bluetooth Software\;c:\Program Files\WIDCOMM\Bluetooth Software\syswow64;c:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;U:\Windows\software\MPlayer;C:\Program Files (x86)\Skype\Phone\;U:\Windows\software\ffmpeg-20150803-git-5750d6c-win64-static\bin;U:\Windows\software\libav-i686-w64-mingw32-11.2\usr\bin;U:\Windows\software\MPlayer-extra [calling]
11601b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4dd0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11611b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4dd0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11621b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4dd0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11631b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4dd0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11641b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4dd0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11651b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4dd0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11661b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4dd0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11671b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4dd0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11681b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
11691b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c4cb0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Dell\Dell Wireless WLAN Card;c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;c:\Program Files\WIDCOMM\Bluetooth Software\;c:\Program Files\WIDCOMM\Bluetooth Software\syswow64;c:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;U:\Windows\software\MPlayer;C:\Program Files (x86)\Skype\Phone\;U:\Windows\software\ffmpeg-20150803-git-5750d6c-win64-static\bin;U:\Windows\software\libav-i686-w64-mingw32-11.2\usr\bin;U:\Windows\software\MPlayer-extra [calling]
11701b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4dd0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11711b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4dd0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11721b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4dd0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11731b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4dd0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11741b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4dd0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11751b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4dd0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11761b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4dd0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11771b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4dd0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11781b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4dd0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11791b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4dd0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11801b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4dd0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11811b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4dd0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11821b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4dd0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11831b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4dd0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11841b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4dd0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11851b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4dd0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11861b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
11871b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007c4cb0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Dell\Dell Wireless WLAN Card;c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;c:\Program Files\WIDCOMM\Bluetooth Software\;c:\Program Files\WIDCOMM\Bluetooth Software\syswow64;c:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;U:\Windows\software\MPlayer;C:\Program Files (x86)\Skype\Phone\;U:\Windows\software\ffmpeg-20150803-git-5750d6c-win64-static\bin;U:\Windows\software\libav-i686-w64-mingw32-11.2\usr\bin;U:\Windows\software\MPlayer-extra [calling]
11881b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4dd0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11891b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4dd0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11901b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4dd0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11911b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4dd0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11921b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\wintrust.dll
11931b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000002781200:C:\Windows\system32 [calling]
11941b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdb30000 'C:\Windows\system32\Wintrust.dll'
11951b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\crypt32.dll
11961b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\crypt32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000002781200:C:\Windows\system32 [calling]
11971b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdba0000 'C:\Windows\system32\crypt32.dll'
11981b0c.192c: SUPR3HardenedMain: Load TrustedMain...
11991b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'opengl32.dll'.
12001b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
12011b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcp100.dll'.
12021b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcr100.dll'.
12031b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qtcorevbox4.dll'.
12041b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'qtguivbox4.dll'.
12051b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'qtnetworkvbox4.dll'.
12061b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'qtopenglvbox4.dll'.
12071b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'user32.dll'.
12081b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'gdi32.dll'.
12091b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'advapi32.dll'.
12101b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'shell32.dll'.
12111b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'ole32.dll'.
12121b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'oleaut32.dll'.
12131b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #15 'comdlg32.dll'.
12141b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'winmm.dll'.
12151b0c.192c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.dll)WinVerifyTrust
12161b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.dll
12171b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
12181b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\winmm.dll' [rcNtRedir=0xc0150008]
12191b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004bc pwszName=\Device\HarddiskVolume2\WINDOWS\System32\winmm.dll
12201b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
12211b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
12221b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=82E2B2A7826F88BEB98FFF0540C9BDB0A12F001A
12231b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\WINDOWS\System32\winmm.dll'
12241b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
12251b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
12261b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
12271b0c.192c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\winmm.dll)WinVerifyTrust
12281b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\winmm.dll
12291b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comdlg32.dll'...
12301b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'comdlg32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\comdlg32.dll' [rcNtRedir=0xc0150008]
12311b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004a4 pwszName=\Device\HarddiskVolume2\WINDOWS\System32\comdlg32.dll
12321b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
12331b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
12341b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=66EE5BDFFA413AEA9E1FE7838A08646E94136DA5
12351b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\WINDOWS\System32\comdlg32.dll'
12361b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
12371b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
12381b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'shlwapi.dll'.
12391b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
12401b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'gdi32.dll'.
12411b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'comctl32.dll'.
12421b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'shell32.dll'.
12431b0c.192c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\comdlg32.dll)WinVerifyTrust
12441b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\comdlg32.dll
12451b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
12461b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
12471b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004c8 pwszName=\Device\HarddiskVolume2\WINDOWS\System32\oleaut32.dll
12481b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
12491b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
12501b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=8A837B0D823EB506C6A4C447C1962174D27ED954
12511b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3020338~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\WINDOWS\System32\oleaut32.dll'
12521b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
12531b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ole32.dll'.
12541b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
12551b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
12561b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'user32.dll'.
12571b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'gdi32.dll'.
12581b0c.192c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\oleaut32.dll)WinVerifyTrust
12591b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\oleaut32.dll
12601b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
12611b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\ole32.dll' [rcNtRedir=0xc0150008]
12621b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004c0 pwszName=\Device\HarddiskVolume2\WINDOWS\System32\ole32.dll
12631b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
12641b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
12651b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2E93C1851E5754D607F55581B4DE2A30B711C830
12661b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_2_for_KB3072633~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\WINDOWS\System32\ole32.dll'
12671b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
12681b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
12691b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
12701b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'user32.dll'.
12711b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'rpcrt4.dll'.
12721b0c.192c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\ole32.dll)WinVerifyTrust
12731b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\ole32.dll
12741b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
12751b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\shell32.dll' [rcNtRedir=0xc0150008]
12761b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004b8 pwszName=\Device\HarddiskVolume2\WINDOWS\System32\shell32.dll
12771b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
12781b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
12791b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=0ED534A13973A0F8A98CD4EDC6CBC56E0448E994
12801b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_2_for_KB3039066~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\WINDOWS\System32\shell32.dll'
12811b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
12821b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
12831b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #21 'shlwapi.dll'.
12841b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'user32.dll'.
12851b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #24 'gdi32.dll'.
12861b0c.192c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\shell32.dll)WinVerifyTrust
12871b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\shell32.dll
12881b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
12891b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\advapi32.dll' [rcNtRedir=0xc0150008]
12901b0c.192c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\advapi32.dll
12911b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
12921b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\gdi32.dll' [rcNtRedir=0xc0150008]
12931b0c.192c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\gdi32.dll
12941b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
12951b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\user32.dll' [rcNtRedir=0xc0150008]
12961b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtopenglvbox4.dll'...
12971b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtopenglvbox4.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qtopenglvbox4.dll' [rcNtRedir=0xc0150008]
12981b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'opengl32.dll'.
12991b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
13001b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
13011b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qtguivbox4.dll'.
13021b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qtcorevbox4.dll'.
13031b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcr100.dll'.
13041b0c.192c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll)WinVerifyTrust
13051b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll
13061b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtnetworkvbox4.dll'...
13071b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtnetworkvbox4.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qtnetworkvbox4.dll' [rcNtRedir=0xc0150008]
13081b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ws2_32.dll'.
13091b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'qtcorevbox4.dll'.
13101b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcr100.dll'.
13111b0c.192c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtNetworkVBox4.dll)WinVerifyTrust
13121b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtNetworkVBox4.dll
13131b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtguivbox4.dll'...
13141b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtguivbox4.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qtguivbox4.dll' [rcNtRedir=0xc0150008]
13151b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
13161b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'comdlg32.dll'.
13171b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'oleaut32.dll'.
13181b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'imm32.dll'.
13191b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'winmm.dll'.
13201b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'winspool.drv'.
13211b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ole32.dll'.
13221b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'user32.dll'.
13231b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'advapi32.dll'.
13241b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'shell32.dll'.
13251b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'qtcorevbox4.dll'.
13261b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'msvcp100.dll'.
13271b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'msvcr100.dll'.
13281b0c.192c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll)WinVerifyTrust
13291b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll
13301b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtcorevbox4.dll'...
13311b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtcorevbox4.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qtcorevbox4.dll' [rcNtRedir=0xc0150008]
13321b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
13331b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'ole32.dll'.
13341b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
13351b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ws2_32.dll'.
13361b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcp100.dll'.
13371b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcr100.dll'.
13381b0c.192c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll)WinVerifyTrust
13391b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll
13401b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
13411b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
13421b0c.192c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
13431b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
13441b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
13451b0c.192c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
13461b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
13471b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
13481b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
13491b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\opengl32.dll' [rcNtRedir=0xc0150008]
13501b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000500 pwszName=\Device\HarddiskVolume2\WINDOWS\System32\opengl32.dll
13511b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
13521b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
13531b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=608AC397FCC42B9FBAE25CB8C25EAF4C19AA384D
13541b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\WINDOWS\System32\opengl32.dll'
13551b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
13561b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
13571b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
13581b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'gdi32.dll'.
13591b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'glu32.dll'.
13601b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ddraw.dll'.
13611b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'user32.dll'.
13621b0c.192c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\opengl32.dll)WinVerifyTrust
13631b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\opengl32.dll
13641b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
13651b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\user32.dll' [rcNtRedir=0xc0150008]
13661b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ddraw.dll'...
13671b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ddraw.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\ddraw.dll' [rcNtRedir=0xc0150008]
13681b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004ec pwszName=\Device\HarddiskVolume2\WINDOWS\System32\ddraw.dll
13691b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
13701b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
13711b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=24C763EA54CD792A0F1618411061DC356EE31FF6
13721b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\WINDOWS\System32\ddraw.dll'
13731b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
13741b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
13751b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
13761b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'dciman32.dll'.
13771b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
13781b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'setupapi.dll'.
13791b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'dwmapi.dll'.
13801b0c.192c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\ddraw.dll)WinVerifyTrust
13811b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\ddraw.dll
13821b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'glu32.dll'...
13831b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'glu32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\glu32.dll' [rcNtRedir=0xc0150008]
13841b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004d8 pwszName=\Device\HarddiskVolume2\WINDOWS\System32\glu32.dll
13851b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
13861b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
13871b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=60E45AB914E06A11F44EA76C6EF750AF892F9EA2
13881b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\WINDOWS\System32\glu32.dll'
13891b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
13901b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
13911b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'opengl32.dll'.
13921b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
13931b0c.192c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\glu32.dll)WinVerifyTrust
13941b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\glu32.dll
13951b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
13961b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\gdi32.dll' [rcNtRedir=0xc0150008]
13971b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
13981b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\advapi32.dll' [rcNtRedir=0xc0150008]
13991b0c.192c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\advapi32.dll
14001b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
14011b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
14021b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
14031b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
14041b0c.192c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
14051b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
14061b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
14071b0c.192c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
14081b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
14091b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
14101b0c.192c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\ws2_32.dll
14111b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
14121b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\advapi32.dll' [rcNtRedir=0xc0150008]
14131b0c.192c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\advapi32.dll
14141b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
14151b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\ole32.dll' [rcNtRedir=0xc0150008]
14161b0c.192c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\ole32.dll
14171b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
14181b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\user32.dll' [rcNtRedir=0xc0150008]
14191b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
14201b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
14211b0c.192c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
14221b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
14231b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
14241b0c.192c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
14251b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtcorevbox4.dll'...
14261b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtcorevbox4.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qtcorevbox4.dll' [rcNtRedir=0xc0150008]
14271b0c.192c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll
14281b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
14291b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\shell32.dll' [rcNtRedir=0xc0150008]
14301b0c.192c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\shell32.dll
14311b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
14321b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\advapi32.dll' [rcNtRedir=0xc0150008]
14331b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
14341b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\user32.dll' [rcNtRedir=0xc0150008]
14351b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
14361b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\ole32.dll' [rcNtRedir=0xc0150008]
14371b0c.192c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\ole32.dll
14381b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winspool.drv'...
14391b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'winspool.drv' -> '\Device\HarddiskVolume2\WINDOWS\System32\winspool.drv' [rcNtRedir=0xc0150008]
14401b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004cc pwszName=\Device\HarddiskVolume2\WINDOWS\System32\winspool.drv
14411b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
14421b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
14431b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=C89A2ED7B99A056D78CA6BAC9CCAB8B1FF119A14
14441b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\WINDOWS\System32\winspool.drv'
14451b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
14461b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
14471b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
14481b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
14491b0c.192c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\winspool.drv)WinVerifyTrust
14501b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\winspool.drv
14511b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
14521b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\winmm.dll' [rcNtRedir=0xc0150008]
14531b0c.192c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\winmm.dll
14541b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
14551b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\imm32.dll' [rcNtRedir=0xc0150008]
14561b0c.192c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\imm32.dll
14571b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
14581b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
14591b0c.192c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\oleaut32.dll
14601b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comdlg32.dll'...
14611b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'comdlg32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\comdlg32.dll' [rcNtRedir=0xc0150008]
14621b0c.192c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\comdlg32.dll
14631b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
14641b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\gdi32.dll' [rcNtRedir=0xc0150008]
14651b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
14661b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
14671b0c.192c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
14681b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtcorevbox4.dll'...
14691b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtcorevbox4.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qtcorevbox4.dll' [rcNtRedir=0xc0150008]
14701b0c.192c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll
14711b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
14721b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
14731b0c.192c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\ws2_32.dll
14741b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
14751b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
14761b0c.192c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
14771b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtcorevbox4.dll'...
14781b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtcorevbox4.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qtcorevbox4.dll' [rcNtRedir=0xc0150008]
14791b0c.192c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll
14801b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtguivbox4.dll'...
14811b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtguivbox4.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qtguivbox4.dll' [rcNtRedir=0xc0150008]
14821b0c.192c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll
14831b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
14841b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\user32.dll' [rcNtRedir=0xc0150008]
14851b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
14861b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\gdi32.dll' [rcNtRedir=0xc0150008]
14871b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
14881b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\opengl32.dll' [rcNtRedir=0xc0150008]
14891b0c.192c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\opengl32.dll
14901b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
14911b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\gdi32.dll' [rcNtRedir=0xc0150008]
14921b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
14931b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\user32.dll' [rcNtRedir=0xc0150008]
14941b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
14951b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
14961b0c.192c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\shlwapi.dll
14971b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
14981b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
14991b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
15001b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
15011b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
15021b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\user32.dll' [rcNtRedir=0xc0150008]
15031b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
15041b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\gdi32.dll' [rcNtRedir=0xc0150008]
15051b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
15061b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
15071b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
15081b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\gdi32.dll' [rcNtRedir=0xc0150008]
15091b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
15101b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\user32.dll' [rcNtRedir=0xc0150008]
15111b0c.192c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\user32.dll
15121b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
15131b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
15141b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
15151b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
15161b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
15171b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\ole32.dll' [rcNtRedir=0xc0150008]
15181b0c.192c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\ole32.dll
15191b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
15201b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\shell32.dll' [rcNtRedir=0xc0150008]
15211b0c.192c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\shell32.dll
15221b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comctl32.dll'...
15231b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'comctl32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\comctl32.dll' [rcNtRedir=0x0]
15241b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004d0 pwszName=\Device\HarddiskVolume2\WINDOWS\System32\comctl32.dll
15251b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
15261b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
15271b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=761964761EE466757E306124E042F4C2ACBEA092
15281b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3059317~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\WINDOWS\System32\comctl32.dll'
15291b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
15301b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'advapi32.dll'.
15311b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
15321b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
15331b0c.192c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\comctl32.dll)WinVerifyTrust
15341b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\comctl32.dll
15351b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
15361b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\gdi32.dll' [rcNtRedir=0xc0150008]
15371b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
15381b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\user32.dll' [rcNtRedir=0xc0150008]
15391b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
15401b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
15411b0c.192c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\shlwapi.dll
15421b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
15431b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
15441b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
15451b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\user32.dll' [rcNtRedir=0xc0150008]
15461b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
15471b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
15481b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
15491b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\user32.dll' [rcNtRedir=0xc0150008]
15501b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
15511b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\gdi32.dll' [rcNtRedir=0xc0150008]
15521b0c.192c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\gdi32.dll
15531b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
15541b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\advapi32.dll' [rcNtRedir=0xc0150008]
15551b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
15561b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\user32.dll' [rcNtRedir=0xc0150008]
15571b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
15581b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\gdi32.dll' [rcNtRedir=0xc0150008]
15591b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
15601b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
15611b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
15621b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\user32.dll' [rcNtRedir=0xc0150008]
15631b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
15641b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\opengl32.dll' [rcNtRedir=0xc0150008]
15651b0c.192c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\opengl32.dll
15661b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
15671b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
15681b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dwmapi.dll'...
15691b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'dwmapi.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\dwmapi.dll' [rcNtRedir=0xc0150008]
15701b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000510 pwszName=\Device\HarddiskVolume2\WINDOWS\System32\dwmapi.dll
15711b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
15721b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
15731b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=C408F88301F22BE596490B4A80BD2E09034763B4
15741b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3048761~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\WINDOWS\System32\dwmapi.dll'
15751b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
15761b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
15771b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
15781b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
15791b0c.192c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\dwmapi.dll)WinVerifyTrust
15801b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\dwmapi.dll
15811b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
15821b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\setupapi.dll' [rcNtRedir=0xc0150008]
15831b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000518 pwszName=\Device\HarddiskVolume2\WINDOWS\System32\setupapi.dll
15841b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
15851b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
15861b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=1499C4FEA6E143F9BEC35B4FFA098917D3A6EBF2
15871b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\WINDOWS\System32\setupapi.dll'
15881b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
15891b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'cfgmgr32.dll'.
15901b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcrt.dll'.
15911b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'gdi32.dll'.
15921b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
15931b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'user32.dll'.
15941b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'oleaut32.dll'.
15951b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'devobj.dll'.
15961b0c.192c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\setupapi.dll)WinVerifyTrust
15971b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\setupapi.dll
15981b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
15991b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\gdi32.dll' [rcNtRedir=0xc0150008]
16001b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dciman32.dll'...
16011b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'dciman32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\dciman32.dll' [rcNtRedir=0xc0150008]
16021b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000051c pwszName=\Device\HarddiskVolume2\WINDOWS\System32\dciman32.dll
16031b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
16041b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
16051b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=8C9D8A0CA28E607D6CBDB572E9C7896DA20280E0
16061b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3079904~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\WINDOWS\System32\dciman32.dll'
16071b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
16081b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
16091b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'gdi32.dll'.
16101b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
16111b0c.192c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\dciman32.dll)WinVerifyTrust
16121b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\dciman32.dll
16131b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
16141b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\user32.dll' [rcNtRedir=0xc0150008]
16151b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
16161b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
16171b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
16181b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\user32.dll' [rcNtRedir=0xc0150008]
16191b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
16201b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\gdi32.dll' [rcNtRedir=0xc0150008]
16211b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
16221b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
16231b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'devobj.dll'...
16241b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'devobj.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\devobj.dll' [rcNtRedir=0xc0150008]
16251b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000528 pwszName=\Device\HarddiskVolume2\WINDOWS\System32\devobj.dll
16261b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
16271b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
16281b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B410A095222E69F0ECE7D66E4AC27A7125D2EB5A
16291b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\WINDOWS\System32\devobj.dll'
16301b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
16311b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
16321b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'cfgmgr32.dll'.
16331b0c.192c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\devobj.dll)WinVerifyTrust
16341b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\devobj.dll
16351b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
16361b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
16371b0c.192c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\oleaut32.dll
16381b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
16391b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\user32.dll' [rcNtRedir=0xc0150008]
16401b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
16411b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
16421b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
16431b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\gdi32.dll' [rcNtRedir=0xc0150008]
16441b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
16451b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
16461b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
16471b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
16481b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000534 pwszName=\Device\HarddiskVolume2\WINDOWS\System32\cfgmgr32.dll
16491b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
16501b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
16511b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=8F731777EFC4BC982C1E1467FBF29A74CC14D93A
16521b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\WINDOWS\System32\cfgmgr32.dll'
16531b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
16541b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
16551b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'rpcrt4.dll'.
16561b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
16571b0c.192c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\cfgmgr32.dll)WinVerifyTrust
16581b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\cfgmgr32.dll
16591b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
16601b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\user32.dll' [rcNtRedir=0xc0150008]
16611b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
16621b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\gdi32.dll' [rcNtRedir=0xc0150008]
16631b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
16641b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
16651b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
16661b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\advapi32.dll' [rcNtRedir=0xc0150008]
16671b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
16681b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
16691b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
16701b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
16711b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
16721b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
16731b0c.192c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\cfgmgr32.dll
16741b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
16751b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
16761b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VirtualBox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000086e0f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
16771b0c.192c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.dll
16781b0c.192c: supR3HardenedDllNotificationCallback: load 000007fee4320000 LB 0x00ab0000 C:\Program Files\Oracle\VirtualBox\VirtualBox.dll [fFlags=0x0]
16791b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.dll
16801b0c.192c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\opengl32.dll
16811b0c.192c: supR3HardenedDllNotificationCallback: load 000007fee4200000 LB 0x0011d000 C:\Windows\system32\OPENGL32.dll [fFlags=0x0]
16821b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\opengl32.dll
16831b0c.192c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\glu32.dll
16841b0c.192c: supR3HardenedDllNotificationCallback: load 000007feec1e0000 LB 0x0002d000 C:\Windows\system32\GLU32.dll [fFlags=0x0]
16851b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\glu32.dll
16861b0c.192c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\ddraw.dll
16871b0c.192c: supR3HardenedDllNotificationCallback: load 000007fefae10000 LB 0x000f1000 C:\Windows\system32\DDRAW.dll [fFlags=0x0]
16881b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\ddraw.dll
16891b0c.192c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\dciman32.dll
16901b0c.192c: supR3HardenedDllNotificationCallback: load 000007fefb110000 LB 0x00008000 C:\Windows\system32\DCIMAN32.dll [fFlags=0x0]
16911b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\dciman32.dll
16921b0c.192c: supR3HardenedDllNotificationCallback: load 000007fefeb20000 LB 0x001d7000 C:\Windows\system32\SETUPAPI.dll [fFlags=0x0]
16931b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\setupapi.dll
16941b0c.192c: supR3HardenedDllNotificationCallback: load 000007fefdda0000 LB 0x00036000 C:\Windows\system32\CFGMGR32.dll [fFlags=0x0]
16951b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\cfgmgr32.dll
16961b0c.192c: supR3HardenedDllNotificationCallback: load 000007feffb70000 LB 0x000d7000 C:\Windows\system32\OLEAUT32.dll [fFlags=0x0]
16971b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\oleaut32.dll
16981b0c.192c: supR3HardenedDllNotificationCallback: load 000007fefe5e0000 LB 0x00203000 C:\Windows\system32\ole32.dll [fFlags=0x0]
16991b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\ole32.dll
17001b0c.192c: supR3HardenedDllNotificationCallback: load 000007fefdae0000 LB 0x0001a000 C:\Windows\system32\DEVOBJ.dll [fFlags=0x0]
17011b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\devobj.dll
17021b0c.192c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\dwmapi.dll
17031b0c.192c: supR3HardenedDllNotificationCallback: load 000007fefbb10000 LB 0x00018000 C:\Windows\system32\dwmapi.dll [fFlags=0x0]
17041b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\dwmapi.dll
17051b0c.192c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll
17061b0c.192c: supR3HardenedDllNotificationCallback: load 000000005d960000 LB 0x002de000 C:\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll [fFlags=0x0]
17071b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll
17081b0c.192c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll
17091b0c.192c: supR3HardenedDllNotificationCallback: load 000000005cff0000 LB 0x0096c000 C:\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll [fFlags=0x0]
17101b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll
17111b0c.192c: supR3HardenedDllNotificationCallback: load 000007fefea50000 LB 0x00097000 C:\Windows\system32\COMDLG32.dll [fFlags=0x0]
17121b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\comdlg32.dll
17131b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'advapi32.dll'.
17141b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
17151b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
17161b0c.192c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\WINDOWS\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll)
17171b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll
17181b0c.192c: supR3HardenedDllNotificationCallback: load 000007fef6d20000 LB 0x000a0000 C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\COMCTL32.dll [fFlags=0x0]
17191b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll [avoiding WinVerifyTrust]
17201b0c.192c: supR3HardenedDllNotificationCallback: load 000007fefed00000 LB 0x00d89000 C:\Windows\system32\SHELL32.dll [fFlags=0x0]
17211b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\shell32.dll
17221b0c.192c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\winmm.dll
17231b0c.192c: supR3HardenedDllNotificationCallback: load 000007fefbcd0000 LB 0x0003b000 C:\Windows\system32\WINMM.dll [fFlags=0x0]
17241b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\winmm.dll
17251b0c.192c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\winspool.drv
17261b0c.192c: supR3HardenedDllNotificationCallback: load 000007fefb4a0000 LB 0x00071000 C:\Windows\system32\WINSPOOL.DRV [fFlags=0x0]
17271b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\winspool.drv
17281b0c.192c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtNetworkVBox4.dll
17291b0c.192c: supR3HardenedDllNotificationCallback: load 000000005cee0000 LB 0x00105000 C:\Program Files\Oracle\VirtualBox\QtNetworkVBox4.dll [fFlags=0x0]
17301b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtNetworkVBox4.dll
17311b0c.192c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll
17321b0c.192c: supR3HardenedDllNotificationCallback: load 000000005ce00000 LB 0x000dc000 C:\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll [fFlags=0x0]
17331b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll
17341b0c.192c: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume2\WINDOWS\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll'.
17351b0c.192c: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\WINDOWS\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll' [rescheduled]
17361b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\imm32.dll
17371b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
17381b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\user32.dll' [rcNtRedir=0xc0150008]
17391b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
17401b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\gdi32.dll' [rcNtRedir=0xc0150008]
17411b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
17421b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\advapi32.dll' [rcNtRedir=0xc0150008]
17431b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\imm32.dll (Input=imm32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000086e4e0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
17441b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feffc50000 'C:\Windows\system32\imm32.dll'
17451b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4320000 'C:\Program Files\Oracle\VirtualBox\VirtualBox.dll'
17461b0c.192c: SUPR3HardenedMain: Calling TrustedMain (000007fee4321770)...
17471b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\winmm.dll
17481b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\winmm.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000086e0f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
17491b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbcd0000 'C:\Windows\system32\winmm.dll'
17501b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000005c8 pwszName=\Device\HarddiskVolume2\WINDOWS\System32\uxtheme.dll
17511b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
17521b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
17531b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=936D45CC7026757A151F62882B557DD75D5FCB21
17541b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\WINDOWS\System32\uxtheme.dll'
17551b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
17561b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
17571b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
17581b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'gdi32.dll'.
17591b0c.192c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\uxtheme.dll)WinVerifyTrust
17601b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\uxtheme.dll
17611b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
17621b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\gdi32.dll' [rcNtRedir=0xc0150008]
17631b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
17641b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\user32.dll' [rcNtRedir=0xc0150008]
17651b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
17661b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
17671b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000002820860:C:\Windows\system32;C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
17681b0c.192c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\uxtheme.dll
17691b0c.192c: supR3HardenedDllNotificationCallback: load 000007fefbfc0000 LB 0x00056000 C:\Windows\system32\uxtheme.dll [fFlags=0x0]
17701b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\uxtheme.dll
17711b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbfc0000 'C:\Windows\system32\uxtheme.dll'
17721b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\uxtheme.dll
17731b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000002820860:C:\Windows\system32;C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
17741b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbfc0000 'C:\Windows\system32\uxtheme.dll'
17751b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\uxtheme.dll
17761b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000002821570:C:\Windows\system32;C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
17771b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbfc0000 'C:\Windows\system32\uxtheme.dll'
17781b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\uxtheme.dll
17791b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000002821570:C:\Windows\system32;C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
17801b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbfc0000 'C:\Windows\system32\uxtheme.dll'
17811b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\dwmapi.dll
17821b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\dwmapi.dll (Input=dwmapi.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000086e0f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
17831b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbb10000 'C:\Windows\system32\dwmapi.dll'
17841b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\cryptbase.dll
17851b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTBASE.dll (Input=CRYPTBASE.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000086e0f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
17861b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd8c0000 'C:\Windows\system32\CRYPTBASE.dll'
17871b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\shell32.dll
17881b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000086e0f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
17891b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefed00000 'C:\Windows\system32\shell32.dll'
17901b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\kernel32.dll
17911b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000086e0f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
17921b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077b50000 'C:\Windows\system32\kernel32.dll'
17931b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\uxtheme.dll
17941b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000086e0f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
17951b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbfc0000 'C:\Windows\system32\uxtheme.dll'
17961b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\uxtheme.dll
17971b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000086e0f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
17981b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbfc0000 'C:\Windows\system32\uxtheme.dll'
17991b0c.192c: supR3HardenedMonitor_LdrLoadDll: error opening 'C:\Windows\system32\wintab32.dll': 0 (NtPath=\??\C:\Windows\system32\wintab32.dll; Input=C:\Windows\system32\wintab32.dll; rcNtGetDll=0x0
18001b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wintab32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000086e0f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
18011b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000135 'C:\Windows\system32\wintab32.dll'
18021b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077a50000 'C:\Windows\system32\user32.dll'
18031b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\uxtheme.dll
18041b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000086e0f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
18051b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbfc0000 'C:\Windows\system32\uxtheme.dll'
18061b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077a50000 'C:\Windows\system32\user32.dll'
18071b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feffa90000 'C:\Windows\system32\advapi32.dll'
18081b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\userenv.dll
18091b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\userenv.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000086e0f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
18101b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdb00000 'C:\Windows\system32\userenv.dll'
18111b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\kernel32.dll
18121b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000086e0f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
18131b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077b50000 'C:\Windows\system32\kernel32.dll'
18141b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000061c pwszName=\Device\HarddiskVolume2\WINDOWS\System32\clbcatq.dll
18151b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
18161b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
18171b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B01469787CE9D8C6FEE98FB207652B88B8494526
18181b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\WINDOWS\System32\clbcatq.dll'
18191b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
18201b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
18211b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'ole32.dll'.
18221b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
18231b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
18241b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
18251b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'rpcrt4.dll'.
18261b0c.192c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\clbcatq.dll)WinVerifyTrust
18271b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\clbcatq.dll
18281b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
18291b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
18301b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
18311b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
18321b0c.192c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\oleaut32.dll
18331b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
18341b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\advapi32.dll' [rcNtRedir=0xc0150008]
18351b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
18361b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\user32.dll' [rcNtRedir=0xc0150008]
18371b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
18381b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\ole32.dll' [rcNtRedir=0xc0150008]
18391b0c.192c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\ole32.dll
18401b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
18411b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
18421b0c.192c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll
18431b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CLBCatQ.DLL (Input=CLBCatQ.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000086e0f0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
18441b0c.192c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\clbcatq.dll
18451b0c.192c: supR3HardenedDllNotificationCallback: load 000007fefe200000 LB 0x00099000 C:\Windows\system32\CLBCatQ.DLL [fFlags=0x0]
18461b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\clbcatq.dll
18471b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe200000 'C:\Windows\system32\CLBCatQ.DLL'
18481b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feffa90000 'C:\Windows\system32\ADVAPI32.dll'
18491b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\cryptsp.dll
18501b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTSP.dll (Input=CRYPTSP.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000086e840:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
18511b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd440000 'C:\Windows\system32\CRYPTSP.dll'
18521b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000063c pwszName=\Device\HarddiskVolume2\WINDOWS\System32\RpcRtRemote.dll
18531b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
18541b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
18551b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=DFC4A7C7E103D324218E6EF5D219B953746D6EC1
18561b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\WINDOWS\System32\RpcRtRemote.dll'
18571b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
18581b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'rpcrt4.dll'.
18591b0c.192c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\RpcRtRemote.dll)WinVerifyTrust
18601b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\RpcRtRemote.dll
18611b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
18621b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
18631b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\RpcRtRemote.dll (Input=RpcRtRemote.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000086e840:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
18641b0c.192c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\RpcRtRemote.dll
18651b0c.192c: supR3HardenedDllNotificationCallback: load 000007fefd970000 LB 0x00014000 C:\Windows\system32\RpcRtRemote.dll [fFlags=0x0]
18661b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\RpcRtRemote.dll
18671b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd970000 'C:\Windows\system32\RpcRtRemote.dll'
18681b0c.1914: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
18691b0c.1914: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
18701b0c.1914: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'psapi.dll'.
18711b0c.1914: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vboxrt.dll'.
18721b0c.1914: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'advapi32.dll'.
18731b0c.1914: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'version.dll'.
18741b0c.1914: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'ws2_32.dll'.
18751b0c.1914: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'ole32.dll'.
18761b0c.1914: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'oleaut32.dll'.
18771b0c.1914: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxC.dll)WinVerifyTrust
18781b0c.1914: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxC.dll
18791b0c.1914: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
18801b0c.1914: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
18811b0c.1914: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\oleaut32.dll
18821b0c.1914: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
18831b0c.1914: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\ole32.dll' [rcNtRedir=0xc0150008]
18841b0c.1914: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\ole32.dll
18851b0c.1914: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
18861b0c.1914: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
18871b0c.1914: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\ws2_32.dll
18881b0c.1914: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'version.dll'...
18891b0c.1914: supR3HardenedWinVerifyCacheProcessImportTodos: 'version.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\version.dll' [rcNtRedir=0xc0150008]
18901b0c.1914: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000690 pwszName=\Device\HarddiskVolume2\WINDOWS\System32\version.dll
18911b0c.1914: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
18921b0c.1914: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
18931b0c.1914: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=A3AB94A028D0330A3DBCAE54C04C648532198DB9
18941b0c.1914: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\WINDOWS\System32\version.dll'
18951b0c.1914: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
18961b0c.1914: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
18971b0c.1914: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\version.dll)WinVerifyTrust
18981b0c.1914: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\version.dll
18991b0c.1914: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
19001b0c.1914: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\advapi32.dll' [rcNtRedir=0xc0150008]
19011b0c.1914: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\advapi32.dll
19021b0c.1914: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
19031b0c.1914: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
19041b0c.1914: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'psapi.dll'...
19051b0c.1914: supR3HardenedWinVerifyCacheProcessImportTodos: 'psapi.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\psapi.dll' [rcNtRedir=0xc0150008]
19061b0c.1914: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000694 pwszName=\Device\HarddiskVolume2\WINDOWS\System32\psapi.dll
19071b0c.1914: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
19081b0c.1914: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
19091b0c.1914: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=561BAAB249C395B66D294444DF251EDB701DB607
19101b0c.1914: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\WINDOWS\System32\psapi.dll'
19111b0c.1914: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
19121b0c.1914: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\psapi.dll)WinVerifyTrust
19131b0c.1914: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\psapi.dll
19141b0c.1914: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
19151b0c.1914: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
19161b0c.1914: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
19171b0c.1914: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
19181b0c.1914: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
19191b0c.1914: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
19201b0c.1914: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
19211b0c.1914: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxC.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000089b100:C:\Program Files\Oracle\VirtualBox;C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
19221b0c.1914: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxC.dll
19231b0c.1914: supR3HardenedDllNotificationCallback: load 000007fee3c20000 LB 0x005d5000 C:\Program Files\Oracle\VirtualBox\VBoxC.dll [fFlags=0x0]
19241b0c.1914: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxC.dll
19251b0c.1914: supR3HardenedDllNotificationCallback: load 0000000077e30000 LB 0x00007000 C:\Windows\system32\PSAPI.DLL [fFlags=0x0]
19261b0c.1914: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\psapi.dll
19271b0c.1914: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\version.dll
19281b0c.1914: supR3HardenedDllNotificationCallback: load 000007fefcac0000 LB 0x0000c000 C:\Windows\system32\VERSION.dll [fFlags=0x0]
19291b0c.1914: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\version.dll
19301b0c.1914: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee3c20000 'C:\Program Files\Oracle\VirtualBox\VBoxC.dll'
19311b0c.1914: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\oleaut32.dll
19321b0c.1914: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\oleaut32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000002821570:C:\Windows\system32;C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
19331b0c.1914: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feffb70000 'C:\Windows\system32\oleaut32.dll'
19341b0c.1914: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000684 pwszName=\Device\HarddiskVolume2\WINDOWS\System32\sxs.dll
19351b0c.1914: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
19361b0c.1914: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
19371b0c.1914: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=FCAC019C19F878C2B628662A84ECE75A01818BC9
19381b0c.1914: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\WINDOWS\System32\sxs.dll'
19391b0c.1914: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
19401b0c.1914: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\sxs.dll)WinVerifyTrust
19411b0c.1914: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\sxs.dll
19421b0c.1914: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\SXS.DLL (Input=SXS.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000086ecc0:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
19431b0c.1914: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\sxs.dll
19441b0c.1914: supR3HardenedDllNotificationCallback: load 000007fefd8d0000 LB 0x00091000 C:\Windows\system32\SXS.DLL [fFlags=0x0]
19451b0c.1914: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\sxs.dll
19461b0c.1914: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd8d0000 'C:\Windows\system32\SXS.DLL'
19471b0c.1914: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feffa90000 'C:\Windows\system32\ADVAPI32.dll'
19481b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\oleaut32.dll
19491b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\OLEAUT32.dll (Input=OLEAUT32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000086ef00:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
19501b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feffb70000 'C:\Windows\system32\OLEAUT32.dll'
19511b0c.192c: supR3HardenedMonitor_LdrLoadDll: error opening 'C:\Windows\system32\wintab32.dll': 0 (NtPath=\??\C:\Windows\system32\wintab32.dll; Input=C:\Windows\system32\wintab32.dll; rcNtGetDll=0x0
19521b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wintab32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000004f3b230:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
19531b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000135 'C:\Windows\system32\wintab32.dll'
19541b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe570000 'C:\Windows\system32\gdi32.dll'
19551b0c.1b60: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
19561b0c.1b60: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
19571b0c.1b60: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMain.dll)WinVerifyTrust
19581b0c.1b60: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMain.dll
19591b0c.1b60: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
19601b0c.1b60: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
19611b0c.1b60: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
19621b0c.1b60: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
19631b0c.1b60: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.amd64/VBoxPuelMain.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000004f3a420:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
19641b0c.1b60: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMain.dll
19651b0c.1b60: supR3HardenedDllNotificationCallback: load 000007feec1d0000 LB 0x0000d000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMain.DLL [fFlags=0x0]
19661b0c.1b60: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMain.dll
19671b0c.1b60: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec1d0000 'C:\Program Files\Oracle\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.amd64/VBoxPuelMain.DLL'
19681b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077a50000 'C:\Windows\system32\user32.dll'
19691b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\shell32.dll
19701b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000086ed50:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
19711b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefed00000 'C:\Windows\system32\shell32.dll'
19721b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'vboxoglhostcrutil.dll'.
19731b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
19741b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcr100.dll'.
19751b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qtcorevbox4.dll'.
19761b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qtguivbox4.dll'.
19771b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'qtopenglvbox4.dll'.
19781b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'opengl32.dll'.
19791b0c.192c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxTestOGL.exe)
19801b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxTestOGL.exe
19811b0c.192c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxTestOGL.exe'
19821b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000aa8 pwszName=\Device\HarddiskVolume2\WINDOWS\System32\apphelp.dll
19831b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
19841b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
19851b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=8FFB8CDACDC5C9C6D9256E97FB0710E2753FFAA1
19861b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3045645~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\WINDOWS\System32\apphelp.dll'
19871b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
19881b0c.192c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\apphelp.dll)WinVerifyTrust
19891b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\apphelp.dll
19901b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
19911b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\opengl32.dll' [rcNtRedir=0xc0150008]
19921b0c.192c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\opengl32.dll
19931b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtopenglvbox4.dll'...
19941b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtopenglvbox4.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qtopenglvbox4.dll' [rcNtRedir=0xc0150008]
19951b0c.192c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll
19961b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtguivbox4.dll'...
19971b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtguivbox4.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qtguivbox4.dll' [rcNtRedir=0xc0150008]
19981b0c.192c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll
19991b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtcorevbox4.dll'...
20001b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtcorevbox4.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qtcorevbox4.dll' [rcNtRedir=0xc0150008]
20011b0c.192c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll
20021b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
20031b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
20041b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
20051b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
20061b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxoglhostcrutil.dll'...
20071b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxoglhostcrutil.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxoglhostcrutil.dll' [rcNtRedir=0xc0150008]
20081b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
20091b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
20101b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'shlwapi.dll'.
20111b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ws2_32.dll'.
20121b0c.192c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLhostcrutil.dll)WinVerifyTrust
20131b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLhostcrutil.dll
20141b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
20151b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
20161b0c.192c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\ws2_32.dll
20171b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
20181b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
20191b0c.192c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\shlwapi.dll
20201b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
20211b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
20221b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
20231b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
20241b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\apphelp.dll (rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
20251b0c.192c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\apphelp.dll
20261b0c.192c: supR3HardenedDllNotificationCallback: load 000007fefd860000 LB 0x00057000 C:\Windows\system32\apphelp.dll [fFlags=0x0]
20271b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\apphelp.dll
20281b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd860000 'C:\Windows\system32\apphelp.dll'
20291b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
20301b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
20311b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'shell32.dll'.
20321b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ole32.dll'.
20331b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
20341b0c.192c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\WIDCOMM\Bluetooth Software\BtMmHook.dll)WinVerifyTrust
20351b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\WIDCOMM\Bluetooth Software\BtMmHook.dll
20361b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
20371b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
20381b0c.192c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\oleaut32.dll
20391b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
20401b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\ole32.dll' [rcNtRedir=0xc0150008]
20411b0c.192c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\ole32.dll
20421b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
20431b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\shell32.dll' [rcNtRedir=0xc0150008]
20441b0c.192c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\shell32.dll
20451b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
20461b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\advapi32.dll' [rcNtRedir=0xc0150008]
20471b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
20481b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\user32.dll' [rcNtRedir=0xc0150008]
20491b0c.192c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\user32.dll
20501b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\WIDCOMM\Bluetooth Software\btmmhook.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000002cd40c0:C:\Program Files\WIDCOMM\Bluetooth Software;C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
20511b0c.192c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\WIDCOMM\Bluetooth Software\BtMmHook.dll
20521b0c.192c: supR3HardenedDllNotificationCallback: load 0000000010000000 LB 0x00065000 C:\Program Files\WIDCOMM\Bluetooth Software\btmmhook.dll [fFlags=0x0]
20531b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\WIDCOMM\Bluetooth Software\BtMmHook.dll
20541b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\psapi.dll
20551b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\PSAPI.DLL (Input=PSAPI.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000004f3a810:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
20561b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077e30000 'C:\Windows\system32\PSAPI.DLL'
20571b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000010000000 'C:\Program Files\WIDCOMM\Bluetooth Software\btmmhook.dll'
20581b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feffa90000 'C:\Windows\system32\ADVAPI32.dll'
20591b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\ole32.dll
20601b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ole32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000004f3a810:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
20611b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe5e0000 'C:\Windows\system32\ole32.dll'
20621b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe5e0000 'C:\Windows\system32\ole32.dll'
20631b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feffb70000 'C:\Windows\system32\OLEAUT32.dll'
20641b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000af0 pwszName=\Device\HarddiskVolume2\WINDOWS\System32\wbem\wbemprox.dll
20651b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
20661b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
20671b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=41D7AA7A9ECA84ABF6801478BA3134174B21C472
20681b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\WINDOWS\System32\wbem\wbemprox.dll'
20691b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
20701b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
20711b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'wbemcomn.dll'.
20721b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
20731b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
20741b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ole32.dll'.
20751b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'ws2_32.dll'.
20761b0c.192c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\wbem\wbemprox.dll)WinVerifyTrust
20771b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\wbem\wbemprox.dll
20781b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
20791b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
20801b0c.192c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\ws2_32.dll
20811b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
20821b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\ole32.dll' [rcNtRedir=0xc0150008]
20831b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
20841b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
20851b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
20861b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\advapi32.dll' [rcNtRedir=0xc0150008]
20871b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wbemcomn.dll'...
20881b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'wbemcomn.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\wbemcomn.dll' [rcNtRedir=0xc0150008]
20891b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000af8 pwszName=\Device\HarddiskVolume2\WINDOWS\System32\wbemcomn.dll
20901b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
20911b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
20921b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=03D0A77E5195AA70198FDE6C2FAC2C76FF200674
20931b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\WINDOWS\System32\wbemcomn.dll'
20941b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
20951b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
20961b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'oleaut32.dll'.
20971b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'ole32.dll'.
20981b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
20991b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ws2_32.dll'.
21001b0c.192c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\wbemcomn.dll)WinVerifyTrust
21011b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\wbemcomn.dll
21021b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
21031b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
21041b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
21051b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
21061b0c.192c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\ws2_32.dll
21071b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
21081b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\user32.dll' [rcNtRedir=0xc0150008]
21091b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
21101b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\ole32.dll' [rcNtRedir=0xc0150008]
21111b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
21121b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
21131b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
21141b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
21151b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wbem\wbemprox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000861e30:C:\Windows\system32\wbem;C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
21161b0c.192c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\wbem\wbemprox.dll
21171b0c.192c: supR3HardenedDllNotificationCallback: load 000007feebe20000 LB 0x0000f000 C:\Windows\system32\wbem\wbemprox.dll [fFlags=0x0]
21181b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\wbem\wbemprox.dll
21191b0c.192c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\wbemcomn.dll
21201b0c.192c: supR3HardenedDllNotificationCallback: load 000007feec020000 LB 0x00086000 C:\Windows\system32\wbemcomn.dll [fFlags=0x0]
21211b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\wbemcomn.dll
21221b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feebe20000 'C:\Windows\system32\wbem\wbemprox.dll'
21231b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000b14 pwszName=\Device\HarddiskVolume2\WINDOWS\System32\wbem\wbemsvc.dll
21241b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
21251b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
21261b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=83AB88529BF28CFF670EA617E0B9C376CFE28B0F
21271b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\WINDOWS\System32\wbem\wbemsvc.dll'
21281b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
21291b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
21301b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'rpcrt4.dll'.
21311b0c.192c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\wbem\wbemsvc.dll)WinVerifyTrust
21321b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\wbem\wbemsvc.dll
21331b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
21341b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
21351b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
21361b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
21371b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wbem\wbemsvc.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000861e30:C:\Windows\system32\wbem;C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
21381b0c.192c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\wbem\wbemsvc.dll
21391b0c.192c: supR3HardenedDllNotificationCallback: load 000007fee7260000 LB 0x00014000 C:\Windows\system32\wbem\wbemsvc.dll [fFlags=0x0]
21401b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\wbem\wbemsvc.dll
21411b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7260000 'C:\Windows\system32\wbem\wbemsvc.dll'
21421b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000b20 pwszName=\Device\HarddiskVolume2\WINDOWS\System32\wbem\fastprox.dll
21431b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
21441b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
21451b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=391AD7580DBA8EA6A4190F5A010E834B8C320D79
21461b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\WINDOWS\System32\wbem\fastprox.dll'
21471b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
21481b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
21491b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'wbemcomn.dll'.
21501b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
21511b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'oleaut32.dll'.
21521b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ole32.dll'.
21531b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ntdsapi.dll'.
21541b0c.192c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\wbem\fastprox.dll)WinVerifyTrust
21551b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\wbem\fastprox.dll
21561b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntdsapi.dll'...
21571b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntdsapi.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\ntdsapi.dll' [rcNtRedir=0xc0150008]
21581b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000b08 pwszName=\Device\HarddiskVolume2\WINDOWS\System32\ntdsapi.dll
21591b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
21601b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
21611b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=67C74E045820FCAB3FC8AD5C180928A20C1F11CE
21621b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\WINDOWS\System32\ntdsapi.dll'
21631b0c.192c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
21641b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
21651b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'rpcrt4.dll'.
21661b0c.192c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'ws2_32.dll'.
21671b0c.192c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\ntdsapi.dll)WinVerifyTrust
21681b0c.192c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\ntdsapi.dll
21691b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
21701b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\ole32.dll' [rcNtRedir=0xc0150008]
21711b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
21721b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
21731b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
21741b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\advapi32.dll' [rcNtRedir=0xc0150008]
21751b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wbemcomn.dll'...
21761b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'wbemcomn.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\wbemcomn.dll' [rcNtRedir=0xc0150008]
21771b0c.192c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\wbemcomn.dll
21781b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
21791b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
21801b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
21811b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
21821b0c.192c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\ws2_32.dll
21831b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
21841b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
21851b0c.192c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\rpcrt4.dll
21861b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
21871b0c.192c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
21881b0c.192c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wbem\fastprox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000861e30:C:\Windows\system32\wbem;C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
21891b0c.192c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\wbem\fastprox.dll
21901b0c.192c: supR3HardenedDllNotificationCallback: load 000007feebe60000 LB 0x000e2000 C:\Windows\system32\wbem\fastprox.dll [fFlags=0x0]
21911b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\wbem\fastprox.dll
21921b0c.192c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\ntdsapi.dll
21931b0c.192c: supR3HardenedDllNotificationCallback: load 000007feebe30000 LB 0x00027000 C:\Windows\system32\NTDSAPI.dll [fFlags=0x0]
21941b0c.192c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\ntdsapi.dll
21951b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feebe60000 'C:\Windows\system32\wbem\fastprox.dll'
21961b0c.192c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feffb70000 'C:\Windows\system32\OLEAUT32.dll'
21971b0c.171c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
21981b0c.171c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
21991b0c.171c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
22001b0c.171c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'gdi32.dll'.
22011b0c.171c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'advapi32.dll'.
22021b0c.171c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ws2_32.dll'.
22031b0c.171c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxVRDP.dll)WinVerifyTrust
22041b0c.171c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxVRDP.dll
22051b0c.171c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
22061b0c.171c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
22071b0c.171c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
22081b0c.171c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\advapi32.dll' [rcNtRedir=0xc0150008]
22091b0c.171c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
22101b0c.171c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\gdi32.dll' [rcNtRedir=0xc0150008]
22111b0c.171c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
22121b0c.171c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\user32.dll' [rcNtRedir=0xc0150008]
22131b0c.171c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
22141b0c.171c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
22151b0c.171c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
22161b0c.171c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
22171b0c.171c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.amd64/VBoxVRDP.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000004f3a540:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
22181b0c.171c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxVRDP.dll
22191b0c.171c: supR3HardenedDllNotificationCallback: load 000007fee3390000 LB 0x0017a000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxVRDP.DLL [fFlags=0x0]
22201b0c.171c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxVRDP.dll
22211b0c.171c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee3390000 'C:\Program Files\Oracle\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.amd64/VBoxVRDP.DLL'
22221b0c.1ab8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000bcc pwszName=\Device\HarddiskVolume2\WINDOWS\System32\mswsock.dll
22231b0c.1ab8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
22241b0c.1ab8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
22251b0c.1ab8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=C8E5754748E0E000AB425BF2AEB177780FB43945
22261b0c.1ab8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB2888049~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\WINDOWS\System32\mswsock.dll'
22271b0c.1ab8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
22281b0c.1ab8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
22291b0c.1ab8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
22301b0c.1ab8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rpcrt4.dll'.
22311b0c.1ab8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ws2_32.dll'.
22321b0c.1ab8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\mswsock.dll)WinVerifyTrust
22331b0c.1ab8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\mswsock.dll
22341b0c.1ab8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
22351b0c.1ab8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
22361b0c.1ab8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
22371b0c.1ab8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
22381b0c.1ab8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
22391b0c.1ab8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\user32.dll' [rcNtRedir=0xc0150008]
22401b0c.1ab8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
22411b0c.1ab8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
22421b0c.1ab8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\mswsock.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000004f3a540:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
22431b0c.1ab8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\mswsock.dll
22441b0c.1ab8: supR3HardenedDllNotificationCallback: load 000007fefd1f0000 LB 0x00055000 C:\Windows\system32\mswsock.dll [fFlags=0x0]
22451b0c.1ab8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\mswsock.dll
22461b0c.1ab8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd1f0000 'C:\Windows\system32\mswsock.dll'
22471b0c.1ab8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000bf8 pwszName=\Device\HarddiskVolume2\WINDOWS\System32\wship6.dll
22481b0c.1ab8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
22491b0c.1ab8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
22501b0c.1ab8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=68F2FDFC5151940B71C922BC59B7767F02726F85
22511b0c.1ab8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\WINDOWS\System32\wship6.dll'
22521b0c.1ab8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
22531b0c.1ab8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'ws2_32.dll'.
22541b0c.1ab8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\wship6.dll)WinVerifyTrust
22551b0c.1ab8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\wship6.dll
22561b0c.1ab8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
22571b0c.1ab8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
22581b0c.1ab8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\wship6.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000004f3a540:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
22591b0c.1ab8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\wship6.dll
22601b0c.1ab8: supR3HardenedDllNotificationCallback: load 000007fefd360000 LB 0x00007000 C:\Windows\System32\wship6.dll [fFlags=0x0]
22611b0c.1ab8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\wship6.dll
22621b0c.1ab8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd360000 'C:\Windows\System32\wship6.dll'
22631b0c.1ab8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\mswsock.dll
22641b0c.1ab8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\mswsock.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000004f3a540:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
22651b0c.1ab8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd1f0000 'C:\Windows\system32\mswsock.dll'
22661b0c.1ab8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000be8 pwszName=\Device\HarddiskVolume2\WINDOWS\System32\WSHTCPIP.DLL
22671b0c.1ab8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
22681b0c.1ab8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
22691b0c.1ab8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=1EFFE58BB9FD8A94FD1609B7F82A43C8E09D98AA
22701b0c.1ab8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\WINDOWS\System32\WSHTCPIP.DLL'
22711b0c.1ab8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
22721b0c.1ab8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'ws2_32.dll'.
22731b0c.1ab8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\WSHTCPIP.DLL)WinVerifyTrust
22741b0c.1ab8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\WSHTCPIP.DLL
22751b0c.1ab8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
22761b0c.1ab8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
22771b0c.1ab8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\wshtcpip.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000004f3a540:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
22781b0c.1ab8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\WSHTCPIP.DLL
22791b0c.1ab8: supR3HardenedDllNotificationCallback: load 000007fefcbe0000 LB 0x00007000 C:\Windows\System32\wshtcpip.dll [fFlags=0x0]
22801b0c.1ab8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\WSHTCPIP.DLL
22811b0c.1ab8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcbe0000 'C:\Windows\System32\wshtcpip.dll'
22821b0c.171c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
22831b0c.171c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrem.dll'.
22841b0c.171c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
22851b0c.171c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll)WinVerifyTrust
22861b0c.171c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
22871b0c.171c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
22881b0c.171c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
22891b0c.171c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrem.dll'...
22901b0c.171c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrem.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrem.dll' [rcNtRedir=0xc0150008]
22911b0c.171c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'vboxrt.dll'.
22921b0c.171c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
22931b0c.171c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcrt.dll'.
22941b0c.171c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxREM.dll)WinVerifyTrust
22951b0c.171c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxREM.dll
22961b0c.171c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
22971b0c.171c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
22981b0c.171c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
22991b0c.171c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
23001b0c.171c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
23011b0c.171c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
23021b0c.171c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
23031b0c.171c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
23041b0c.171c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
23051b0c.171c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000004f3a540:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
23061b0c.171c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
23071b0c.171c: supR3HardenedDllNotificationCallback: load 000007fee30f0000 LB 0x00291000 C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL [fFlags=0x0]
23081b0c.171c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
23091b0c.171c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxREM.dll
23101b0c.171c: supR3HardenedDllNotificationCallback: load 000000005c170000 LB 0x0010a000 C:\Program Files\Oracle\VirtualBox\VBoxREM.dll [fFlags=0x0]
23111b0c.171c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxREM.dll
23121b0c.171c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee30f0000 'C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL'
23131b0c.15b8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
23141b0c.15b8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'ndis.sys'.
23151b0c.15b8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'netio.sys'.
23161b0c.15b8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\drivers\VBoxNetLwf.sys)
23171b0c.15b8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\drivers\VBoxNetLwf.sys
23181b0c.15b8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\drivers\VBoxNetLwf.sys [avoiding WinVerifyTrust]
23191b0c.15b8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
23201b0c.15b8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\drivers\VBoxUSBMon.sys)
23211b0c.15b8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\drivers\VBoxUSBMon.sys
23221b0c.15b8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\drivers\VBoxUSBMon.sys [avoiding WinVerifyTrust]
23231b0c.15b8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
23241b0c.15b8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\drivers\VBoxDrv.sys)
23251b0c.15b8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\drivers\VBoxDrv.sys
23261b0c.15b8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\drivers\VBoxDrv.sys [avoiding WinVerifyTrust]
23271b0c.15b8: \Device\HarddiskVolume2\WINDOWS\System32\drivers\VBoxNetAdp.sys: Owner is administrators group.
23281b0c.15b8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
23291b0c.15b8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'ndis.sys'.
23301b0c.15b8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\drivers\VBoxNetAdp.sys)
23311b0c.15b8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\drivers\VBoxNetAdp.sys
23321b0c.15b8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\drivers\VBoxNetAdp.sys [avoiding WinVerifyTrust]
23331b0c.15b8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
23341b0c.15b8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'ndis.sys'.
23351b0c.15b8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\drivers\VBoxNetFlt.sys)
23361b0c.15b8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\drivers\VBoxNetFlt.sys
23371b0c.15b8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\drivers\VBoxNetFlt.sys [avoiding WinVerifyTrust]
23381b0c.79c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\WINDOWS\System32\drivers\VBoxNetFlt.sys'
23391b0c.79c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\WINDOWS\System32\drivers\VBoxNetAdp.sys'
23401b0c.79c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\WINDOWS\System32\drivers\VBoxDrv.sys'
23411b0c.79c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\WINDOWS\System32\drivers\VBoxUSBMon.sys'
23421b0c.79c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\WINDOWS\System32\drivers\VBoxNetLwf.sys'
23431b0c.79c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
23441b0c.79c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
23451b0c.79c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
23461b0c.79c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
23471b0c.79c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll)WinVerifyTrust
23481b0c.79c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll
23491b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
23501b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\user32.dll' [rcNtRedir=0xc0150008]
23511b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
23521b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
23531b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
23541b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
23551b0c.79c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
23561b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
23571b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
23581b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ndis.sys'...
23591b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ndis.sys' -> '\Device\HarddiskVolume2\WINDOWS\System32\drivers\ndis.sys' [rcNtRedir=0xc0150008]
23601b0c.79c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
23611b0c.79c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'hal.dll'.
23621b0c.79c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'netio.sys'.
23631b0c.79c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\drivers\ndis.sys)WinVerifyTrust
23641b0c.79c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\drivers\ndis.sys
23651b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
23661b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume2\WINDOWS\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
23671b0c.79c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'pshed.dll'.
23681b0c.79c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'hal.dll'.
23691b0c.79c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'kdcom.dll'.
23701b0c.79c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'clfs.sys'.
23711b0c.79c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ci.dll'.
23721b0c.79c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\ntoskrnl.exe)WinVerifyTrust
23731b0c.79c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\ntoskrnl.exe
23741b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ndis.sys'...
23751b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ndis.sys' -> '\Device\HarddiskVolume2\WINDOWS\System32\drivers\ndis.sys' [rcNtRedir=0xc0150008]
23761b0c.79c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\drivers\ndis.sys
23771b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
23781b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume2\WINDOWS\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
23791b0c.79c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\ntoskrnl.exe
23801b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
23811b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume2\WINDOWS\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
23821b0c.79c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\ntoskrnl.exe
23831b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
23841b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume2\WINDOWS\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
23851b0c.79c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\ntoskrnl.exe
23861b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'netio.sys'...
23871b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: 'netio.sys' -> '\Device\HarddiskVolume2\WINDOWS\System32\drivers\netio.sys' [rcNtRedir=0xc0150008]
23881b0c.79c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
23891b0c.79c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'ndis.sys'.
23901b0c.79c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msrpc.sys'.
23911b0c.79c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\drivers\netio.sys)WinVerifyTrust
23921b0c.79c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\drivers\netio.sys
23931b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ndis.sys'...
23941b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ndis.sys' -> '\Device\HarddiskVolume2\WINDOWS\System32\drivers\ndis.sys' [rcNtRedir=0xc0150008]
23951b0c.79c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\drivers\ndis.sys
23961b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
23971b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume2\WINDOWS\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
23981b0c.79c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\ntoskrnl.exe
23991b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msrpc.sys'...
24001b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msrpc.sys' -> '\Device\HarddiskVolume2\WINDOWS\System32\drivers\msrpc.sys' [rcNtRedir=0xc0150008]
24011b0c.79c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
24021b0c.79c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\drivers\msrpc.sys)WinVerifyTrust
24031b0c.79c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\drivers\msrpc.sys
24041b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ndis.sys'...
24051b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ndis.sys' -> '\Device\HarddiskVolume2\WINDOWS\System32\drivers\ndis.sys' [rcNtRedir=0xc0150008]
24061b0c.79c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\drivers\ndis.sys
24071b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
24081b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume2\WINDOWS\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
24091b0c.79c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\ntoskrnl.exe
24101b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ci.dll'...
24111b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ci.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\ci.dll' [rcNtRedir=0xc0150008]
24121b0c.79c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
24131b0c.79c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\ci.dll)WinVerifyTrust
24141b0c.79c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\ci.dll
24151b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'clfs.sys'...
24161b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: 'clfs.sys' -> '\Device\HarddiskVolume2\WINDOWS\System32\clfs.sys' [rcNtRedir=0xc0150008]
24171b0c.79c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
24181b0c.79c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\clfs.sys)WinVerifyTrust
24191b0c.79c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\clfs.sys
24201b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'kdcom.dll'...
24211b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: 'kdcom.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\kdcom.dll' [rcNtRedir=0xc0150008]
24221b0c.79c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
24231b0c.79c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'hal.dll'.
24241b0c.79c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\kdcom.dll)WinVerifyTrust
24251b0c.79c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\kdcom.dll
24261b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'hal.dll'...
24271b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: 'hal.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\hal.dll' [rcNtRedir=0xc0150008]
24281b0c.79c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
24291b0c.79c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'kdcom.dll'.
24301b0c.79c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'pshed.dll'.
24311b0c.79c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\hal.dll)WinVerifyTrust
24321b0c.79c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\hal.dll
24331b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'pshed.dll'...
24341b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: 'pshed.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\pshed.dll' [rcNtRedir=0xc0150008]
24351b0c.79c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
24361b0c.79c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'hal.dll'.
24371b0c.79c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\PSHED.DLL)WinVerifyTrust
24381b0c.79c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\PSHED.DLL
24391b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'netio.sys'...
24401b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: 'netio.sys' -> '\Device\HarddiskVolume2\WINDOWS\System32\drivers\netio.sys' [rcNtRedir=0xc0150008]
24411b0c.79c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\drivers\netio.sys
24421b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'hal.dll'...
24431b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: 'hal.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\hal.dll' [rcNtRedir=0xc0150008]
24441b0c.79c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\hal.dll
24451b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
24461b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume2\WINDOWS\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
24471b0c.79c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\ntoskrnl.exe
24481b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'hal.dll'...
24491b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: 'hal.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\hal.dll' [rcNtRedir=0xc0150008]
24501b0c.79c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\hal.dll
24511b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
24521b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume2\WINDOWS\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
24531b0c.79c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\ntoskrnl.exe
24541b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'pshed.dll'...
24551b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: 'pshed.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\pshed.dll' [rcNtRedir=0xc0150008]
24561b0c.79c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\PSHED.DLL
24571b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'kdcom.dll'...
24581b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: 'kdcom.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\kdcom.dll' [rcNtRedir=0xc0150008]
24591b0c.79c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\kdcom.dll
24601b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
24611b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume2\WINDOWS\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
24621b0c.79c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\ntoskrnl.exe
24631b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'hal.dll'...
24641b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: 'hal.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\hal.dll' [rcNtRedir=0xc0150008]
24651b0c.79c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\hal.dll
24661b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
24671b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume2\WINDOWS\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
24681b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
24691b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume2\WINDOWS\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
24701b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
24711b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume2\WINDOWS\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
24721b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
24731b0c.79c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume2\WINDOWS\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
24741b0c.79c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000004f3a540:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
24751b0c.79c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll
24761b0c.79c: supR3HardenedDllNotificationCallback: load 000007fee30e0000 LB 0x0000a000 C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL [fFlags=0x0]
24771b0c.79c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll
24781b0c.79c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee30e0000 'C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL'
24791b0c.198c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
24801b0c.198c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
24811b0c.198c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
24821b0c.198c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll)WinVerifyTrust
24831b0c.198c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll
24841b0c.198c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
24851b0c.198c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
24861b0c.198c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
24871b0c.198c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
24881b0c.198c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
24891b0c.198c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
24901b0c.198c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
24911b0c.198c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
24921b0c.198c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000004f3a540:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
24931b0c.198c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll
24941b0c.198c: supR3HardenedDllNotificationCallback: load 000007fee30d0000 LB 0x0000d000 C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL [fFlags=0x0]
24951b0c.198c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll
24961b0c.198c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee30d0000 'C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL'
24971b0c.15b8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxTestOGL.exe
24981b0c.234: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
24991b0c.234: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxoglhostcrutil.dll'.
25001b0c.234: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
25011b0c.234: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vboxvmm.dll'.
25021b0c.234: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'vboxoglrenderspu.dll'.
25031b0c.234: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'advapi32.dll'.
25041b0c.234: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'ole32.dll'.
25051b0c.234: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'oleaut32.dll'.
25061b0c.234: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedCrOpenGL.dll)WinVerifyTrust
25071b0c.234: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedCrOpenGL.dll
25081b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
25091b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
25101b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
25111b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\ole32.dll' [rcNtRedir=0xc0150008]
25121b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
25131b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\advapi32.dll' [rcNtRedir=0xc0150008]
25141b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxoglrenderspu.dll'...
25151b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxoglrenderspu.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxoglrenderspu.dll' [rcNtRedir=0xc0150008]
25161b0c.234: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
25171b0c.234: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxoglhostcrutil.dll'.
25181b0c.234: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
25191b0c.234: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
25201b0c.234: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
25211b0c.234: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'advapi32.dll'.
25221b0c.234: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLrenderspu.dll)WinVerifyTrust
25231b0c.234: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLrenderspu.dll
25241b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
25251b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
25261b0c.234: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
25271b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
25281b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
25291b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxoglhostcrutil.dll'...
25301b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxoglhostcrutil.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxoglhostcrutil.dll' [rcNtRedir=0xc0150008]
25311b0c.234: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLhostcrutil.dll
25321b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
25331b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
25341b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
25351b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\advapi32.dll' [rcNtRedir=0xc0150008]
25361b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
25371b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\gdi32.dll' [rcNtRedir=0xc0150008]
25381b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
25391b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\user32.dll' [rcNtRedir=0xc0150008]
25401b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
25411b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
25421b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxoglhostcrutil.dll'...
25431b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxoglhostcrutil.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxoglhostcrutil.dll' [rcNtRedir=0xc0150008]
25441b0c.234: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLhostcrutil.dll
25451b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
25461b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
25471b0c.234: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSharedCrOpenGL.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000004f3a540:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
25481b0c.234: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedCrOpenGL.dll
25491b0c.234: supR3HardenedDllNotificationCallback: load 000007fee2fa0000 LB 0x0012a000 C:\Program Files\Oracle\VirtualBox\VBoxSharedCrOpenGL.DLL [fFlags=0x0]
25501b0c.234: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedCrOpenGL.dll
25511b0c.234: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLhostcrutil.dll
25521b0c.234: supR3HardenedDllNotificationCallback: load 000007fee2f60000 LB 0x00034000 C:\Program Files\Oracle\VirtualBox\VBoxOGLhostcrutil.dll [fFlags=0x0]
25531b0c.234: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLhostcrutil.dll
25541b0c.234: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLrenderspu.dll
25551b0c.234: supR3HardenedDllNotificationCallback: load 000007fee2f30000 LB 0x00028000 C:\Program Files\Oracle\VirtualBox\VBoxOGLrenderspu.dll [fFlags=0x0]
25561b0c.234: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLrenderspu.dll
25571b0c.234: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee2fa0000 'C:\Program Files\Oracle\VirtualBox\VBoxSharedCrOpenGL.DLL'
25581b0c.234: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLrenderspu.dll
25591b0c.234: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxOGLrenderspu.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000004f3a540:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
25601b0c.234: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee2f30000 'C:\Program Files\Oracle\VirtualBox\VBoxOGLrenderspu.dll'
25611b0c.234: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
25621b0c.234: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxoglhostcrutil.dll'.
25631b0c.234: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLhosterrorspu.dll)WinVerifyTrust
25641b0c.234: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLhosterrorspu.dll
25651b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxoglhostcrutil.dll'...
25661b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxoglhostcrutil.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxoglhostcrutil.dll' [rcNtRedir=0xc0150008]
25671b0c.234: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLhostcrutil.dll
25681b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
25691b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
25701b0c.234: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxOGLhosterrorspu.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000004f3a540:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
25711b0c.234: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLhosterrorspu.dll
25721b0c.234: supR3HardenedDllNotificationCallback: load 000007fee2f10000 LB 0x0001a000 C:\Program Files\Oracle\VirtualBox\VBoxOGLhosterrorspu.dll [fFlags=0x0]
25731b0c.234: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLhosterrorspu.dll
25741b0c.234: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee2f10000 'C:\Program Files\Oracle\VirtualBox\VBoxOGLhosterrorspu.dll'
25751b0c.234: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\opengl32.dll
25761b0c.234: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32/opengl32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000004f3a540:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
25771b0c.234: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\opengl32.dll
25781b0c.234: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4200000 'C:\Windows\system32/opengl32.dll'
25791b0c.234: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\opengl32.dll
25801b0c.234: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\OPENGL32.dll (Input=OPENGL32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000004f3a540:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
25811b0c.234: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4200000 'C:\Windows\system32\OPENGL32.dll'
25821b0c.234: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe570000 'C:\Windows\system32\gdi32.dll'
25831b0c.234: \Device\HarddiskVolume2\WINDOWS\System32\atig6pxx.dll: Owner is administrators group.
25841b0c.234: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000d9c pwszName=\Device\HarddiskVolume2\WINDOWS\System32\atig6pxx.dll
25851b0c.234: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
25861b0c.234: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
25871b0c.234: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=EDDAB983C6492C056E49224E82BE37B02859812E
25881b0c.234: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem24.CAT'; file='\Device\HarddiskVolume2\WINDOWS\System32\atig6pxx.dll'
25891b0c.234: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
25901b0c.234: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
25911b0c.234: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
25921b0c.234: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcrt.dll'.
25931b0c.234: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
25941b0c.234: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\atig6pxx.dll)WinVerifyTrust
25951b0c.234: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\atig6pxx.dll
25961b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
25971b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\advapi32.dll' [rcNtRedir=0xc0150008]
25981b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
25991b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
26001b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
26011b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\gdi32.dll' [rcNtRedir=0xc0150008]
26021b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
26031b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\user32.dll' [rcNtRedir=0xc0150008]
26041b0c.234: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\atig6pxx.dll (Input=atig6pxx.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000004f3a540:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
26051b0c.234: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\atig6pxx.dll
26061b0c.234: supR3HardenedDllNotificationCallback: load 000007fee2f00000 LB 0x00008000 C:\Windows\system32\atig6pxx.dll [fFlags=0x0]
26071b0c.234: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\atig6pxx.dll
26081b0c.234: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee2f00000 'C:\Windows\system32\atig6pxx.dll'
26091b0c.234: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe570000 'C:\Windows\system32\gdi32.dll'
26101b0c.234: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe570000 'C:\Windows\system32\gdi32.dll'
26111b0c.234: \Device\HarddiskVolume2\WINDOWS\System32\atio6axx.dll: Owner is administrators group.
26121b0c.234: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000dbc pwszName=\Device\HarddiskVolume2\WINDOWS\System32\atio6axx.dll
26131b0c.234: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
26141b0c.234: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
26151b0c.234: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=1D0FFD5A6F249115FEE64CEF5ACBBA5D720B737C
26161b0c.234: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem24.CAT'; file='\Device\HarddiskVolume2\WINDOWS\System32\atio6axx.dll'
26171b0c.234: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
26181b0c.234: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
26191b0c.234: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
26201b0c.234: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'version.dll'.
26211b0c.234: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
26221b0c.234: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\atio6axx.dll)WinVerifyTrust
26231b0c.234: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\atio6axx.dll
26241b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
26251b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\advapi32.dll' [rcNtRedir=0xc0150008]
26261b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'version.dll'...
26271b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: 'version.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\version.dll' [rcNtRedir=0xc0150008]
26281b0c.234: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\version.dll
26291b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
26301b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\gdi32.dll' [rcNtRedir=0xc0150008]
26311b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
26321b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\user32.dll' [rcNtRedir=0xc0150008]
26331b0c.234: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\atio6axx.dll (Input=atio6axx.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000004f3a540:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
26341b0c.234: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\atio6axx.dll
26351b0c.234: supR3HardenedDllNotificationCallback: load 0000000069030000 LB 0x010ff000 C:\Windows\system32\atio6axx.dll [fFlags=0x0]
26361b0c.234: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\atio6axx.dll
26371b0c.234: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\dwmapi.dll
26381b0c.234: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\dwmapi.dll (Input=dwmapi.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000004f3ac00:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
26391b0c.234: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbb10000 'C:\Windows\system32\dwmapi.dll'
26401b0c.234: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000069030000 'C:\Windows\system32\atio6axx.dll'
26411b0c.234: \Device\HarddiskVolume2\WINDOWS\System32\atig6txx.dll: Owner is administrators group.
26421b0c.234: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000dcc pwszName=\Device\HarddiskVolume2\WINDOWS\System32\atig6txx.dll
26431b0c.234: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
26441b0c.234: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
26451b0c.234: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=15972F598A1F9447712528265645E2FE28261A9A
26461b0c.234: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem24.CAT'; file='\Device\HarddiskVolume2\WINDOWS\System32\atig6txx.dll'
26471b0c.234: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
26481b0c.234: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
26491b0c.234: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
26501b0c.234: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcrt.dll'.
26511b0c.234: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\atig6txx.dll)WinVerifyTrust
26521b0c.234: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\atig6txx.dll
26531b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
26541b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
26551b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
26561b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\gdi32.dll' [rcNtRedir=0xc0150008]
26571b0c.234: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\gdi32.dll
26581b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
26591b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\user32.dll' [rcNtRedir=0xc0150008]
26601b0c.234: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\atig6txx.dll (Input=atig6txx.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000004f3a540:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
26611b0c.234: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\atig6txx.dll
26621b0c.234: supR3HardenedDllNotificationCallback: load 000007fee2ef0000 LB 0x00009000 C:\Windows\system32\atig6txx.dll [fFlags=0x0]
26631b0c.234: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\atig6txx.dll
26641b0c.234: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee2ef0000 'C:\Windows\system32\atig6txx.dll'
26651b0c.234: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe570000 'C:\Windows\system32\gdi32.dll'
26661b0c.234: \Device\HarddiskVolume2\WINDOWS\System32\atiadlxx.dll: Owner is administrators group.
26671b0c.234: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000d90 pwszName=\Device\HarddiskVolume2\WINDOWS\System32\atiadlxx.dll
26681b0c.234: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000860f20
26691b0c.234: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000860f20
26701b0c.234: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=405FF55B61979B33C23AABF37A66FF4CF666CEF2
26711b0c.234: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem24.CAT'; file='\Device\HarddiskVolume2\WINDOWS\System32\atiadlxx.dll'
26721b0c.234: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
26731b0c.234: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
26741b0c.234: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
26751b0c.234: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
26761b0c.234: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'setupapi.dll'.
26771b0c.234: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcrt.dll'.
26781b0c.234: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\atiadlxx.dll)WinVerifyTrust
26791b0c.234: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\atiadlxx.dll
26801b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
26811b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
26821b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
26831b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\setupapi.dll' [rcNtRedir=0xc0150008]
26841b0c.234: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\setupapi.dll
26851b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
26861b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\advapi32.dll' [rcNtRedir=0xc0150008]
26871b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
26881b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\gdi32.dll' [rcNtRedir=0xc0150008]
26891b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
26901b0c.234: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\user32.dll' [rcNtRedir=0xc0150008]
26911b0c.234: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\atiadlxx.dll (Input=atiadlxx.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000004f3a540:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
26921b0c.234: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\atiadlxx.dll
26931b0c.234: supR3HardenedDllNotificationCallback: load 0000000180000000 LB 0x00052000 C:\Windows\system32\atiadlxx.dll [fFlags=0x0]
26941b0c.234: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\atiadlxx.dll
26951b0c.234: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000180000000 'C:\Windows\system32\atiadlxx.dll'
26961b0c.234: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe570000 'C:\Windows\system32\gdi32.dll'
26971b0c.234: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077a50000 'C:\Windows\system32\USER32.DLL'
26981b0c.234: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077a50000 'C:\Windows\system32\USER32.DLL'
26991b0c.234: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe570000 'C:\Windows\system32\gdi32.dll'
27001b0c.234: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe570000 'C:\Windows\system32\gdi32.dll'
27011b0c.234: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe570000 'C:\Windows\system32\gdi32.dll'
27021b0c.234: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077a50000 'C:\Windows\system32\USER32.DLL'
27031b0c.234: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077a50000 'C:\Windows\system32\USER32.DLL'
27041b0c.234: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077a50000 'C:\Windows\system32\USER32.DLL'
27051b0c.234: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077a50000 'C:\Windows\system32\USER32.DLL'
27061b0c.234: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077a50000 'C:\Windows\system32\USER32.DLL'
27071b0c.234: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077a50000 'C:\Windows\system32\USER32.DLL'
27081b0c.234: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077a50000 'C:\Windows\system32\USER32.DLL'
27091b0c.234: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077a50000 'C:\Windows\system32\USER32.DLL'
27101b0c.234: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077a50000 'C:\Windows\system32\USER32.DLL'
27111b0c.234: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077a50000 'C:\Windows\system32\USER32.DLL'
27121b0c.234: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\wintrust.dll
27131b0c.234: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\WINTRUST.dll (Input=WINTRUST.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000004f3a540:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
27141b0c.234: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdb30000 'C:\Windows\system32\WINTRUST.dll'
27151b0c.234: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077a50000 'C:\Windows\system32\USER32.DLL'
27161b0c.234: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077a50000 'C:\Windows\system32\USER32.DLL'
27171b0c.234: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077a50000 'C:\Windows\system32\USER32.DLL'
27181b0c.234: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077a50000 'C:\Windows\system32\USER32.DLL'
27191b0c.234: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe570000 'C:\Windows\system32\gdi32.dll'
27201b0c.234: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe570000 'C:\Windows\system32\gdi32.dll'
27211b0c.234: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe570000 'C:\Windows\system32\gdi32.dll'
27221b0c.234: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4200000 'C:\Windows\system32\OPENGL32.DLL'
27231b0c.234: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4200000 'C:\Windows\system32\OPENGL32.dll'
27241b0c.234: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4200000 'C:\Windows\system32\OPENGL32.dll'
27251b0c.234: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4200000 'C:\Windows\system32\OPENGL32.dll'
27261b0c.234: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4200000 'C:\Windows\system32\OPENGL32.dll'
27271b0c.234: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4200000 'C:\Windows\system32\OPENGL32.dll'
27281b0c.234: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4200000 'C:\Windows\system32\OPENGL32.dll'
27291b0c.f98: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feffb70000 'C:\Windows\system32\OLEAUT32.dll'
27301948.d38: supR3HardNtChildWaitFor[2]: Quitting: ExitCode=0xc0000005 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 429331 ms, the end);
27311ab0.c84: supR3HardNtChildWaitFor[1]: Quitting: ExitCode=0xc0000005 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 429705 ms, the end);

© 2024 Oracle Support Privacy / Do Not Sell My Info Terms of Use Trademark Policy Automated Access Etiquette