VirtualBox

Ticket #14130: VBoxStartup.log

File VBoxStartup.log, 265.0 KB (added by c3p0i, 9 years ago)
Line 
1a80.1634: Log file opened: 4.3.28r100309 g_hStartupLog=000000fc g_uNtVerCombined=0x611db110
2a80.1634: \SystemRoot\System32\ntdll.dll:
3a80.1634: CreationTime: 2015-05-13T01:43:23.150528200Z
4a80.1634: LastWriteTime: 2015-04-27T19:08:02.560861300Z
5a80.1634: ChangeTime: 2015-05-13T06:05:12.472030600Z
6a80.1634: FileAttributes: 0x20
7a80.1634: Size: 0x13f400
8a80.1634: NT Headers: 0xd0
9a80.1634: Timestamp: 0x553e8801
10a80.1634: Machine: 0x14c - i386
11a80.1634: Timestamp: 0x553e8801
12a80.1634: Image Version: 6.1
13a80.1634: SizeOfImage: 0x141000 (1314816)
14a80.1634: Resource Dir: 0xe1000 LB 0x5a028
15a80.1634: ProductName: Microsoft® Windows® Operating System
16a80.1634: ProductVersion: 6.1.7601.18839
17a80.1634: FileVersion: 6.1.7601.18839 (win7sp1_gdr.150427-0707)
18a80.1634: FileDescription: NT Layer DLL
19a80.1634: \SystemRoot\System32\kernel32.dll:
20a80.1634: CreationTime: 2014-04-17T06:50:28.609395400Z
21a80.1634: LastWriteTime: 2014-03-04T09:17:13.817000000Z
22a80.1634: ChangeTime: 2014-04-22T06:36:30.681081700Z
23a80.1634: FileAttributes: 0x20
24a80.1634: Size: 0xd4000
25a80.1634: NT Headers: 0xf0
26a80.1634: Timestamp: 0x531599f5
27a80.1634: Machine: 0x14c - i386
28a80.1634: Timestamp: 0x531599f5
29a80.1634: Image Version: 6.1
30a80.1634: SizeOfImage: 0xd4000 (868352)
31a80.1634: Resource Dir: 0xc7000 LB 0x528
32a80.1634: ProductName: Microsoft® Windows® Operating System
33a80.1634: ProductVersion: 6.1.7601.18409
34a80.1634: FileVersion: 6.1.7601.18409 (win7sp1_gdr.140303-2144)
35a80.1634: FileDescription: Windows NT BASE API Client DLL
36a80.1634: \SystemRoot\System32\KernelBase.dll:
37a80.1634: CreationTime: 2014-05-14T10:04:05.890013400Z
38a80.1634: LastWriteTime: 2014-03-04T09:17:13.817000000Z
39a80.1634: ChangeTime: 2014-05-14T15:06:48.300616400Z
40a80.1634: FileAttributes: 0x20
41a80.1634: Size: 0x47a00
42a80.1634: NT Headers: 0xe0
43a80.1634: Timestamp: 0x531599f6
44a80.1634: Machine: 0x14c - i386
45a80.1634: Timestamp: 0x531599f6
46a80.1634: Image Version: 6.1
47a80.1634: SizeOfImage: 0x4b000 (307200)
48a80.1634: Resource Dir: 0x47000 LB 0x530
49a80.1634: ProductName: Microsoft® Windows® Operating System
50a80.1634: ProductVersion: 6.1.7601.18409
51a80.1634: FileVersion: 6.1.7601.18409 (win7sp1_gdr.140303-2144)
52a80.1634: FileDescription: Windows NT BASE API Client DLL
53a80.1634: \SystemRoot\System32\apisetschema.dll:
54a80.1634: CreationTime: 2015-05-13T01:43:21.798450900Z
55a80.1634: LastWriteTime: 2015-04-27T18:59:41.743000000Z
56a80.1634: ChangeTime: 2015-05-13T06:05:12.222430200Z
57a80.1634: FileAttributes: 0x20
58a80.1634: Size: 0x1a00
59a80.1634: NT Headers: 0xc0
60a80.1634: Timestamp: 0x553e8756
61a80.1634: Machine: 0x14c - i386
62a80.1634: Timestamp: 0x553e8756
63a80.1634: Image Version: 6.1
64a80.1634: SizeOfImage: 0x50000 (327680)
65a80.1634: Resource Dir: 0x30000 LB 0x3f8
66a80.1634: ProductName: Microsoft® Windows® Operating System
67a80.1634: ProductVersion: 6.1.7601.18839
68a80.1634: FileVersion: 6.1.7601.18839 (win7sp1_gdr.150427-0707)
69a80.1634: FileDescription: ApiSet Schema DLL
70a80.1634: supR3HardenedWinFindAdversaries: 0x0
71a80.1634: Calling main()
72a80.1634: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
73a80.1634: SUPR3HardenedMain: Respawn #1
74a80.1634: System32: \Device\HarddiskVolume2\Windows\System32
75a80.1634: WinSxS: \Device\HarddiskVolume2\Windows\winsxs
76a80.1634: KnownDllPath: C:\Windows\system32
77a80.1634: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
78a80.1634: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe)
79a80.1634: supR3HardNtEnableThreadCreation:
80a80.1634: supR3HardNtDisableThreadCreation: pvLdrInitThunk=77223861 pvNtTerminateThread=77206930
81a80.1634: supR3HardenedWinDoReSpawn(1): New child 3c4.d74 [kernel32].
82a80.1634: supR3HardNtChildGatherData: PebBaseAddress=7ffd8000 cbPeb=0x248
83a80.1634: supR3HardNtPuChFindNtdll: uNtDllParentAddr=771c0000 uNtDllChildAddr=771c0000
84a80.1634: supR3HardenedWinSetupChildInit: uLdrInitThunk=77223861
85a80.1634: supR3HardenedWinSetupChildInit: Start child.
86a80.1634: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
87a80.1634: supR3HardNtChildPurify: Startup delay kludge #1/0: 264 ms, 0 sleeps
88a80.1634: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
89a80.1634: *00000000-fffeffff 0x0001/0x0000 0x0000000
90a80.1634: *00010000-fffeffff 0x0004/0x0004 0x0020000
91a80.1634: *00030000-0002bfff 0x0002/0x0002 0x0040000
92a80.1634: 00034000-00027fff 0x0001/0x0000 0x0000000
93a80.1634: *00040000-0003efff 0x0004/0x0004 0x0020000
94a80.1634: 00041000-00031fff 0x0001/0x0000 0x0000000
95a80.1634: *00050000-0004efff 0x0004/0x0004 0x0020000
96a80.1634: 00051000-ffff1fff 0x0001/0x0000 0x0000000
97a80.1634: *000b0000-fffb2fff 0x0000/0x0004 0x0020000
98a80.1634: 001ad000-001aafff 0x0104/0x0004 0x0020000
99a80.1634: 001af000-001adfff 0x0004/0x0004 0x0020000
100a80.1634: 001b0000-ff97ffff 0x0001/0x0000 0x0000000
101a80.1634: *009e0000-009e0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
102a80.1634: 009e1000-00a55fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
103a80.1634: 00a56000-00a56fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
104a80.1634: 00a57000-00a84fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
105a80.1634: 00a85000-00a85fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
106a80.1634: 00a86000-00a86fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
107a80.1634: 00a87000-00a87fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
108a80.1634: 00a88000-00a88fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
109a80.1634: 00a89000-00a8afff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
110a80.1634: 00a8b000-00a8dfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
111a80.1634: 00a8e000-00ac0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
112a80.1634: 00ac1000-8a3c1fff 0x0001/0x0000 0x0000000
113a80.1634: *771c0000-771c0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
114a80.1634: 771c1000-77297fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
115a80.1634: 77298000-7729dfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
116a80.1634: 7729e000-7729efff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
117a80.1634: 7729f000-772a0fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
118a80.1634: 772a1000-77300fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
119a80.1634: 77301000-771e1fff 0x0001/0x0000 0x0000000
120a80.1634: *77420000-77420fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\apisetschema.dll
121a80.1634: 77421000-6e891fff 0x0001/0x0000 0x0000000
122a80.1634: *7ffb0000-7ff8cfff 0x0002/0x0002 0x0040000
123a80.1634: 7ffd3000-7ffcdfff 0x0001/0x0000 0x0000000
124a80.1634: *7ffd8000-7ffd6fff 0x0004/0x0004 0x0020000
125a80.1634: 7ffd9000-7ffd2fff 0x0001/0x0000 0x0000000
126a80.1634: *7ffdf000-7ffddfff 0x0004/0x0004 0x0020000
127a80.1634: *7ffe0000-7ffdefff 0x0002/0x0002 0x0020000
128a80.1634: 7ffe1000-7ffd1fff 0x0001/0x0002 0x0020000
129a80.1634: apisetschema.dll: timestamp 0x553e8756 (rc=VINF_SUCCESS)
130a80.1634: VirtualBox.exe: timestamp 0x55536e4b (rc=VINF_SUCCESS)
131a80.1634: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
132a80.1634: '\Device\HarddiskVolume2\Windows\System32\apisetschema.dll' has no imports
133a80.1634: '\Device\HarddiskVolume2\Windows\System32\ntdll.dll' has no imports
134a80.1634: supR3HardNtChildPurify: Done after 314 ms and 0 fixes (loop #0).
135a80.1634: supR3HardNtEnableThreadCreation:
1363c4.d74: Log file opened: 4.3.28r100309 g_hStartupLog=00000004 g_uNtVerCombined=0x611db110
1373c4.d74: supR3HardenedVmProcessInit: uNtDllAddr=771c0000
1383c4.d74: ntdll.dll: timestamp 0x553e8801 (rc=VINF_SUCCESS)
1393c4.d74: New simple heap: #1 002b0000 LB 0x400000 (for 1314816 allocation)
1403c4.d74: System32: \Device\HarddiskVolume2\Windows\System32
1413c4.d74: WinSxS: \Device\HarddiskVolume2\Windows\winsxs
1423c4.d74: KnownDllPath: C:\Windows\system32
1433c4.d74: supR3HardenedVmProcessInit: Opening vboxdrv stub...
1443c4.d74: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
1453c4.d74: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
1463c4.d74: Registered Dll notification callback with NTDLL.
1473c4.d74: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\kernel32.dll)
1483c4.d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\kernel32.dll
1493c4.d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=00000000:<flags> [calling]
1503c4.d74: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
1513c4.d74: supR3HardenedDllNotificationCallback: load 76670000 LB 0x000d4000 C:\Windows\system32\kernel32.dll [fFlags=0x0]
1523c4.d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
1533c4.d74: supR3HardenedDllNotificationCallback: load 75400000 LB 0x0004b000 C:\Windows\system32\KERNELBASE.dll [fFlags=0x0]
1543c4.d74: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\KernelBase.dll)
1553c4.d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\KernelBase.dll
1563c4.d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=76670000 'C:\Windows\system32\kernel32.dll'
1573c4.d74: supR3HardNtDisableThreadCreation: pvLdrInitThunk=77223861 pvNtTerminateThread=77206930
158a80.1634: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 47 ms.
1593c4.d74: \SystemRoot\System32\ntdll.dll:
1603c4.d74: CreationTime: 2015-05-13T01:43:23.150528200Z
1613c4.d74: LastWriteTime: 2015-04-27T19:08:02.560861300Z
1623c4.d74: ChangeTime: 2015-05-13T06:05:12.472030600Z
1633c4.d74: FileAttributes: 0x20
1643c4.d74: Size: 0x13f400
1653c4.d74: NT Headers: 0xd0
1663c4.d74: Timestamp: 0x553e8801
1673c4.d74: Machine: 0x14c - i386
1683c4.d74: Timestamp: 0x553e8801
1693c4.d74: Image Version: 6.1
1703c4.d74: SizeOfImage: 0x141000 (1314816)
1713c4.d74: Resource Dir: 0xe1000 LB 0x5a028
1723c4.d74: ProductName: Microsoft® Windows® Operating System
1733c4.d74: ProductVersion: 6.1.7601.18839
1743c4.d74: FileVersion: 6.1.7601.18839 (win7sp1_gdr.150427-0707)
1753c4.d74: FileDescription: NT Layer DLL
1763c4.d74: \SystemRoot\System32\kernel32.dll:
1773c4.d74: CreationTime: 2014-04-17T06:50:28.609395400Z
1783c4.d74: LastWriteTime: 2014-03-04T09:17:13.817000000Z
1793c4.d74: ChangeTime: 2014-04-22T06:36:30.681081700Z
1803c4.d74: FileAttributes: 0x20
1813c4.d74: Size: 0xd4000
1823c4.d74: NT Headers: 0xf0
1833c4.d74: Timestamp: 0x531599f5
1843c4.d74: Machine: 0x14c - i386
1853c4.d74: Timestamp: 0x531599f5
1863c4.d74: Image Version: 6.1
1873c4.d74: SizeOfImage: 0xd4000 (868352)
1883c4.d74: Resource Dir: 0xc7000 LB 0x528
1893c4.d74: ProductName: Microsoft® Windows® Operating System
1903c4.d74: ProductVersion: 6.1.7601.18409
1913c4.d74: FileVersion: 6.1.7601.18409 (win7sp1_gdr.140303-2144)
1923c4.d74: FileDescription: Windows NT BASE API Client DLL
1933c4.d74: \SystemRoot\System32\KernelBase.dll:
1943c4.d74: CreationTime: 2014-05-14T10:04:05.890013400Z
1953c4.d74: LastWriteTime: 2014-03-04T09:17:13.817000000Z
1963c4.d74: ChangeTime: 2014-05-14T15:06:48.300616400Z
1973c4.d74: FileAttributes: 0x20
1983c4.d74: Size: 0x47a00
1993c4.d74: NT Headers: 0xe0
2003c4.d74: Timestamp: 0x531599f6
2013c4.d74: Machine: 0x14c - i386
2023c4.d74: Timestamp: 0x531599f6
2033c4.d74: Image Version: 6.1
2043c4.d74: SizeOfImage: 0x4b000 (307200)
2053c4.d74: Resource Dir: 0x47000 LB 0x530
2063c4.d74: ProductName: Microsoft® Windows® Operating System
2073c4.d74: ProductVersion: 6.1.7601.18409
2083c4.d74: FileVersion: 6.1.7601.18409 (win7sp1_gdr.140303-2144)
2093c4.d74: FileDescription: Windows NT BASE API Client DLL
2103c4.d74: \SystemRoot\System32\apisetschema.dll:
2113c4.d74: CreationTime: 2015-05-13T01:43:21.798450900Z
2123c4.d74: LastWriteTime: 2015-04-27T18:59:41.743000000Z
2133c4.d74: ChangeTime: 2015-05-13T06:05:12.222430200Z
2143c4.d74: FileAttributes: 0x20
2153c4.d74: Size: 0x1a00
2163c4.d74: NT Headers: 0xc0
2173c4.d74: Timestamp: 0x553e8756
2183c4.d74: Machine: 0x14c - i386
2193c4.d74: Timestamp: 0x553e8756
2203c4.d74: Image Version: 6.1
2213c4.d74: SizeOfImage: 0x50000 (327680)
2223c4.d74: Resource Dir: 0x30000 LB 0x3f8
2233c4.d74: ProductName: Microsoft® Windows® Operating System
2243c4.d74: ProductVersion: 6.1.7601.18839
2253c4.d74: FileVersion: 6.1.7601.18839 (win7sp1_gdr.150427-0707)
2263c4.d74: FileDescription: ApiSet Schema DLL
2273c4.d74: supR3HardenedWinFindAdversaries: 0x0
2283c4.d74: Calling main()
2293c4.d74: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
2303c4.d74: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
2313c4.d74: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe)
2323c4.d74: SUPR3HardenedMain: Respawn #2
2333c4.d74: supR3HardNtEnableThreadCreation:
2343c4.d74: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\apphelp.dll)
2353c4.d74: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\apphelp.dll
2363c4.d74: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\apphelp.dll (rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=00000000:<flags> [calling]
2373c4.d74: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\apphelp.dll [lacks WinVerifyTrust]
2383c4.d74: supR3HardenedDllNotificationCallback: load 75080000 LB 0x0004c000 C:\Windows\system32\apphelp.dll [fFlags=0x0]
2393c4.d74: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\apphelp.dll [lacks WinVerifyTrust]
2403c4.d74: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=75080000 'C:\Windows\system32\apphelp.dll'
2413c4.d74: supR3HardNtDisableThreadCreation: pvLdrInitThunk=77223861 pvNtTerminateThread=77206930
2423c4.d74: supR3HardenedWinDoReSpawn(2): New child 1620.10b0 [kernel32].
2433c4.d74: supR3HardNtChildGatherData: PebBaseAddress=7ffdb000 cbPeb=0x248
2443c4.d74: supR3HardNtPuChFindNtdll: uNtDllParentAddr=771c0000 uNtDllChildAddr=771c0000
2453c4.d74: supR3HardenedWinSetupChildInit: uLdrInitThunk=77223861
2463c4.d74: supR3HardenedWinSetupChildInit: Start child.
2473c4.d74: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
2483c4.d74: supR3HardNtChildPurify: Startup delay kludge #1/0: 264 ms, 0 sleeps
2493c4.d74: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
2503c4.d74: *00000000-fffeffff 0x0001/0x0000 0x0000000
2513c4.d74: *00010000-fffeffff 0x0004/0x0004 0x0020000
2523c4.d74: *00030000-0002bfff 0x0002/0x0002 0x0040000
2533c4.d74: 00034000-00027fff 0x0001/0x0000 0x0000000
2543c4.d74: *00040000-0003efff 0x0004/0x0004 0x0020000
2553c4.d74: 00041000-00031fff 0x0001/0x0000 0x0000000
2563c4.d74: *00050000-0004efff 0x0004/0x0004 0x0020000
2573c4.d74: 00051000-00021fff 0x0001/0x0000 0x0000000
2583c4.d74: *00080000-fff82fff 0x0000/0x0004 0x0020000
2593c4.d74: 0017d000-0017afff 0x0104/0x0004 0x0020000
2603c4.d74: 0017f000-0017dfff 0x0004/0x0004 0x0020000
2613c4.d74: 00180000-ff91ffff 0x0001/0x0000 0x0000000
2623c4.d74: *009e0000-009e0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
2633c4.d74: 009e1000-00a55fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
2643c4.d74: 00a56000-00a56fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
2653c4.d74: 00a57000-00a84fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
2663c4.d74: 00a85000-00a85fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
2673c4.d74: 00a86000-00a86fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
2683c4.d74: 00a87000-00a87fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
2693c4.d74: 00a88000-00a88fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
2703c4.d74: 00a89000-00a8afff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
2713c4.d74: 00a8b000-00a8dfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
2723c4.d74: 00a8e000-00ac0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
2733c4.d74: 00ac1000-8a3c1fff 0x0001/0x0000 0x0000000
2743c4.d74: *771c0000-771c0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
2753c4.d74: 771c1000-77297fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
2763c4.d74: 77298000-7729dfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
2773c4.d74: 7729e000-7729efff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
2783c4.d74: 7729f000-772a0fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
2793c4.d74: 772a1000-77300fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
2803c4.d74: 77301000-771e1fff 0x0001/0x0000 0x0000000
2813c4.d74: *77420000-77420fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\apisetschema.dll
2823c4.d74: 77421000-6e891fff 0x0001/0x0000 0x0000000
2833c4.d74: *7ffb0000-7ff8cfff 0x0002/0x0002 0x0040000
2843c4.d74: 7ffd3000-7ffcafff 0x0001/0x0000 0x0000000
2853c4.d74: *7ffdb000-7ffd9fff 0x0004/0x0004 0x0020000
2863c4.d74: 7ffdc000-7ffd8fff 0x0001/0x0000 0x0000000
2873c4.d74: *7ffdf000-7ffddfff 0x0004/0x0004 0x0020000
2883c4.d74: *7ffe0000-7ffdefff 0x0002/0x0002 0x0020000
2893c4.d74: 7ffe1000-7ffd1fff 0x0001/0x0002 0x0020000
2903c4.d74: apisetschema.dll: timestamp 0x553e8756 (rc=VINF_SUCCESS)
2913c4.d74: VirtualBox.exe: timestamp 0x55536e4b (rc=VINF_SUCCESS)
2923c4.d74: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
2933c4.d74: '\Device\HarddiskVolume2\Windows\System32\apisetschema.dll' has no imports
2943c4.d74: '\Device\HarddiskVolume2\Windows\System32\ntdll.dll' has no imports
2953c4.d74: supR3HardNtChildPurify: Done after 317 ms and 0 fixes (loop #0).
2963c4.d74: supR3HardenedEarlyCompact: Removed heap 1 (0x2b0000 LB 0x400000)
2971620.10b0: Log file opened: 4.3.28r100309 g_hStartupLog=00000004 g_uNtVerCombined=0x611db110
2981620.10b0: supR3HardenedVmProcessInit: uNtDllAddr=771c0000
2993c4.d74: supR3HardNtEnableThreadCreation:
3001620.10b0: ntdll.dll: timestamp 0x553e8801 (rc=VINF_SUCCESS)
3011620.10b0: New simple heap: #1 00280000 LB 0x400000 (for 1314816 allocation)
3021620.10b0: System32: \Device\HarddiskVolume2\Windows\System32
3031620.10b0: WinSxS: \Device\HarddiskVolume2\Windows\winsxs
3041620.10b0: KnownDllPath: C:\Windows\system32
3051620.10b0: supR3HardenedVmProcessInit: Opening vboxdrv...
3061620.10b0: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
3071620.10b0: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
3081620.10b0: Registered Dll notification callback with NTDLL.
3091620.10b0: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\kernel32.dll)
3101620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\kernel32.dll
3111620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=00000000:<flags> [calling]
3121620.10b0: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
3131620.10b0: supR3HardenedDllNotificationCallback: load 76670000 LB 0x000d4000 C:\Windows\system32\kernel32.dll [fFlags=0x0]
3141620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
3151620.10b0: supR3HardenedDllNotificationCallback: load 75400000 LB 0x0004b000 C:\Windows\system32\KERNELBASE.dll [fFlags=0x0]
3161620.10b0: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\KernelBase.dll)
3171620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\KernelBase.dll
3181620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=76670000 'C:\Windows\system32\kernel32.dll'
3191620.10b0: supR3HardNtDisableThreadCreation: pvLdrInitThunk=77223861 pvNtTerminateThread=77206930
3203c4.d74: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 51 ms.
3211620.10b0: \SystemRoot\System32\ntdll.dll:
3221620.10b0: CreationTime: 2015-05-13T01:43:23.150528200Z
3231620.10b0: LastWriteTime: 2015-04-27T19:08:02.560861300Z
3241620.10b0: ChangeTime: 2015-05-13T06:05:12.472030600Z
3251620.10b0: FileAttributes: 0x20
3261620.10b0: Size: 0x13f400
3271620.10b0: NT Headers: 0xd0
3281620.10b0: Timestamp: 0x553e8801
3291620.10b0: Machine: 0x14c - i386
3301620.10b0: Timestamp: 0x553e8801
3311620.10b0: Image Version: 6.1
3321620.10b0: SizeOfImage: 0x141000 (1314816)
3331620.10b0: Resource Dir: 0xe1000 LB 0x5a028
3341620.10b0: ProductName: Microsoft® Windows® Operating System
3351620.10b0: ProductVersion: 6.1.7601.18839
3361620.10b0: FileVersion: 6.1.7601.18839 (win7sp1_gdr.150427-0707)
3371620.10b0: FileDescription: NT Layer DLL
3381620.10b0: \SystemRoot\System32\kernel32.dll:
3391620.10b0: CreationTime: 2014-04-17T06:50:28.609395400Z
3401620.10b0: LastWriteTime: 2014-03-04T09:17:13.817000000Z
3411620.10b0: ChangeTime: 2014-04-22T06:36:30.681081700Z
3421620.10b0: FileAttributes: 0x20
3431620.10b0: Size: 0xd4000
3441620.10b0: NT Headers: 0xf0
3451620.10b0: Timestamp: 0x531599f5
3461620.10b0: Machine: 0x14c - i386
3471620.10b0: Timestamp: 0x531599f5
3481620.10b0: Image Version: 6.1
3491620.10b0: SizeOfImage: 0xd4000 (868352)
3501620.10b0: Resource Dir: 0xc7000 LB 0x528
3511620.10b0: ProductName: Microsoft® Windows® Operating System
3521620.10b0: ProductVersion: 6.1.7601.18409
3531620.10b0: FileVersion: 6.1.7601.18409 (win7sp1_gdr.140303-2144)
3541620.10b0: FileDescription: Windows NT BASE API Client DLL
3551620.10b0: \SystemRoot\System32\KernelBase.dll:
3561620.10b0: CreationTime: 2014-05-14T10:04:05.890013400Z
3571620.10b0: LastWriteTime: 2014-03-04T09:17:13.817000000Z
3581620.10b0: ChangeTime: 2014-05-14T15:06:48.300616400Z
3591620.10b0: FileAttributes: 0x20
3601620.10b0: Size: 0x47a00
3611620.10b0: NT Headers: 0xe0
3621620.10b0: Timestamp: 0x531599f6
3631620.10b0: Machine: 0x14c - i386
3641620.10b0: Timestamp: 0x531599f6
3651620.10b0: Image Version: 6.1
3661620.10b0: SizeOfImage: 0x4b000 (307200)
3671620.10b0: Resource Dir: 0x47000 LB 0x530
3681620.10b0: ProductName: Microsoft® Windows® Operating System
3691620.10b0: ProductVersion: 6.1.7601.18409
3701620.10b0: FileVersion: 6.1.7601.18409 (win7sp1_gdr.140303-2144)
3711620.10b0: FileDescription: Windows NT BASE API Client DLL
3721620.10b0: \SystemRoot\System32\apisetschema.dll:
3731620.10b0: CreationTime: 2015-05-13T01:43:21.798450900Z
3741620.10b0: LastWriteTime: 2015-04-27T18:59:41.743000000Z
3751620.10b0: ChangeTime: 2015-05-13T06:05:12.222430200Z
3761620.10b0: FileAttributes: 0x20
3771620.10b0: Size: 0x1a00
3781620.10b0: NT Headers: 0xc0
3791620.10b0: Timestamp: 0x553e8756
3801620.10b0: Machine: 0x14c - i386
3811620.10b0: Timestamp: 0x553e8756
3821620.10b0: Image Version: 6.1
3831620.10b0: SizeOfImage: 0x50000 (327680)
3841620.10b0: Resource Dir: 0x30000 LB 0x3f8
3851620.10b0: ProductName: Microsoft® Windows® Operating System
3861620.10b0: ProductVersion: 6.1.7601.18839
3871620.10b0: FileVersion: 6.1.7601.18839 (win7sp1_gdr.150427-0707)
3881620.10b0: FileDescription: ApiSet Schema DLL
3891620.10b0: supR3HardenedWinFindAdversaries: 0x0
3901620.10b0: Calling main()
3911620.10b0: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
3921620.10b0: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
3931620.10b0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe)
3941620.10b0: SUPR3HardenedMain: Final process, opening VBoxDrv...
3951620.10b0: supR3HardenedEarlyCompact: Removed heap 1 (0x280000 LB 0x400000)
3961620.10b0: supR3HardNtEnableThreadCreation:
3971620.10b0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll)
3981620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll
3991620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0072325c:C:\Windows\system32 [calling]
4001620.10b0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
4011620.10b0: supR3HardenedDllNotificationCallback: load 73f80000 LB 0x00005000 C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL [fFlags=0x0]
4021620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
4031620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
4041620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00723a04:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\ibm\gsk8\lib;C:\Program Files\ibm\gsk8\bin;C:\Program Files\IBM Informix Client SDK\bin;D:\app\c3p0i\product\11.2.0\client_2\bin;D:\app\c3p0i\product\11.2.0\client_1;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Bitvise SSH Client;C:\Program Files\Gow\bin;C:\Program Files\Microsoft SQL Server\80\Tools\Binn\;C:\Program Files\Sikuli X\libs;C:\Program Files\Java\jre6\\bin;C:\Program Files\OpenVPN\bin [calling]
4051620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=73f80000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
4061620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
4071620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00723a04:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\ibm\gsk8\lib;C:\Program Files\ibm\gsk8\bin;C:\Program Files\IBM Informix Client SDK\bin;D:\app\c3p0i\product\11.2.0\client_2\bin;D:\app\c3p0i\product\11.2.0\client_1;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Bitvise SSH Client;C:\Program Files\Gow\bin;C:\Program Files\Microsoft SQL Server\80\Tools\Binn\;C:\Program Files\Sikuli X\libs;C:\Program Files\Java\jre6\\bin;C:\Program Files\OpenVPN\bin [calling]
4081620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=73f80000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
4091620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=73f80000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
4101620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
4111620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'crypt32.dll'.
4121620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msasn1.dll'.
4131620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
4141620.10b0: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\wintrust.dll)
4151620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wintrust.dll
4161620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
4171620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
4181620.10b0: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll)
4191620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
4201620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
4211620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume2\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
4221620.10b0: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\msasn1.dll)
4231620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msasn1.dll
4241620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
4251620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume2\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
4261620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
4271620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msasn1.dll'.
4281620.10b0: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\crypt32.dll)
4291620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\crypt32.dll
4301620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
4311620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
4321620.10b0: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\msvcrt.dll)
4331620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
4341620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
4351620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume2\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
4361620.10b0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
4371620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
4381620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
4391620.10b0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
4401620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0072325c:C:\Windows\system32 [calling]
4411620.10b0: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
4421620.10b0: supR3HardenedDllNotificationCallback: load 751d0000 LB 0x0002f000 C:\Windows\system32\Wintrust.dll [fFlags=0x0]
4431620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
4441620.10b0: supR3HardenedDllNotificationCallback: load 762d0000 LB 0x000ac000 C:\Windows\system32\msvcrt.dll [fFlags=0x0]
4451620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
4461620.10b0: supR3HardenedDllNotificationCallback: load 752a0000 LB 0x00121000 C:\Windows\system32\CRYPT32.dll [fFlags=0x0]
4471620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
4481620.10b0: supR3HardenedDllNotificationCallback: load 751b0000 LB 0x0000c000 C:\Windows\system32\MSASN1.dll [fFlags=0x0]
4491620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
4501620.10b0: supR3HardenedDllNotificationCallback: load 77360000 LB 0x000a2000 C:\Windows\system32\RPCRT4.dll [fFlags=0x0]
4511620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
4521620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=751d0000 'C:\Windows\system32\Wintrust.dll'
4531620.10b0: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\bcrypt.dll)
4541620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\bcrypt.dll
4551620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcrypt.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0072325c:C:\Windows\system32 [calling]
4561620.10b0: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
4571620.10b0: supR3HardenedDllNotificationCallback: load 74d00000 LB 0x00017000 C:\Windows\system32\bcrypt.dll [fFlags=0x0]
4581620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
4591620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=74d00000 'C:\Windows\system32\bcrypt.dll'
4601620.10b0: bcrypt.dll loaded at 74d00000, BCryptOpenAlgorithmProvider at 74d02cda, preloading providers:
4611620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
4621620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'bcrypt.dll'.
4631620.10b0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll)
4641620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll
4651620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
4661620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume2\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
4671620.10b0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
4681620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
4691620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
4701620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
4711620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'rpcrt4.dll'.
4721620.10b0: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\advapi32.dll)
4731620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\advapi32.dll
4741620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
4751620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
4761620.10b0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
4771620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
4781620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
4791620.10b0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
4801620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcryptprimitives.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00723a04:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\ibm\gsk8\lib;C:\Program Files\ibm\gsk8\bin;C:\Program Files\IBM Informix Client SDK\bin;D:\app\c3p0i\product\11.2.0\client_2\bin;D:\app\c3p0i\product\11.2.0\client_1;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Bitvise SSH Client;C:\Program Files\Gow\bin;C:\Program Files\Microsoft SQL Server\80\Tools\Binn\;C:\Program Files\Sikuli X\libs;C:\Program Files\Java\jre6\\bin;C:\Program Files\OpenVPN\bin [calling]
4811620.10b0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
4821620.10b0: supR3HardenedDllNotificationCallback: load 748d0000 LB 0x0003d000 C:\Windows\system32\bcryptprimitives.dll [fFlags=0x0]
4831620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
4841620.10b0: supR3HardenedDllNotificationCallback: load 76780000 LB 0x000a1000 C:\Windows\system32\ADVAPI32.dll [fFlags=0x0]
4851620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
4861620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcrt.dll'.
4871620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #15 'rpcrt4.dll'.
4881620.10b0: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\sechost.dll)
4891620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\sechost.dll
4901620.10b0: supR3HardenedDllNotificationCallback: load 76650000 LB 0x00019000 C:\Windows\SYSTEM32\sechost.dll [fFlags=0x0]
4911620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\sechost.dll [lacks WinVerifyTrust]
4921620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=748d0000 'C:\Windows\system32\bcryptprimitives.dll'
4931620.10b0: BCryptOpenAlgorithmProvider(,'MD2',0,0) -> 0x0 (hAlgo=0074e110)
4941620.10b0: BCryptOpenAlgorithmProvider(,'MD4',0,0) -> 0x0 (hAlgo=0074e760)
4951620.10b0: BCryptOpenAlgorithmProvider(,'MD5',0,0) -> 0x0 (hAlgo=0074f518)
4961620.10b0: BCryptOpenAlgorithmProvider(,'SHA1',0,0) -> 0x0 (hAlgo=0074e068)
4971620.10b0: BCryptOpenAlgorithmProvider(,'SHA256',0,0) -> 0x0 (hAlgo=0074f668)
4981620.10b0: BCryptOpenAlgorithmProvider(,'SHA512',0,0) -> 0x0 (hAlgo=0074f708)
4991620.10b0: BCryptOpenAlgorithmProvider(,'RSA',0,0) -> 0x0 (hAlgo=0074f5b8)
5001620.10b0: BCryptOpenAlgorithmProvider(,'DSA',0,0) -> 0x0 (hAlgo=0074f878)
5011620.10b0: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\cryptsp.dll)
5021620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cryptsp.dll
5031620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
5041620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
5051620.10b0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
5061620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
5071620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
5081620.10b0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
5091620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTSP.dll (Input=CRYPTSP.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00723a04:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\ibm\gsk8\lib;C:\Program Files\ibm\gsk8\bin;C:\Program Files\IBM Informix Client SDK\bin;D:\app\c3p0i\product\11.2.0\client_2\bin;D:\app\c3p0i\product\11.2.0\client_1;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Bitvise SSH Client;C:\Program Files\Gow\bin;C:\Program Files\Microsoft SQL Server\80\Tools\Binn\;C:\Program Files\Sikuli X\libs;C:\Program Files\Java\jre6\\bin;C:\Program Files\OpenVPN\bin [calling]
5101620.10b0: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
5111620.10b0: supR3HardenedDllNotificationCallback: load 74bf0000 LB 0x00017000 C:\Windows\system32\CRYPTSP.dll [fFlags=0x0]
5121620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
5131620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=74bf0000 'C:\Windows\system32\CRYPTSP.dll'
5141620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
5151620.10b0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\rsaenh.dll)
5161620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\rsaenh.dll
5171620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
5181620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
5191620.10b0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
5201620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00723a04:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\ibm\gsk8\lib;C:\Program Files\ibm\gsk8\bin;C:\Program Files\IBM Informix Client SDK\bin;D:\app\c3p0i\product\11.2.0\client_2\bin;D:\app\c3p0i\product\11.2.0\client_1;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Bitvise SSH Client;C:\Program Files\Gow\bin;C:\Program Files\Microsoft SQL Server\80\Tools\Binn\;C:\Program Files\Sikuli X\libs;C:\Program Files\Java\jre6\\bin;C:\Program Files\OpenVPN\bin [calling]
5211620.10b0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
5221620.10b0: supR3HardenedDllNotificationCallback: load 74990000 LB 0x0003b000 C:\Windows\system32\rsaenh.dll [fFlags=0x0]
5231620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
5241620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=74990000 'C:\Windows\system32\rsaenh.dll'
5251620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
5261620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ADVAPI32.dll (Input=ADVAPI32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00723a04:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\ibm\gsk8\lib;C:\Program Files\ibm\gsk8\bin;C:\Program Files\IBM Informix Client SDK\bin;D:\app\c3p0i\product\11.2.0\client_2\bin;D:\app\c3p0i\product\11.2.0\client_1;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Bitvise SSH Client;C:\Program Files\Gow\bin;C:\Program Files\Microsoft SQL Server\80\Tools\Binn\;C:\Program Files\Sikuli X\libs;C:\Program Files\Java\jre6\\bin;C:\Program Files\OpenVPN\bin [calling]
5271620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=76780000 'C:\Windows\system32\ADVAPI32.dll'
5281620.10b0: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\cryptbase.dll)
5291620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cryptbase.dll
5301620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTBASE.dll (Input=CRYPTBASE.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00723a04:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\ibm\gsk8\lib;C:\Program Files\ibm\gsk8\bin;C:\Program Files\IBM Informix Client SDK\bin;D:\app\c3p0i\product\11.2.0\client_2\bin;D:\app\c3p0i\product\11.2.0\client_1;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Bitvise SSH Client;C:\Program Files\Gow\bin;C:\Program Files\Microsoft SQL Server\80\Tools\Binn\;C:\Program Files\Sikuli X\libs;C:\Program Files\Java\jre6\\bin;C:\Program Files\OpenVPN\bin [calling]
5311620.10b0: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptbase.dll [lacks WinVerifyTrust]
5321620.10b0: supR3HardenedDllNotificationCallback: load 750d0000 LB 0x0000c000 C:\Windows\system32\CRYPTBASE.dll [fFlags=0x0]
5331620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptbase.dll [lacks WinVerifyTrust]
5341620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=750d0000 'C:\Windows\system32\CRYPTBASE.dll'
5351620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
5361620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00723a04:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\ibm\gsk8\lib;C:\Program Files\ibm\gsk8\bin;C:\Program Files\IBM Informix Client SDK\bin;D:\app\c3p0i\product\11.2.0\client_2\bin;D:\app\c3p0i\product\11.2.0\client_1;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Bitvise SSH Client;C:\Program Files\Gow\bin;C:\Program Files\Microsoft SQL Server\80\Tools\Binn\;C:\Program Files\Sikuli X\libs;C:\Program Files\Java\jre6\\bin;C:\Program Files\OpenVPN\bin [calling]
5371620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=76670000 'C:\Windows\system32\kernel32.dll'
5381620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
5391620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\WINTRUST.DLL (Input=WINTRUST.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00723a04:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\ibm\gsk8\lib;C:\Program Files\ibm\gsk8\bin;C:\Program Files\IBM Informix Client SDK\bin;D:\app\c3p0i\product\11.2.0\client_2\bin;D:\app\c3p0i\product\11.2.0\client_1;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Bitvise SSH Client;C:\Program Files\Gow\bin;C:\Program Files\Microsoft SQL Server\80\Tools\Binn\;C:\Program Files\Sikuli X\libs;C:\Program Files\Java\jre6\\bin;C:\Program Files\OpenVPN\bin [calling]
5401620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=751d0000 'C:\Windows\system32\WINTRUST.DLL'
5411620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
5421620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPT32.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00723a04:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\ibm\gsk8\lib;C:\Program Files\ibm\gsk8\bin;C:\Program Files\IBM Informix Client SDK\bin;D:\app\c3p0i\product\11.2.0\client_2\bin;D:\app\c3p0i\product\11.2.0\client_1;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Bitvise SSH Client;C:\Program Files\Gow\bin;C:\Program Files\Microsoft SQL Server\80\Tools\Binn\;C:\Program Files\Sikuli X\libs;C:\Program Files\Java\jre6\\bin;C:\Program Files\OpenVPN\bin [calling]
5431620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=752a0000 'C:\Windows\system32\CRYPT32.dll'
5441620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
5451620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'advapi32.dll'.
5461620.10b0: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\imagehlp.dll)
5471620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\imagehlp.dll
5481620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
5491620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
5501620.10b0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
5511620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
5521620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
5531620.10b0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
5541620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\imagehlp.dll (Input=imagehlp.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00723a04:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\ibm\gsk8\lib;C:\Program Files\ibm\gsk8\bin;C:\Program Files\IBM Informix Client SDK\bin;D:\app\c3p0i\product\11.2.0\client_2\bin;D:\app\c3p0i\product\11.2.0\client_1;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Bitvise SSH Client;C:\Program Files\Gow\bin;C:\Program Files\Microsoft SQL Server\80\Tools\Binn\;C:\Program Files\Sikuli X\libs;C:\Program Files\Java\jre6\\bin;C:\Program Files\OpenVPN\bin [calling]
5551620.10b0: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\imagehlp.dll [lacks WinVerifyTrust]
5561620.10b0: supR3HardenedDllNotificationCallback: load 76750000 LB 0x0002b000 C:\Windows\system32\imagehlp.dll [fFlags=0x0]
5571620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\imagehlp.dll [lacks WinVerifyTrust]
5581620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=76750000 'C:\Windows\system32\imagehlp.dll'
5591620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
5601620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTSP.dll (Input=CRYPTSP.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00723a04:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\ibm\gsk8\lib;C:\Program Files\ibm\gsk8\bin;C:\Program Files\IBM Informix Client SDK\bin;D:\app\c3p0i\product\11.2.0\client_2\bin;D:\app\c3p0i\product\11.2.0\client_1;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Bitvise SSH Client;C:\Program Files\Gow\bin;C:\Program Files\Microsoft SQL Server\80\Tools\Binn\;C:\Program Files\Sikuli X\libs;C:\Program Files\Java\jre6\\bin;C:\Program Files\OpenVPN\bin [calling]
5611620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=74bf0000 'C:\Windows\system32\CRYPTSP.dll'
5621620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
5631620.10b0: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\user32.dll)
5641620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\user32.dll
5651620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
5661620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
5671620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
5681620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'lpk.dll'.
5691620.10b0: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\gdi32.dll)
5701620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\gdi32.dll
5711620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'lpk.dll'...
5721620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'lpk.dll' -> '\Device\HarddiskVolume2\Windows\System32\lpk.dll' [rcNtRedir=0xc0150008]
5731620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'gdi32.dll'.
5741620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'user32.dll'.
5751620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'usp10.dll'.
5761620.10b0: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\lpk.dll)
5771620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\lpk.dll
5781620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
5791620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
5801620.10b0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
5811620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'usp10.dll'...
5821620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'usp10.dll' -> '\Device\HarddiskVolume2\Windows\System32\usp10.dll' [rcNtRedir=0xc0150008]
5831620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
5841620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
5851620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'gdi32.dll'.
5861620.10b0: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\usp10.dll)
5871620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\usp10.dll
5881620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
5891620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
5901620.10b0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
5911620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
5921620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
5931620.10b0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
5941620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
5951620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
5961620.10b0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
5971620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
5981620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
5991620.10b0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
6001620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
6011620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
6021620.10b0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
6031620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\USER32.dll (Input=USER32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00723a04:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\ibm\gsk8\lib;C:\Program Files\ibm\gsk8\bin;C:\Program Files\IBM Informix Client SDK\bin;D:\app\c3p0i\product\11.2.0\client_2\bin;D:\app\c3p0i\product\11.2.0\client_1;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Bitvise SSH Client;C:\Program Files\Gow\bin;C:\Program Files\Microsoft SQL Server\80\Tools\Binn\;C:\Program Files\Sikuli X\libs;C:\Program Files\Java\jre6\\bin;C:\Program Files\OpenVPN\bin [calling]
6041620.10b0: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
6051620.10b0: supR3HardenedDllNotificationCallback: load 76450000 LB 0x000c9000 C:\Windows\system32\USER32.dll [fFlags=0x0]
6061620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
6071620.10b0: supR3HardenedDllNotificationCallback: load 76400000 LB 0x0004e000 C:\Windows\system32\GDI32.dll [fFlags=0x0]
6081620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
6091620.10b0: supR3HardenedDllNotificationCallback: load 77340000 LB 0x0000a000 C:\Windows\system32\LPK.dll [fFlags=0x0]
6101620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\lpk.dll [lacks WinVerifyTrust]
6111620.10b0: supR3HardenedDllNotificationCallback: load 76de0000 LB 0x0009d000 C:\Windows\system32\USP10.dll [fFlags=0x0]
6121620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\usp10.dll [lacks WinVerifyTrust]
6131620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
6141620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\gdi32.dll (Input=gdi32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00723a04:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\ibm\gsk8\lib;C:\Program Files\ibm\gsk8\bin;C:\Program Files\IBM Informix Client SDK\bin;D:\app\c3p0i\product\11.2.0\client_2\bin;D:\app\c3p0i\product\11.2.0\client_1;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Bitvise SSH Client;C:\Program Files\Gow\bin;C:\Program Files\Microsoft SQL Server\80\Tools\Binn\;C:\Program Files\Sikuli X\libs;C:\Program Files\Java\jre6\\bin;C:\Program Files\OpenVPN\bin [calling]
6151620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=76400000 'C:\Windows\system32\gdi32.dll'
6161620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'user32.dll'.
6171620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
6181620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msctf.dll'.
6191620.10b0: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\imm32.dll)
6201620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\imm32.dll
6211620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msctf.dll'...
6221620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msctf.dll' -> '\Device\HarddiskVolume2\Windows\System32\msctf.dll' [rcNtRedir=0xc0150008]
6231620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
6241620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
6251620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'gdi32.dll'.
6261620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'imm32.dll'.
6271620.10b0: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\msctf.dll)
6281620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msctf.dll
6291620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
6301620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
6311620.10b0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
6321620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
6331620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
6341620.10b0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
6351620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
6361620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume2\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
6371620.10b0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\imm32.dll [lacks WinVerifyTrust]
6381620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
6391620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
6401620.10b0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
6411620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
6421620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
6431620.10b0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
6441620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
6451620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
6461620.10b0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
6471620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\IMM32.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00723a04:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\ibm\gsk8\lib;C:\Program Files\ibm\gsk8\bin;C:\Program Files\IBM Informix Client SDK\bin;D:\app\c3p0i\product\11.2.0\client_2\bin;D:\app\c3p0i\product\11.2.0\client_1;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Bitvise SSH Client;C:\Program Files\Gow\bin;C:\Program Files\Microsoft SQL Server\80\Tools\Binn\;C:\Program Files\Sikuli X\libs;C:\Program Files\Java\jre6\\bin;C:\Program Files\OpenVPN\bin [calling]
6481620.10b0: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\imm32.dll [lacks WinVerifyTrust]
6491620.10b0: supR3HardenedDllNotificationCallback: load 76630000 LB 0x0001f000 C:\Windows\system32\IMM32.DLL [fFlags=0x0]
6501620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\imm32.dll [lacks WinVerifyTrust]
6511620.10b0: supR3HardenedDllNotificationCallback: load 76520000 LB 0x000cc000 C:\Windows\system32\MSCTF.dll [fFlags=0x0]
6521620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msctf.dll [lacks WinVerifyTrust]
6531620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=76630000 'C:\Windows\system32\IMM32.DLL'
6541620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=76450000 'C:\Windows\system32\USER32.dll'
6551620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'bcrypt.dll'.
6561620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
6571620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msasn1.dll'.
6581620.10b0: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\ncrypt.dll)
6591620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ncrypt.dll
6601620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
6611620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume2\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
6621620.10b0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
6631620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
6641620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
6651620.10b0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
6661620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
6671620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume2\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
6681620.10b0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
6691620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ncrypt.dll (Input=ncrypt.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00723a04:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\ibm\gsk8\lib;C:\Program Files\ibm\gsk8\bin;C:\Program Files\IBM Informix Client SDK\bin;D:\app\c3p0i\product\11.2.0\client_2\bin;D:\app\c3p0i\product\11.2.0\client_1;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Bitvise SSH Client;C:\Program Files\Gow\bin;C:\Program Files\Microsoft SQL Server\80\Tools\Binn\;C:\Program Files\Sikuli X\libs;C:\Program Files\Java\jre6\\bin;C:\Program Files\OpenVPN\bin [calling]
6701620.10b0: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\ncrypt.dll [lacks WinVerifyTrust]
6711620.10b0: supR3HardenedDllNotificationCallback: load 74d20000 LB 0x00038000 C:\Windows\system32\ncrypt.dll [fFlags=0x0]
6721620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\ncrypt.dll [lacks WinVerifyTrust]
6731620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=74d20000 'C:\Windows\system32\ncrypt.dll'
6741620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
6751620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcrypt.dll (Input=bcrypt.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00723a04:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\ibm\gsk8\lib;C:\Program Files\ibm\gsk8\bin;C:\Program Files\IBM Informix Client SDK\bin;D:\app\c3p0i\product\11.2.0\client_2\bin;D:\app\c3p0i\product\11.2.0\client_1;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Bitvise SSH Client;C:\Program Files\Gow\bin;C:\Program Files\Microsoft SQL Server\80\Tools\Binn\;C:\Program Files\Sikuli X\libs;C:\Program Files\Java\jre6\\bin;C:\Program Files\OpenVPN\bin [calling]
6761620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=74d00000 'C:\Windows\system32\bcrypt.dll'
6771620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
6781620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'rpcrt4.dll'.
6791620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #19 'profapi.dll'.
6801620.10b0: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\userenv.dll)
6811620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\userenv.dll
6821620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'profapi.dll'...
6831620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'profapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\profapi.dll' [rcNtRedir=0xc0150008]
6841620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
6851620.10b0: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\profapi.dll)
6861620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\profapi.dll
6871620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
6881620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
6891620.10b0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
6901620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
6911620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
6921620.10b0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
6931620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
6941620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
6951620.10b0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
6961620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\USERENV.dll (Input=USERENV.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00723a04:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\ibm\gsk8\lib;C:\Program Files\ibm\gsk8\bin;C:\Program Files\IBM Informix Client SDK\bin;D:\app\c3p0i\product\11.2.0\client_2\bin;D:\app\c3p0i\product\11.2.0\client_1;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Bitvise SSH Client;C:\Program Files\Gow\bin;C:\Program Files\Microsoft SQL Server\80\Tools\Binn\;C:\Program Files\Sikuli X\libs;C:\Program Files\Java\jre6\\bin;C:\Program Files\OpenVPN\bin [calling]
6971620.10b0: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\userenv.dll [lacks WinVerifyTrust]
6981620.10b0: supR3HardenedDllNotificationCallback: load 754b0000 LB 0x00017000 C:\Windows\system32\USERENV.dll [fFlags=0x0]
6991620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\userenv.dll [lacks WinVerifyTrust]
7001620.10b0: supR3HardenedDllNotificationCallback: load 751c0000 LB 0x0000b000 C:\Windows\system32\profapi.dll [fFlags=0x0]
7011620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\profapi.dll [lacks WinVerifyTrust]
7021620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=754b0000 'C:\Windows\system32\USERENV.dll'
7031620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00723a04:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\ibm\gsk8\lib;C:\Program Files\ibm\gsk8\bin;C:\Program Files\IBM Informix Client SDK\bin;D:\app\c3p0i\product\11.2.0\client_2\bin;D:\app\c3p0i\product\11.2.0\client_1;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Bitvise SSH Client;C:\Program Files\Gow\bin;C:\Program Files\Microsoft SQL Server\80\Tools\Binn\;C:\Program Files\Sikuli X\libs;C:\Program Files\Java\jre6\\bin;C:\Program Files\OpenVPN\bin [calling]
7041620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=76650000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
7051620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00723a04:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\ibm\gsk8\lib;C:\Program Files\ibm\gsk8\bin;C:\Program Files\IBM Informix Client SDK\bin;D:\app\c3p0i\product\11.2.0\client_2\bin;D:\app\c3p0i\product\11.2.0\client_1;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Bitvise SSH Client;C:\Program Files\Gow\bin;C:\Program Files\Microsoft SQL Server\80\Tools\Binn\;C:\Program Files\Sikuli X\libs;C:\Program Files\Java\jre6\\bin;C:\Program Files\OpenVPN\bin [calling]
7061620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=76650000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
7071620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
7081620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'rpcrt4.dll'.
7091620.10b0: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\gpapi.dll)
7101620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\gpapi.dll
7111620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
7121620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
7131620.10b0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
7141620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
7151620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
7161620.10b0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
7171620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\GPAPI.dll (Input=GPAPI.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00723a04:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\ibm\gsk8\lib;C:\Program Files\ibm\gsk8\bin;C:\Program Files\IBM Informix Client SDK\bin;D:\app\c3p0i\product\11.2.0\client_2\bin;D:\app\c3p0i\product\11.2.0\client_1;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Bitvise SSH Client;C:\Program Files\Gow\bin;C:\Program Files\Microsoft SQL Server\80\Tools\Binn\;C:\Program Files\Sikuli X\libs;C:\Program Files\Java\jre6\\bin;C:\Program Files\OpenVPN\bin [calling]
7181620.10b0: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gpapi.dll [lacks WinVerifyTrust]
7191620.10b0: supR3HardenedDllNotificationCallback: load 747a0000 LB 0x00016000 C:\Windows\system32\GPAPI.dll [fFlags=0x0]
7201620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gpapi.dll [lacks WinVerifyTrust]
7211620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=747a0000 'C:\Windows\system32\GPAPI.dll'
7221620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-Management-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00723a04:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\ibm\gsk8\lib;C:\Program Files\ibm\gsk8\bin;C:\Program Files\IBM Informix Client SDK\bin;D:\app\c3p0i\product\11.2.0\client_2\bin;D:\app\c3p0i\product\11.2.0\client_1;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Bitvise SSH Client;C:\Program Files\Gow\bin;C:\Program Files\Microsoft SQL Server\80\Tools\Binn\;C:\Program Files\Sikuli X\libs;C:\Program Files\Java\jre6\\bin;C:\Program Files\OpenVPN\bin [calling]
7231620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=76650000 'API-MS-WIN-Service-Management-L1-1-0.dll'
7241620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
7251620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rpcrt4.dll (Input=rpcrt4.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00723a04:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\ibm\gsk8\lib;C:\Program Files\ibm\gsk8\bin;C:\Program Files\IBM Informix Client SDK\bin;D:\app\c3p0i\product\11.2.0\client_2\bin;D:\app\c3p0i\product\11.2.0\client_1;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Bitvise SSH Client;C:\Program Files\Gow\bin;C:\Program Files\Microsoft SQL Server\80\Tools\Binn\;C:\Program Files\Sikuli X\libs;C:\Program Files\Java\jre6\\bin;C:\Program Files\OpenVPN\bin [calling]
7261620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77360000 'C:\Windows\system32\rpcrt4.dll'
7271620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-Management-L2-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00723a04:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\ibm\gsk8\lib;C:\Program Files\ibm\gsk8\bin;C:\Program Files\IBM Informix Client SDK\bin;D:\app\c3p0i\product\11.2.0\client_2\bin;D:\app\c3p0i\product\11.2.0\client_1;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Bitvise SSH Client;C:\Program Files\Gow\bin;C:\Program Files\Microsoft SQL Server\80\Tools\Binn\;C:\Program Files\Sikuli X\libs;C:\Program Files\Java\jre6\\bin;C:\Program Files\OpenVPN\bin [calling]
7281620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=76650000 'API-MS-WIN-Service-Management-L2-1-0.dll'
7291620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00723a04:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\ibm\gsk8\lib;C:\Program Files\ibm\gsk8\bin;C:\Program Files\IBM Informix Client SDK\bin;D:\app\c3p0i\product\11.2.0\client_2\bin;D:\app\c3p0i\product\11.2.0\client_1;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Bitvise SSH Client;C:\Program Files\Gow\bin;C:\Program Files\Microsoft SQL Server\80\Tools\Binn\;C:\Program Files\Sikuli X\libs;C:\Program Files\Java\jre6\\bin;C:\Program Files\OpenVPN\bin [calling]
7301620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=76650000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
7311620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
7321620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
7331620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'crypt32.dll'.
7341620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'wldap32.dll'.
7351620.10b0: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\cryptnet.dll)
7361620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cryptnet.dll
7371620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wldap32.dll'...
7381620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'wldap32.dll' -> '\Device\HarddiskVolume2\Windows\System32\wldap32.dll' [rcNtRedir=0xc0150008]
7391620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
7401620.10b0: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\Wldap32.dll)
7411620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\Wldap32.dll
7421620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
7431620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume2\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
7441620.10b0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
7451620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
7461620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
7471620.10b0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
7481620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
7491620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
7501620.10b0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
7511620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
7521620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
7531620.10b0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
7541620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (Input=cryptnet.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00723a04:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\ibm\gsk8\lib;C:\Program Files\ibm\gsk8\bin;C:\Program Files\IBM Informix Client SDK\bin;D:\app\c3p0i\product\11.2.0\client_2\bin;D:\app\c3p0i\product\11.2.0\client_1;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Bitvise SSH Client;C:\Program Files\Gow\bin;C:\Program Files\Microsoft SQL Server\80\Tools\Binn\;C:\Program Files\Sikuli X\libs;C:\Program Files\Java\jre6\\bin;C:\Program Files\OpenVPN\bin [calling]
7551620.10b0: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
7561620.10b0: supR3HardenedDllNotificationCallback: load 6f420000 LB 0x0001c000 C:\Windows\system32\cryptnet.dll [fFlags=0x0]
7571620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
7581620.10b0: supR3HardenedDllNotificationCallback: load 76920000 LB 0x00045000 C:\Windows\system32\WLDAP32.dll [fFlags=0x0]
7591620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\Wldap32.dll [lacks WinVerifyTrust]
7601620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
7611620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00723a04:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\ibm\gsk8\lib;C:\Program Files\ibm\gsk8\bin;C:\Program Files\IBM Informix Client SDK\bin;D:\app\c3p0i\product\11.2.0\client_2\bin;D:\app\c3p0i\product\11.2.0\client_1;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Bitvise SSH Client;C:\Program Files\Gow\bin;C:\Program Files\Microsoft SQL Server\80\Tools\Binn\;C:\Program Files\Sikuli X\libs;C:\Program Files\Java\jre6\\bin;C:\Program Files\OpenVPN\bin [calling]
7621620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6f420000 'C:\Windows\system32\cryptnet.dll'
7631620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
7641620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00723a04:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\ibm\gsk8\lib;C:\Program Files\ibm\gsk8\bin;C:\Program Files\IBM Informix Client SDK\bin;D:\app\c3p0i\product\11.2.0\client_2\bin;D:\app\c3p0i\product\11.2.0\client_1;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Bitvise SSH Client;C:\Program Files\Gow\bin;C:\Program Files\Microsoft SQL Server\80\Tools\Binn\;C:\Program Files\Sikuli X\libs;C:\Program Files\Java\jre6\\bin;C:\Program Files\OpenVPN\bin [calling]
7651620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6f420000 'C:\Windows\system32\cryptnet.dll'
7661620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
7671620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00723a04:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\ibm\gsk8\lib;C:\Program Files\ibm\gsk8\bin;C:\Program Files\IBM Informix Client SDK\bin;D:\app\c3p0i\product\11.2.0\client_2\bin;D:\app\c3p0i\product\11.2.0\client_1;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Bitvise SSH Client;C:\Program Files\Gow\bin;C:\Program Files\Microsoft SQL Server\80\Tools\Binn\;C:\Program Files\Sikuli X\libs;C:\Program Files\Java\jre6\\bin;C:\Program Files\OpenVPN\bin [calling]
7681620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6f420000 'C:\Windows\system32\cryptnet.dll'
7691620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
7701620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00723a04:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\ibm\gsk8\lib;C:\Program Files\ibm\gsk8\bin;C:\Program Files\IBM Informix Client SDK\bin;D:\app\c3p0i\product\11.2.0\client_2\bin;D:\app\c3p0i\product\11.2.0\client_1;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Bitvise SSH Client;C:\Program Files\Gow\bin;C:\Program Files\Microsoft SQL Server\80\Tools\Binn\;C:\Program Files\Sikuli X\libs;C:\Program Files\Java\jre6\\bin;C:\Program Files\OpenVPN\bin [calling]
7711620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6f420000 'C:\Windows\system32\cryptnet.dll'
7721620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
7731620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00723a04:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\ibm\gsk8\lib;C:\Program Files\ibm\gsk8\bin;C:\Program Files\IBM Informix Client SDK\bin;D:\app\c3p0i\product\11.2.0\client_2\bin;D:\app\c3p0i\product\11.2.0\client_1;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Bitvise SSH Client;C:\Program Files\Gow\bin;C:\Program Files\Microsoft SQL Server\80\Tools\Binn\;C:\Program Files\Sikuli X\libs;C:\Program Files\Java\jre6\\bin;C:\Program Files\OpenVPN\bin [calling]
7741620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6f420000 'C:\Windows\system32\cryptnet.dll'
7751620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
7761620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00723a04:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\ibm\gsk8\lib;C:\Program Files\ibm\gsk8\bin;C:\Program Files\IBM Informix Client SDK\bin;D:\app\c3p0i\product\11.2.0\client_2\bin;D:\app\c3p0i\product\11.2.0\client_1;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Bitvise SSH Client;C:\Program Files\Gow\bin;C:\Program Files\Microsoft SQL Server\80\Tools\Binn\;C:\Program Files\Sikuli X\libs;C:\Program Files\Java\jre6\\bin;C:\Program Files\OpenVPN\bin [calling]
7771620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6f420000 'C:\Windows\system32\cryptnet.dll'
7781620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
7791620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6f420000 'C:\Windows\system32\cryptnet.dll'
7801620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
7811620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6f420000 'C:\Windows\system32\cryptnet.dll'
7821620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
7831620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6f420000 'C:\Windows\system32\cryptnet.dll'
7841620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
7851620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6f420000 'C:\Windows\system32\cryptnet.dll'
7861620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
7871620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6f420000 'C:\Windows\system32\cryptnet.dll'
7881620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6f420000 'C:\Windows\system32\cryptnet.dll'
7891620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
7901620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6f420000 'C:\Windows\system32\cryptnet.dll'
7911620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00723a04:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\ibm\gsk8\lib;C:\Program Files\ibm\gsk8\bin;C:\Program Files\IBM Informix Client SDK\bin;D:\app\c3p0i\product\11.2.0\client_2\bin;D:\app\c3p0i\product\11.2.0\client_1;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Bitvise SSH Client;C:\Program Files\Gow\bin;C:\Program Files\Microsoft SQL Server\80\Tools\Binn\;C:\Program Files\Sikuli X\libs;C:\Program Files\Java\jre6\\bin;C:\Program Files\OpenVPN\bin [calling]
7921620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=76650000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
7931620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\profapi.dll [lacks WinVerifyTrust]
7941620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\profapi.dll (Input=profapi.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00723a04:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\ibm\gsk8\lib;C:\Program Files\ibm\gsk8\bin;C:\Program Files\IBM Informix Client SDK\bin;D:\app\c3p0i\product\11.2.0\client_2\bin;D:\app\c3p0i\product\11.2.0\client_1;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Bitvise SSH Client;C:\Program Files\Gow\bin;C:\Program Files\Microsoft SQL Server\80\Tools\Binn\;C:\Program Files\Sikuli X\libs;C:\Program Files\Java\jre6\\bin;C:\Program Files\OpenVPN\bin [calling]
7951620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=751c0000 'C:\Windows\system32\profapi.dll'
7961620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
7971620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
7981620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msvcrt.dll'.
7991620.10b0: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\shlwapi.dll)
8001620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\shlwapi.dll
8011620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
8021620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
8031620.10b0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
8041620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
8051620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
8061620.10b0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
8071620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
8081620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
8091620.10b0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
8101620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\SHLWAPI.dll (Input=SHLWAPI.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00723a04:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\ibm\gsk8\lib;C:\Program Files\ibm\gsk8\bin;C:\Program Files\IBM Informix Client SDK\bin;D:\app\c3p0i\product\11.2.0\client_2\bin;D:\app\c3p0i\product\11.2.0\client_1;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Bitvise SSH Client;C:\Program Files\Gow\bin;C:\Program Files\Microsoft SQL Server\80\Tools\Binn\;C:\Program Files\Sikuli X\libs;C:\Program Files\Java\jre6\\bin;C:\Program Files\OpenVPN\bin [calling]
8111620.10b0: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll [lacks WinVerifyTrust]
8121620.10b0: supR3HardenedDllNotificationCallback: load 768c0000 LB 0x00057000 C:\Windows\system32\SHLWAPI.dll [fFlags=0x0]
8131620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll [lacks WinVerifyTrust]
8141620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=768c0000 'C:\Windows\system32\SHLWAPI.dll'
8151620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000 pwszName=\SystemRoot\System32\ntdll.dll
8161620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: New context 00769d60
8171620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00769d60
8181620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=D75B31A39D3E7A982110991D3130254CB608909B
8191620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00723a04:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\ibm\gsk8\lib;C:\Program Files\ibm\gsk8\bin;C:\Program Files\IBM Informix Client SDK\bin;D:\app\c3p0i\product\11.2.0\client_2\bin;D:\app\c3p0i\product\11.2.0\client_1;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Bitvise SSH Client;C:\Program Files\Gow\bin;C:\Program Files\Microsoft SQL Server\80\Tools\Binn\;C:\Program Files\Sikuli X\libs;C:\Program Files\Java\jre6\\bin;C:\Program Files\OpenVPN\bin [calling]
8201620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=76650000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
8211620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-Management-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00723a04:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\ibm\gsk8\lib;C:\Program Files\ibm\gsk8\bin;C:\Program Files\IBM Informix Client SDK\bin;D:\app\c3p0i\product\11.2.0\client_2\bin;D:\app\c3p0i\product\11.2.0\client_1;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Bitvise SSH Client;C:\Program Files\Gow\bin;C:\Program Files\Microsoft SQL Server\80\Tools\Binn\;C:\Program Files\Sikuli X\libs;C:\Program Files\Java\jre6\\bin;C:\Program Files\OpenVPN\bin [calling]
8221620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=76650000 'API-MS-WIN-Service-Management-L1-1-0.dll'
8231620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-winsvc-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00723a04:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\ibm\gsk8\lib;C:\Program Files\ibm\gsk8\bin;C:\Program Files\IBM Informix Client SDK\bin;D:\app\c3p0i\product\11.2.0\client_2\bin;D:\app\c3p0i\product\11.2.0\client_1;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Bitvise SSH Client;C:\Program Files\Gow\bin;C:\Program Files\Microsoft SQL Server\80\Tools\Binn\;C:\Program Files\Sikuli X\libs;C:\Program Files\Java\jre6\\bin;C:\Program Files\OpenVPN\bin [calling]
8241620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=76650000 'API-MS-WIN-Service-winsvc-L1-1-0.dll'
8251620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
8261620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ADVAPI32.dll (Input=ADVAPI32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00723a04:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\ibm\gsk8\lib;C:\Program Files\ibm\gsk8\bin;C:\Program Files\IBM Informix Client SDK\bin;D:\app\c3p0i\product\11.2.0\client_2\bin;D:\app\c3p0i\product\11.2.0\client_1;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Bitvise SSH Client;C:\Program Files\Gow\bin;C:\Program Files\Microsoft SQL Server\80\Tools\Binn\;C:\Program Files\Sikuli X\libs;C:\Program Files\Java\jre6\\bin;C:\Program Files\OpenVPN\bin [calling]
8271620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=76780000 'C:\Windows\system32\ADVAPI32.dll'
8281620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-LSALookup-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00723a04:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\ibm\gsk8\lib;C:\Program Files\ibm\gsk8\bin;C:\Program Files\IBM Informix Client SDK\bin;D:\app\c3p0i\product\11.2.0\client_2\bin;D:\app\c3p0i\product\11.2.0\client_1;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Bitvise SSH Client;C:\Program Files\Gow\bin;C:\Program Files\Microsoft SQL Server\80\Tools\Binn\;C:\Program Files\Sikuli X\libs;C:\Program Files\Java\jre6\\bin;C:\Program Files\OpenVPN\bin [calling]
8291620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=76650000 'API-MS-Win-Security-LSALookup-L1-1-0.dll'
8301620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-LSALookup-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00723a04:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\ibm\gsk8\lib;C:\Program Files\ibm\gsk8\bin;C:\Program Files\IBM Informix Client SDK\bin;D:\app\c3p0i\product\11.2.0\client_2\bin;D:\app\c3p0i\product\11.2.0\client_1;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Bitvise SSH Client;C:\Program Files\Gow\bin;C:\Program Files\Microsoft SQL Server\80\Tools\Binn\;C:\Program Files\Sikuli X\libs;C:\Program Files\Java\jre6\\bin;C:\Program Files\OpenVPN\bin [calling]
8311620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=76650000 'API-MS-Win-Security-LSALookup-L1-1-0.dll'
8321620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_38_for_KB3022345~31bf3856ad364e35~x86~~6.1.1.2.cat'; file='\SystemRoot\System32\ntdll.dll'
8331620.10b0: g_pfnWinVerifyTrust=751d273a
8341620.10b0: supR3HardenedScreenImage/preload: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [redoing WinVerifyTrust]
8351620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000e4 pwszName=\Device\HarddiskVolume2\Windows\System32\crypt32.dll
8361620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00769d60
8371620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00769d60
8381620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=5899593484521EBF43C3FBEF1689EAD74AD8ED7D
8391620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_106_for_KB3033929~31bf3856ad364e35~x86~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\crypt32.dll'
8401620.10b0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
8411620.10b0: supR3HardenedScreenImage/preload: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\crypt32.dll'
8421620.10b0: supR3HardenedScreenImage/preload: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [redoing WinVerifyTrust]
8431620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000d8 pwszName=\Device\HarddiskVolume2\Windows\System32\wintrust.dll
8441620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00769d60
8451620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00769d60
8461620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=AD400B10391BF763CC5DFDE600010DE093424AAC
8471620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_57_for_KB3033929~31bf3856ad364e35~x86~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\wintrust.dll'
8481620.10b0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
8491620.10b0: supR3HardenedScreenImage/preload: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\wintrust.dll'
8501620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000390 pwszName=\Device\HarddiskVolume2\Windows\System32\shlwapi.dll
8511620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00769d60
8521620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00769d60
8531620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=5A97620B38393821964747185BD0CFB4FF244F0A
8541620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\shlwapi.dll'
8551620.10b0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
8561620.10b0: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll'
8571620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000384 pwszName=\Device\HarddiskVolume2\Windows\System32\Wldap32.dll
8581620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00769d60
8591620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00769d60
8601620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=4274E678F4A09F0955B304F45CFA0547B0F86BC7
8611620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\Wldap32.dll'
8621620.10b0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
8631620.10b0: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\Wldap32.dll'
8641620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000380 pwszName=\Device\HarddiskVolume2\Windows\System32\cryptnet.dll
8651620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00769d60
8661620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00769d60
8671620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=89E77407A345B2D82F06806B31C1CEFF03A91A6A
8681620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_57_for_KB3033929~31bf3856ad364e35~x86~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\cryptnet.dll'
8691620.10b0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
8701620.10b0: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\cryptnet.dll'
8711620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000025c pwszName=\Device\HarddiskVolume2\Windows\System32\gpapi.dll
8721620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00769d60
8731620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00769d60
8741620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=BD66D8D7C0A43466AD80C34E81C083C3C69E195B
8751620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\gpapi.dll'
8761620.10b0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
8771620.10b0: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\gpapi.dll'
8781620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000001c8 pwszName=\Device\HarddiskVolume2\Windows\System32\profapi.dll
8791620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00769d60
8801620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00769d60
8811620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=D9A4C90615FC5B5674208A5401C018FEA2A04A4B
8821620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\profapi.dll'
8831620.10b0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
8841620.10b0: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\profapi.dll'
8851620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000001c4 pwszName=\Device\HarddiskVolume2\Windows\System32\userenv.dll
8861620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00769d60
8871620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00769d60
8881620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=21925C895DA97CB66CCC5FBA910D9ABD265AA276
8891620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\userenv.dll'
8901620.10b0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
8911620.10b0: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\userenv.dll'
8921620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000001b0 pwszName=\Device\HarddiskVolume2\Windows\System32\ncrypt.dll
8931620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00769d60
8941620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00769d60
8951620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=3C162057009F15589931F2F9C420601EA23D426B
8961620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_38_for_KB3022345~31bf3856ad364e35~x86~~6.1.1.2.cat'; file='\Device\HarddiskVolume2\Windows\System32\ncrypt.dll'
8971620.10b0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
8981620.10b0: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\ncrypt.dll'
8991620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000198 pwszName=\Device\HarddiskVolume2\Windows\System32\msctf.dll
9001620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00769d60
9011620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00769d60
9021620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=21CC868DE3508F5C6F6D348B324C1E8AB2969CC6
9031620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_2_for_KB3033889~31bf3856ad364e35~x86~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\Windows\System32\msctf.dll'
9041620.10b0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
9051620.10b0: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\msctf.dll'
9061620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000194 pwszName=\Device\HarddiskVolume2\Windows\System32\imm32.dll
9071620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00769d60
9081620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00769d60
9091620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=CB8862BB29C3F539B9BF3A9E49EBC509A515AC5C
9101620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\imm32.dll'
9111620.10b0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
9121620.10b0: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\imm32.dll'
9131620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000190 pwszName=\Device\HarddiskVolume2\Windows\System32\usp10.dll
9141620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00769d60
9151620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00769d60
9161620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=43A12765C9BE008AD8F89DD9D8ADE42781F3CECF
9171620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_2_for_KB2957509~31bf3856ad364e35~x86~~6.1.1.2.cat'; file='\Device\HarddiskVolume2\Windows\System32\usp10.dll'
9181620.10b0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
9191620.10b0: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\usp10.dll'
9201620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000018c pwszName=\Device\HarddiskVolume2\Windows\System32\lpk.dll
9211620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00769d60
9221620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00769d60
9231620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=82BA1962EC46224806FF94FB51B2673A26041759
9241620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_2_for_KB3032323~31bf3856ad364e35~x86~~6.1.1.3.cat'; file='\Device\HarddiskVolume2\Windows\System32\lpk.dll'
9251620.10b0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
9261620.10b0: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\lpk.dll'
9271620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000188 pwszName=\Device\HarddiskVolume2\Windows\System32\gdi32.dll
9281620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00769d60
9291620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00769d60
9301620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=9262291212E863338E5EEFAE7EA78C13B621DE20
9311620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_2_for_KB3046306~31bf3856ad364e35~x86~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\Windows\System32\gdi32.dll'
9321620.10b0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
9331620.10b0: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\gdi32.dll'
9341620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000184 pwszName=\Device\HarddiskVolume2\Windows\System32\user32.dll
9351620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00769d60
9361620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00769d60
9371620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=46D722AD9F66278A8EBC0D192855961CE6A21050
9381620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\user32.dll'
9391620.10b0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
9401620.10b0: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\user32.dll'
9411620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000180 pwszName=\Device\HarddiskVolume2\Windows\System32\imagehlp.dll
9421620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00769d60
9431620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00769d60
9441620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=D59F877FD4F27652A01B1936874AFAF3A55572A8
9451620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_2_for_KB2893294~31bf3856ad364e35~x86~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\imagehlp.dll'
9461620.10b0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
9471620.10b0: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\imagehlp.dll'
9481620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000134 pwszName=\Device\HarddiskVolume2\Windows\System32\cryptbase.dll
9491620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00769d60
9501620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00769d60
9511620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=7E0CBD7D0C7F18B4CDC624EAFFFE29E8644EB2D5
9521620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\cryptbase.dll'
9531620.10b0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
9541620.10b0: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\cryptbase.dll'
9551620.10b0: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\rsaenh.dll'
9561620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000130 pwszName=\Device\HarddiskVolume2\Windows\System32\cryptsp.dll
9571620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00769d60
9581620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00769d60
9591620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=EFE6B29BE955FB2D869F3B57909DF90693FBBCEB
9601620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_57_for_KB3033929~31bf3856ad364e35~x86~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\cryptsp.dll'
9611620.10b0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
9621620.10b0: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\cryptsp.dll'
9631620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000124 pwszName=\Device\HarddiskVolume2\Windows\System32\sechost.dll
9641620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00769d60
9651620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00769d60
9661620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=03C748C87A1DF5DB8A18BC64469B9F2F9B1E97A4
9671620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_38_for_KB3022345~31bf3856ad364e35~x86~~6.1.1.2.cat'; file='\Device\HarddiskVolume2\Windows\System32\sechost.dll'
9681620.10b0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
9691620.10b0: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\sechost.dll'
9701620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000120 pwszName=\Device\HarddiskVolume2\Windows\System32\advapi32.dll
9711620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00769d60
9721620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00769d60
9731620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=E9F27C8C9C98181856ECB8B0C4901455595659DC
9741620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_38_for_KB3022345~31bf3856ad364e35~x86~~6.1.1.2.cat'; file='\Device\HarddiskVolume2\Windows\System32\advapi32.dll'
9751620.10b0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
9761620.10b0: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\advapi32.dll'
9771620.10b0: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll'
9781620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000108 pwszName=\Device\HarddiskVolume2\Windows\System32\bcrypt.dll
9791620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00769d60
9801620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00769d60
9811620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F0BAB1EFD5C685AC53B020519B5A6984B19E5071
9821620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\bcrypt.dll'
9831620.10b0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
9841620.10b0: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\bcrypt.dll'
9851620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000e8 pwszName=\Device\HarddiskVolume2\Windows\System32\msvcrt.dll
9861620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00769d60
9871620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00769d60
9881620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=50B466D5DDEDD2D1A524F20B8873F187B62AA69F
9891620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_2_for_KB2654428~31bf3856ad364e35~x86~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\Windows\System32\msvcrt.dll'
9901620.10b0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
9911620.10b0: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll'
9921620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000e0 pwszName=\Device\HarddiskVolume2\Windows\System32\msasn1.dll
9931620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00769d60
9941620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00769d60
9951620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=7068F2E1634BBD478D1FBCF4C463626913EA7285
9961620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\msasn1.dll'
9971620.10b0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
9981620.10b0: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\msasn1.dll'
9991620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000dc pwszName=\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
10001620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00769d60
10011620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00769d60
10021620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=06D41DECE180CBB3CA57E6BA142D5CEEF83911AA
10031620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_2_for_KB2978668~31bf3856ad364e35~x86~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll'
10041620.10b0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
10051620.10b0: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll'
10061620.10b0: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll'
10071620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000024 pwszName=\Device\HarddiskVolume2\Windows\System32\KernelBase.dll
10081620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00769d60
10091620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00769d60
10101620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=8EB77778F9F6A58100DE8E79F4C640441D1A46DC
10111620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_31_for_KB2871997~31bf3856ad364e35~x86~~6.1.2.5.cat'; file='\Device\HarddiskVolume2\Windows\System32\KernelBase.dll'
10121620.10b0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
10131620.10b0: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\KernelBase.dll'
10141620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000001c pwszName=\Device\HarddiskVolume2\Windows\System32\kernel32.dll
10151620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00769d60
10161620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00769d60
10171620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=8384E0CDC14CEB0CEB1E02FD8F4D7F7A10FC6E0E
10181620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_31_for_KB2871997~31bf3856ad364e35~x86~~6.1.2.5.cat'; file='\Device\HarddiskVolume2\Windows\System32\kernel32.dll'
10191620.10b0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
10201620.10b0: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\kernel32.dll'
10211620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll
10221620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\crypt32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00769014:C:\Windows\system32 [calling]
10231620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=752a0000 'C:\Windows\system32\crypt32.dll'
10241620.10b0: supR3HardenedWinIsDesiredRootCA: Adding 0x5ad46780fa5df300 DC=com, DC=microsoft, CN=Microsoft Root Certificate Authority
10251620.10b0: supR3HardenedWinIsDesiredRootCA: Adding 0xea5386456178582b C=ZA, ST=Western Cape, L=Durbanville, O=Thawte, OU=Thawte Certification, CN=Thawte Timestamping CA
10261620.10b0: supR3HardenedWinIsDesiredRootCA: Adding 0x3be670c1bd02a900 OU=Copyright (c) 1997 Microsoft Corp., OU=Microsoft Corporation, CN=Microsoft Root Authority
10271620.10b0: supR3HardenedWinIsDesiredRootCA: Adding 0x4d3835aa4180b200 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2011
10281620.10b0: supR3HardenedWinIsDesiredRootCA: Adding 0x987869d3679da00 CN=ClockworkMod
10291620.10b0: supR3HardenedWinIsDesiredRootCA: Adding 0x646e3fe3ba08df00 C=US, O=MSFT, CN=Microsoft Authenticode(tm) Root Authority
10301620.10b0: supR3HardenedWinIsDesiredRootCA: skipping - not-self-signed: C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com, Inc., OU=http://certificates.godaddy.com/repository, CN=Go Daddy Secure Certification Authority(
10311620.10b0: supR3HardenedWinIsDesiredRootCA: Adding 0xece4e4289e08b900 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010
10321620.10b0: supR3HardenedWinIsDesiredRootCA: Adding 0x43a9cc371ff5385a O=Microsoft Trust Network, OU=Microsoft Corporation, OU=Microsoft Time Stamping Service Root, OU=Copyright (c) 1997 Microsoft Corp.
10331620.10b0: supR3HardenedWinIsDesiredRootCA: Adding 0x2e2d2c7c68f0202e O=VeriSign Trust Network, OU=VeriSign, Inc., OU=VeriSign Time Stamping Service Root, OU=NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.
10341620.10b0: supR3HardenedWinIsDesiredRootCA: Adding 0x61a3a33f81aace00 C=US, ST=UT, L=Salt Lake City, O=The USERTRUST Network, OU=http://www.usertrust.com, CN=UTN-USERFirst-Object
10351620.10b0: supR3HardenedWinIsDesiredRootCA: Adding 0xf4fd306318ccda00 C=US, O=GeoTrust Inc., CN=GeoTrust Global CA
10361620.10b0: supR3HardenedWinIsDesiredRootCA: Adding 0x3d98ab22bb04a300 C=IE, O=Baltimore, OU=CyberTrust, CN=Baltimore CyberTrust Root
10371620.10b0: supR3HardenedWinIsDesiredRootCA: Adding 0xa0ee62086758b15d C=US, O=Equifax, OU=Equifax Secure Certificate Authority
10381620.10b0: supR3HardenedWinIsDesiredRootCA: Adding 0x8ff6fc03c1edbd00 C=US, ST=Arizona, L=Scottsdale, O=Starfield Technologies, Inc., CN=Starfield Root Certificate Authority - G2
10391620.10b0: supR3HardenedWinIsDesiredRootCA: Adding 0xa3ce8d99e60eda00 C=BE, O=GlobalSign nv-sa, OU=Root CA, CN=GlobalSign Root CA
10401620.10b0: supR3HardenedWinIsDesiredRootCA: Adding 0xa671e9fec832b700 C=US, O=Starfield Technologies, Inc., OU=Starfield Class 2 Certification Authority
10411620.10b0: supR3HardenedWinIsDesiredRootCA: Adding 0xa8de7211e13be200 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root CA
10421620.10b0: supR3HardenedWinIsDesiredRootCA: Adding 0xff3891b54348328 C=US, O=Entrust.net, OU=www.entrust.net/CPS incorp. by ref. (limits liab.), OU=(c) 1999 Entrust.net Limited, CN=Entrust.net Secure Server Certification Authority
10431620.10b0: supR3HardenedWinIsDesiredRootCA: Adding 0x7ae89c50f0b6a00f C=US, O=GTE Corporation, OU=GTE CyberTrust Solutions, Inc., CN=GTE CyberTrust Global Root
10441620.10b0: supR3HardenedWinIsDesiredRootCA: Adding 0xd45980fbf0a0ac00 C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2006 thawte, Inc. - For authorized use only, CN=thawte Primary Root CA
10451620.10b0: supR3HardenedWinIsDesiredRootCA: Adding 0xf5cd95e581a4ab00 C=US, O=SecureTrust Corporation, CN=SecureTrust CA
10461620.10b0: supR3HardenedWinIsDesiredRootCA: Adding 0xabd0695c5d11d15e C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority - G2, OU=(c) 1998 VeriSign, Inc. - For authorized use only, OU=VeriSign Trust Network
10471620.10b0: supR3HardenedWinIsDesiredRootCA: Adding 0x6f2ebe0e24cfa600 OU=GlobalSign Root CA - R2, O=GlobalSign, CN=GlobalSign
10481620.10b0: supR3HardenedWinIsDesiredRootCA: Adding 0x14018a1bf29e595c C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority
10491620.10b0: supR3HardenedWinIsDesiredRootCA: Adding 0x9e5bc2d78b6a3636 C=ZA, ST=Western Cape, L=Cape Town, O=Thawte Consulting cc, OU=Certification Services Division, CN=Thawte Premium Server CA, Email=premium-server@thawte.com
10501620.10b0: supR3HardenedWinIsDesiredRootCA: Adding 0x7c4fd32ec1b1ce00 C=PL, O=Unizeto Sp. z o.o., CN=Certum CA
10511620.10b0: supR3HardenedWinIsDesiredRootCA: Adding 0xd4fbe673e5ccc600 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA
10521620.10b0: supR3HardenedWinIsDesiredRootCA: Adding 0x6e2ba21058eedf00 C=US, ST=UT, L=Salt Lake City, O=The USERTRUST Network, OU=http://www.usertrust.com, CN=UTN - DATACorp SGC
10531620.10b0: supR3HardenedWinIsDesiredRootCA: Adding 0xb28612a94b4dad00 O=Entrust.net, OU=www.entrust.net/CPS_2048 incorp. by ref. (limits liab.), OU=(c) 1999 Entrust.net Limited, CN=Entrust.net Certification Authority (2048)
10541620.10b0: supR3HardenedWinIsDesiredRootCA: Adding 0x357a29080824af00 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2006 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G5
10551620.10b0: supR3HardenedWinIsDesiredRootCA: Adding 0x59faf1086271bf00 C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com, Inc., CN=Go Daddy Root Certificate Authority - G2
10561620.10b0: supR3HardenedWinIsDesiredRootCA: Adding 0x466cbc09db88c100 C=IL, O=StartCom Ltd., OU=Secure Digital Certificate Signing, CN=StartCom Certification Authority
10571620.10b0: supR3HardenedWinIsDesiredRootCA: Adding 0x30669a4e82fa800 C=US, O=America Online Inc., CN=America Online Root Certification Authority 1
10581620.10b0: supR3HardenedWinIsDesiredRootCA: Adding 0x491857ead79dde00 C=US, O=The Go Daddy Group, Inc., OU=Go Daddy Class 2 Certification Authority
10591620.10b0: supR3HardenedWinIsDesiredRootCA: Adding 0xe66b56ffc86e50a4 C=ZA, ST=Western Cape, L=Cape Town, O=Thawte Consulting cc, OU=Certification Services Division, CN=Thawte Server CA, Email=server-certs@thawte.com
10601620.10b0: supR3HardenedWinIsDesiredRootCA: Adding 0x92ac5ed85c2d0e9b C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2007 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G4
10611620.10b0: supR3HardenedWinIsDesiredRootCA: Adding 0x8043e4ce150ead00 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID Root CA
10621620.10b0: supR3HardenedWinIsDesiredRootCA: Adding 0xa8b43f38c3f7b100 C=US, ST=UT, L=Salt Lake City, O=The USERTRUST Network, OU=http://www.usertrust.com, CN=UTN-USERFirst-Hardware
10631620.10b0: supR3HardenedWinIsDesiredRootCA: Adding 0xf2e6331af7b700 C=SE, O=AddTrust AB, OU=AddTrust External TTP Network, CN=AddTrust External CA Root
10641620.10b0: supR3HardenedWinRetrieveTrustedRootCAs: cAdded=39
10651620.10b0: SUPR3HardenedMain: Load Runtime...
10661620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
10671620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
10681620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ws2_32.dll'.
10691620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'rpcrt4.dll'.
10701620.10b0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll)WinVerifyTrust
10711620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
10721620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
10731620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
10741620.10b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
10751620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
10761620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
10771620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000003cc pwszName=\Device\HarddiskVolume2\Windows\System32\ws2_32.dll
10781620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00769d60
10791620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00769d60
10801620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2535224DB54945234E1A0C452639FCBB02F5F364
10811620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\ws2_32.dll'
10821620.10b0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
10831620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
10841620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'rpcrt4.dll'.
10851620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'nsi.dll'.
10861620.10b0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ws2_32.dll)WinVerifyTrust
10871620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
10881620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
10891620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
10901620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
10911620.10b0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll)WinVerifyTrust
10921620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
10931620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
10941620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
10951620.10b0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll)WinVerifyTrust
10961620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
10971620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
10981620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
10991620.10b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
11001620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
11011620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume2\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
11021620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000440 pwszName=\Device\HarddiskVolume2\Windows\System32\nsi.dll
11031620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00769d60
11041620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00769d60
11051620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B5C25EDD170A1CAACC3D49C508AB6F58BD6DE6E2
11061620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\nsi.dll'
11071620.10b0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
11081620.10b0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\nsi.dll)WinVerifyTrust
11091620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\nsi.dll
11101620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
11111620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
11121620.10b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
11131620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
11141620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
11151620.10b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
11161620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00767af4:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
11171620.10b0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
11181620.10b0: supR3HardenedDllNotificationCallback: load 592b0000 LB 0x0041f000 C:\Program Files\Oracle\VirtualBox\VBoxRT.dll [fFlags=0x0]
11191620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
11201620.10b0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
11211620.10b0: supR3HardenedDllNotificationCallback: load 5cb80000 LB 0x000bf000 C:\Program Files\Oracle\VirtualBox\MSVCR100.dll [fFlags=0x0]
11221620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
11231620.10b0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
11241620.10b0: supR3HardenedDllNotificationCallback: load 63de0000 LB 0x00069000 C:\Program Files\Oracle\VirtualBox\MSVCP100.dll [fFlags=0x0]
11251620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
11261620.10b0: supR3HardenedDllNotificationCallback: load 765f0000 LB 0x00035000 C:\Windows\system32\WS2_32.dll [fFlags=0x0]
11271620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
11281620.10b0: supR3HardenedDllNotificationCallback: load 77320000 LB 0x00006000 C:\Windows\system32\NSI.dll [fFlags=0x0]
11291620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\nsi.dll
11301620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
11311620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00723a04:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\ibm\gsk8\lib;C:\Program Files\ibm\gsk8\bin;C:\Program Files\IBM Informix Client SDK\bin;D:\app\c3p0i\product\11.2.0\client_2\bin;D:\app\c3p0i\product\11.2.0\client_1;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Bitvise SSH Client;C:\Program Files\Gow\bin;C:\Program Files\Microsoft SQL Server\80\Tools\Binn\;C:\Program Files\Sikuli X\libs;C:\Program Files\Java\jre6\\bin;C:\Program Files\OpenVPN\bin [calling]
11321620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=592b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11331620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
11341620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00723a04:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\ibm\gsk8\lib;C:\Program Files\ibm\gsk8\bin;C:\Program Files\IBM Informix Client SDK\bin;D:\app\c3p0i\product\11.2.0\client_2\bin;D:\app\c3p0i\product\11.2.0\client_1;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Bitvise SSH Client;C:\Program Files\Gow\bin;C:\Program Files\Microsoft SQL Server\80\Tools\Binn\;C:\Program Files\Sikuli X\libs;C:\Program Files\Java\jre6\\bin;C:\Program Files\OpenVPN\bin [calling]
11351620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=592b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11361620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
11371620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00723a04:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\ibm\gsk8\lib;C:\Program Files\ibm\gsk8\bin;C:\Program Files\IBM Informix Client SDK\bin;D:\app\c3p0i\product\11.2.0\client_2\bin;D:\app\c3p0i\product\11.2.0\client_1;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Bitvise SSH Client;C:\Program Files\Gow\bin;C:\Program Files\Microsoft SQL Server\80\Tools\Binn\;C:\Program Files\Sikuli X\libs;C:\Program Files\Java\jre6\\bin;C:\Program Files\OpenVPN\bin [calling]
11381620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=592b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11391620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
11401620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00723a04:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\ibm\gsk8\lib;C:\Program Files\ibm\gsk8\bin;C:\Program Files\IBM Informix Client SDK\bin;D:\app\c3p0i\product\11.2.0\client_2\bin;D:\app\c3p0i\product\11.2.0\client_1;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Bitvise SSH Client;C:\Program Files\Gow\bin;C:\Program Files\Microsoft SQL Server\80\Tools\Binn\;C:\Program Files\Sikuli X\libs;C:\Program Files\Java\jre6\\bin;C:\Program Files\OpenVPN\bin [calling]
11411620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=592b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11421620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
11431620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00723a04:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\ibm\gsk8\lib;C:\Program Files\ibm\gsk8\bin;C:\Program Files\IBM Informix Client SDK\bin;D:\app\c3p0i\product\11.2.0\client_2\bin;D:\app\c3p0i\product\11.2.0\client_1;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Bitvise SSH Client;C:\Program Files\Gow\bin;C:\Program Files\Microsoft SQL Server\80\Tools\Binn\;C:\Program Files\Sikuli X\libs;C:\Program Files\Java\jre6\\bin;C:\Program Files\OpenVPN\bin [calling]
11441620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=592b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11451620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
11461620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00723a04:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\ibm\gsk8\lib;C:\Program Files\ibm\gsk8\bin;C:\Program Files\IBM Informix Client SDK\bin;D:\app\c3p0i\product\11.2.0\client_2\bin;D:\app\c3p0i\product\11.2.0\client_1;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Bitvise SSH Client;C:\Program Files\Gow\bin;C:\Program Files\Microsoft SQL Server\80\Tools\Binn\;C:\Program Files\Sikuli X\libs;C:\Program Files\Java\jre6\\bin;C:\Program Files\OpenVPN\bin [calling]
11471620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=592b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11481620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=592b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11491620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=592b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11501620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=592b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11511620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=592b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11521620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=592b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11531620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=592b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11541620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=592b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11551620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
11561620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00723a04:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\ibm\gsk8\lib;C:\Program Files\ibm\gsk8\bin;C:\Program Files\IBM Informix Client SDK\bin;D:\app\c3p0i\product\11.2.0\client_2\bin;D:\app\c3p0i\product\11.2.0\client_1;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Bitvise SSH Client;C:\Program Files\Gow\bin;C:\Program Files\Microsoft SQL Server\80\Tools\Binn\;C:\Program Files\Sikuli X\libs;C:\Program Files\Java\jre6\\bin;C:\Program Files\OpenVPN\bin [calling]
11571620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=592b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11581620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=592b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11591620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=592b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11601620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=592b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11611620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=592b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11621620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=592b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11631620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=592b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11641620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=592b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11651620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=592b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11661620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=592b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11671620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=592b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11681620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=592b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11691620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=592b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11701620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=592b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11711620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=592b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11721620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=592b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11731620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
11741620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00723a04:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\ibm\gsk8\lib;C:\Program Files\ibm\gsk8\bin;C:\Program Files\IBM Informix Client SDK\bin;D:\app\c3p0i\product\11.2.0\client_2\bin;D:\app\c3p0i\product\11.2.0\client_1;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\Bitvise SSH Client;C:\Program Files\Gow\bin;C:\Program Files\Microsoft SQL Server\80\Tools\Binn\;C:\Program Files\Sikuli X\libs;C:\Program Files\Java\jre6\\bin;C:\Program Files\OpenVPN\bin [calling]
11751620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=592b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11761620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=592b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11771620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=592b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11781620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=592b0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11791620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll
11801620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00768f94:C:\Windows\system32 [calling]
11811620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=751d0000 'C:\Windows\system32\Wintrust.dll'
11821620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll
11831620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\crypt32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00768f94:C:\Windows\system32 [calling]
11841620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=752a0000 'C:\Windows\system32\crypt32.dll'
11851620.10b0: SUPR3HardenedMain: Load TrustedMain...
11861620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'opengl32.dll'.
11871620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
11881620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxvmm.dll'.
11891620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcp100.dll'.
11901620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msvcr100.dll'.
11911620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'qtcorevbox4.dll'.
11921620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'qtguivbox4.dll'.
11931620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'qtnetworkvbox4.dll'.
11941620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'qtopenglvbox4.dll'.
11951620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'user32.dll'.
11961620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'gdi32.dll'.
11971620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'advapi32.dll'.
11981620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'shell32.dll'.
11991620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'ole32.dll'.
12001620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #15 'oleaut32.dll'.
12011620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'comdlg32.dll'.
12021620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'winmm.dll'.
12031620.10b0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.dll)WinVerifyTrust
12041620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.dll
12051620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
12061620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
12071620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000480 pwszName=\Device\HarddiskVolume2\Windows\System32\winmm.dll
12081620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00769d60
12091620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00769d60
12101620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=0907A64D7756C59C69C1DFBD06460EC89D3A8FBD
12111620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\winmm.dll'
12121620.10b0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
12131620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
12141620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
12151620.10b0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\winmm.dll)WinVerifyTrust
12161620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\winmm.dll
12171620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comdlg32.dll'...
12181620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'comdlg32.dll' -> '\Device\HarddiskVolume2\Windows\System32\comdlg32.dll' [rcNtRedir=0xc0150008]
12191620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000460 pwszName=\Device\HarddiskVolume2\Windows\System32\comdlg32.dll
12201620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00769d60
12211620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00769d60
12221620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=1C456ACB19416C5E733133B4582891146F151614
12231620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\comdlg32.dll'
12241620.10b0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
12251620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
12261620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'shlwapi.dll'.
12271620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
12281620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'gdi32.dll'.
12291620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'comctl32.dll'.
12301620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'shell32.dll'.
12311620.10b0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\comdlg32.dll)WinVerifyTrust
12321620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\comdlg32.dll
12331620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
12341620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
12351620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000474 pwszName=\Device\HarddiskVolume2\Windows\System32\oleaut32.dll
12361620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00769d60
12371620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00769d60
12381620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=BCE31FDB944BBD2B4E378704B95BEA36085E5ADA
12391620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_2_for_KB3020338~31bf3856ad364e35~x86~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\oleaut32.dll'
12401620.10b0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
12411620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ole32.dll'.
12421620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
12431620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'rpcrt4.dll'.
12441620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'user32.dll'.
12451620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'gdi32.dll'.
12461620.10b0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\oleaut32.dll)WinVerifyTrust
12471620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
12481620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
12491620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
12501620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000048c pwszName=\Device\HarddiskVolume2\Windows\System32\ole32.dll
12511620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00769d60
12521620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00769d60
12531620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=07C15DE99041924EC7DED2E27632443249973ECA
12541620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\ole32.dll'
12551620.10b0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
12561620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
12571620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
12581620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'user32.dll'.
12591620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'rpcrt4.dll'.
12601620.10b0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ole32.dll)WinVerifyTrust
12611620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ole32.dll
12621620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
12631620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
12641620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000484 pwszName=\Device\HarddiskVolume2\Windows\System32\shell32.dll
12651620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00769d60
12661620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00769d60
12671620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=883446B1349BE3E16C87051B0AA3B54938105378
12681620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_2_for_KB3039066~31bf3856ad364e35~x86~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\shell32.dll'
12691620.10b0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
12701620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
12711620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #21 'shlwapi.dll'.
12721620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'user32.dll'.
12731620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #24 'gdi32.dll'.
12741620.10b0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\shell32.dll)WinVerifyTrust
12751620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\shell32.dll
12761620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
12771620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
12781620.10b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
12791620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
12801620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
12811620.10b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll
12821620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
12831620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
12841620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtopenglvbox4.dll'...
12851620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtopenglvbox4.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qtopenglvbox4.dll' [rcNtRedir=0xc0150008]
12861620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'opengl32.dll'.
12871620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
12881620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
12891620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qtguivbox4.dll'.
12901620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qtcorevbox4.dll'.
12911620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcr100.dll'.
12921620.10b0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll)WinVerifyTrust
12931620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll
12941620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtnetworkvbox4.dll'...
12951620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtnetworkvbox4.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qtnetworkvbox4.dll' [rcNtRedir=0xc0150008]
12961620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ws2_32.dll'.
12971620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'qtcorevbox4.dll'.
12981620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcr100.dll'.
12991620.10b0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtNetworkVBox4.dll)WinVerifyTrust
13001620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtNetworkVBox4.dll
13011620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtguivbox4.dll'...
13021620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtguivbox4.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qtguivbox4.dll' [rcNtRedir=0xc0150008]
13031620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
13041620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'comdlg32.dll'.
13051620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'oleaut32.dll'.
13061620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'imm32.dll'.
13071620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'winmm.dll'.
13081620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'winspool.drv'.
13091620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ole32.dll'.
13101620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'user32.dll'.
13111620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'advapi32.dll'.
13121620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'shell32.dll'.
13131620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'qtcorevbox4.dll'.
13141620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'msvcp100.dll'.
13151620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'msvcr100.dll'.
13161620.10b0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll)WinVerifyTrust
13171620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll
13181620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtcorevbox4.dll'...
13191620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtcorevbox4.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qtcorevbox4.dll' [rcNtRedir=0xc0150008]
13201620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
13211620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'ole32.dll'.
13221620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
13231620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ws2_32.dll'.
13241620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcp100.dll'.
13251620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcr100.dll'.
13261620.10b0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll)WinVerifyTrust
13271620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll
13281620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
13291620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
13301620.10b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
13311620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
13321620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
13331620.10b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
13341620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
13351620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
13361620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
13371620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrem.dll'.
13381620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
13391620.10b0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll)WinVerifyTrust
13401620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
13411620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
13421620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
13431620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
13441620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
13451620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000004bc pwszName=\Device\HarddiskVolume2\Windows\System32\opengl32.dll
13461620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00769d60
13471620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00769d60
13481620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=4C7570E385B8CF66CB40344231F3E0AA4189574F
13491620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\opengl32.dll'
13501620.10b0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
13511620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
13521620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
13531620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'gdi32.dll'.
13541620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'glu32.dll'.
13551620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ddraw.dll'.
13561620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'user32.dll'.
13571620.10b0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\opengl32.dll)WinVerifyTrust
13581620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\opengl32.dll
13591620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
13601620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
13611620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ddraw.dll'...
13621620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'ddraw.dll' -> '\Device\HarddiskVolume2\Windows\System32\ddraw.dll' [rcNtRedir=0xc0150008]
13631620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000004b0 pwszName=\Device\HarddiskVolume2\Windows\System32\ddraw.dll
13641620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00769d60
13651620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00769d60
13661620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=6D0AC3B30C2D6C734EBBA3E99BF60B93FDF28E33
13671620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\ddraw.dll'
13681620.10b0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
13691620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
13701620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
13711620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'dciman32.dll'.
13721620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
13731620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'setupapi.dll'.
13741620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'dwmapi.dll'.
13751620.10b0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ddraw.dll)WinVerifyTrust
13761620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ddraw.dll
13771620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'glu32.dll'...
13781620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'glu32.dll' -> '\Device\HarddiskVolume2\Windows\System32\glu32.dll' [rcNtRedir=0xc0150008]
13791620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000004b8 pwszName=\Device\HarddiskVolume2\Windows\System32\glu32.dll
13801620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00769d60
13811620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00769d60
13821620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=8AAE7D02045ADA954DBE714C716FEAB98D1A54F0
13831620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\glu32.dll'
13841620.10b0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
13851620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
13861620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'opengl32.dll'.
13871620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
13881620.10b0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\glu32.dll)WinVerifyTrust
13891620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\glu32.dll
13901620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
13911620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
13921620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
13931620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
13941620.10b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
13951620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
13961620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
13971620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
13981620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
13991620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrem.dll'...
14001620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrem.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrem.dll' [rcNtRedir=0xc0150008]
14011620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
14021620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
14031620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxvmm.dll'.
14041620.10b0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxREM.dll)WinVerifyTrust
14051620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxREM.dll
14061620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
14071620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
14081620.10b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
14091620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
14101620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
14111620.10b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
14121620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
14131620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
14141620.10b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
14151620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
14161620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
14171620.10b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
14181620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
14191620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
14201620.10b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
14211620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
14221620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
14231620.10b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
14241620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
14251620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
14261620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
14271620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
14281620.10b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
14291620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
14301620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
14311620.10b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
14321620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtcorevbox4.dll'...
14331620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtcorevbox4.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qtcorevbox4.dll' [rcNtRedir=0xc0150008]
14341620.10b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll
14351620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
14361620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
14371620.10b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
14381620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
14391620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
14401620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
14411620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
14421620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
14431620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
14441620.10b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
14451620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winspool.drv'...
14461620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'winspool.drv' -> '\Device\HarddiskVolume2\Windows\System32\winspool.drv' [rcNtRedir=0xc0150008]
14471620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000004d8 pwszName=\Device\HarddiskVolume2\Windows\System32\winspool.drv
14481620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00769d60
14491620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00769d60
14501620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B39657B6044CE5C98BB9FC443679CBDE0E6BE222
14511620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\winspool.drv'
14521620.10b0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
14531620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
14541620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
14551620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
14561620.10b0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\winspool.drv)WinVerifyTrust
14571620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\winspool.drv
14581620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
14591620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
14601620.10b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
14611620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
14621620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume2\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
14631620.10b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\imm32.dll
14641620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
14651620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
14661620.10b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
14671620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comdlg32.dll'...
14681620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'comdlg32.dll' -> '\Device\HarddiskVolume2\Windows\System32\comdlg32.dll' [rcNtRedir=0xc0150008]
14691620.10b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\comdlg32.dll
14701620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
14711620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
14721620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
14731620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
14741620.10b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
14751620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtcorevbox4.dll'...
14761620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtcorevbox4.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qtcorevbox4.dll' [rcNtRedir=0xc0150008]
14771620.10b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll
14781620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
14791620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
14801620.10b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
14811620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
14821620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
14831620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtcorevbox4.dll'...
14841620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtcorevbox4.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qtcorevbox4.dll' [rcNtRedir=0xc0150008]
14851620.10b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll
14861620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtguivbox4.dll'...
14871620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtguivbox4.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qtguivbox4.dll' [rcNtRedir=0xc0150008]
14881620.10b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll
14891620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
14901620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
14911620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
14921620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
14931620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
14941620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
14951620.10b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
14961620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
14971620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
14981620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
14991620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
15001620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
15011620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
15021620.10b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll
15031620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
15041620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
15051620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
15061620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
15071620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
15081620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
15091620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
15101620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
15111620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
15121620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
15131620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
15141620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
15151620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
15161620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
15171620.10b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll
15181620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
15191620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
15201620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
15211620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
15221620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
15231620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
15241620.10b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
15251620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
15261620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
15271620.10b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
15281620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comctl32.dll'...
15291620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'comctl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\comctl32.dll' [rcNtRedir=0x0]
15301620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000004dc pwszName=\Device\HarddiskVolume2\Windows\System32\comctl32.dll
15311620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00769d60
15321620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00769d60
15331620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B2DD5817E3C34BF2CE0D876EBC207250E2DB8A3A
15341620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_2_for_KB2864058~31bf3856ad364e35~x86~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\comctl32.dll'
15351620.10b0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
15361620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'advapi32.dll'.
15371620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
15381620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
15391620.10b0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\comctl32.dll)WinVerifyTrust
15401620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\comctl32.dll
15411620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
15421620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
15431620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
15441620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
15451620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
15461620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
15471620.10b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll
15481620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
15491620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
15501620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
15511620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
15521620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
15531620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
15541620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
15551620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
15561620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
15571620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
15581620.10b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll
15591620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
15601620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
15611620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
15621620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
15631620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
15641620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
15651620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
15661620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
15671620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
15681620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
15691620.10b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
15701620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
15711620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
15721620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
15731620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
15741620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
15751620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
15761620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
15771620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
15781620.10b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
15791620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
15801620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
15811620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dwmapi.dll'...
15821620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'dwmapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\dwmapi.dll' [rcNtRedir=0xc0150008]
15831620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000004d0 pwszName=\Device\HarddiskVolume2\Windows\System32\dwmapi.dll
15841620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00769d60
15851620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00769d60
15861620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2DD0519DFAD1ED741C9324879C92EC15A9FFB8D0
15871620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\dwmapi.dll'
15881620.10b0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
15891620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
15901620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
15911620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
15921620.10b0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\dwmapi.dll)WinVerifyTrust
15931620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\dwmapi.dll
15941620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
15951620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
15961620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000004e8 pwszName=\Device\HarddiskVolume2\Windows\System32\setupapi.dll
15971620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00769d60
15981620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00769d60
15991620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=07B90F6FCFF3E079727E8F6884115307C6E5BA41
16001620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\setupapi.dll'
16011620.10b0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
16021620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'cfgmgr32.dll'.
16031620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcrt.dll'.
16041620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'gdi32.dll'.
16051620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
16061620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'user32.dll'.
16071620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'oleaut32.dll'.
16081620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'devobj.dll'.
16091620.10b0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\setupapi.dll)WinVerifyTrust
16101620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\setupapi.dll
16111620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
16121620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
16131620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dciman32.dll'...
16141620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'dciman32.dll' -> '\Device\HarddiskVolume2\Windows\System32\dciman32.dll' [rcNtRedir=0xc0150008]
16151620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000004ec pwszName=\Device\HarddiskVolume2\Windows\System32\dciman32.dll
16161620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00769d60
16171620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00769d60
16181620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2209915514DA0567BF15C35F3296BEE011BE2E28
16191620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_2_for_KB3032323~31bf3856ad364e35~x86~~6.1.1.3.cat'; file='\Device\HarddiskVolume2\Windows\System32\dciman32.dll'
16201620.10b0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
16211620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
16221620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
16231620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
16241620.10b0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\dciman32.dll)WinVerifyTrust
16251620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\dciman32.dll
16261620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
16271620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
16281620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
16291620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
16301620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
16311620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
16321620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
16331620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
16341620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
16351620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
16361620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'devobj.dll'...
16371620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'devobj.dll' -> '\Device\HarddiskVolume2\Windows\System32\devobj.dll' [rcNtRedir=0xc0150008]
16381620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000004f4 pwszName=\Device\HarddiskVolume2\Windows\System32\devobj.dll
16391620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00769d60
16401620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00769d60
16411620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=EE1631BE6E86D9131380E981EC05320E6DF3FD3A
16421620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\devobj.dll'
16431620.10b0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
16441620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
16451620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'cfgmgr32.dll'.
16461620.10b0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\devobj.dll)WinVerifyTrust
16471620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\devobj.dll
16481620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
16491620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
16501620.10b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
16511620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
16521620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
16531620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
16541620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
16551620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
16561620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
16571620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
16581620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
16591620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
16601620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
16611620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000004fc pwszName=\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll
16621620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00769d60
16631620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00769d60
16641620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=A2D26C675A9F5FB0ABA919E9F71726151CB174F1
16651620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll'
16661620.10b0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
16671620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
16681620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'rpcrt4.dll'.
16691620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
16701620.10b0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll)WinVerifyTrust
16711620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll
16721620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
16731620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
16741620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
16751620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
16761620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
16771620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
16781620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
16791620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
16801620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
16811620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
16821620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
16831620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
16841620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
16851620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
16861620.10b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll
16871620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
16881620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
16891620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VirtualBox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00767af4:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
16901620.10b0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.dll
16911620.10b0: supR3HardenedDllNotificationCallback: load 77880000 LB 0x00772000 C:\Program Files\Oracle\VirtualBox\VirtualBox.dll [fFlags=0x0]
16921620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.dll
16931620.10b0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
16941620.10b0: supR3HardenedDllNotificationCallback: load 5cc90000 LB 0x000c8000 C:\Windows\system32\OPENGL32.dll [fFlags=0x0]
16951620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
16961620.10b0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\glu32.dll
16971620.10b0: supR3HardenedDllNotificationCallback: load 67d90000 LB 0x00022000 C:\Windows\system32\GLU32.dll [fFlags=0x0]
16981620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\glu32.dll
16991620.10b0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ddraw.dll
17001620.10b0: supR3HardenedDllNotificationCallback: load 6b9c0000 LB 0x000e7000 C:\Windows\system32\DDRAW.dll [fFlags=0x0]
17011620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ddraw.dll
17021620.10b0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dciman32.dll
17031620.10b0: supR3HardenedDllNotificationCallback: load 6b9b0000 LB 0x00006000 C:\Windows\system32\DCIMAN32.dll [fFlags=0x0]
17041620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dciman32.dll
17051620.10b0: supR3HardenedDllNotificationCallback: load 76a00000 LB 0x0019d000 C:\Windows\system32\SETUPAPI.dll [fFlags=0x0]
17061620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\setupapi.dll
17071620.10b0: supR3HardenedDllNotificationCallback: load 75480000 LB 0x00027000 C:\Windows\system32\CFGMGR32.dll [fFlags=0x0]
17081620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll
17091620.10b0: supR3HardenedDllNotificationCallback: load 76830000 LB 0x0008f000 C:\Windows\system32\OLEAUT32.dll [fFlags=0x0]
17101620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
17111620.10b0: supR3HardenedDllNotificationCallback: load 77060000 LB 0x0015c000 C:\Windows\system32\ole32.dll [fFlags=0x0]
17121620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
17131620.10b0: supR3HardenedDllNotificationCallback: load 75460000 LB 0x00012000 C:\Windows\system32\DEVOBJ.dll [fFlags=0x0]
17141620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\devobj.dll
17151620.10b0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dwmapi.dll
17161620.10b0: supR3HardenedDllNotificationCallback: load 732b0000 LB 0x00013000 C:\Windows\system32\dwmapi.dll [fFlags=0x0]
17171620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dwmapi.dll
17181620.10b0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
17191620.10b0: supR3HardenedDllNotificationCallback: load 5c970000 LB 0x00205000 C:\Program Files\Oracle\VirtualBox\VBoxVMM.dll [fFlags=0x0]
17201620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
17211620.10b0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxREM.dll
17221620.10b0: supR3HardenedDllNotificationCallback: load 6ac00000 LB 0x00007000 C:\Program Files\Oracle\VirtualBox\VBoxREM.dll [fFlags=0x0]
17231620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxREM.dll
17241620.10b0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll
17251620.10b0: supR3HardenedDllNotificationCallback: load 53140000 LB 0x00275000 C:\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll [fFlags=0x0]
17261620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll
17271620.10b0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll
17281620.10b0: supR3HardenedDllNotificationCallback: load 64bf0000 LB 0x0080c000 C:\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll [fFlags=0x0]
17291620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll
17301620.10b0: supR3HardenedDllNotificationCallback: load 76380000 LB 0x0007b000 C:\Windows\system32\COMDLG32.dll [fFlags=0x0]
17311620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\comdlg32.dll
17321620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'advapi32.dll'.
17331620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
17341620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
17351620.10b0: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18201_none_ec80f00e8593ece5\comctl32.dll)
17361620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18201_none_ec80f00e8593ece5\comctl32.dll
17371620.10b0: supR3HardenedDllNotificationCallback: load 6bb70000 LB 0x00084000 C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18201_none_ec80f00e8593ece5\COMCTL32.dll [fFlags=0x0]
17381620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18201_none_ec80f00e8593ece5\comctl32.dll [avoiding WinVerifyTrust]
17391620.10b0: supR3HardenedDllNotificationCallback: load 754d0000 LB 0x00c4b000 C:\Windows\system32\SHELL32.dll [fFlags=0x0]
17401620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
17411620.10b0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
17421620.10b0: supR3HardenedDllNotificationCallback: load 70ef0000 LB 0x00032000 C:\Windows\system32\WINMM.dll [fFlags=0x0]
17431620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
17441620.10b0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winspool.drv
17451620.10b0: supR3HardenedDllNotificationCallback: load 6b8c0000 LB 0x00051000 C:\Windows\system32\WINSPOOL.DRV [fFlags=0x0]
17461620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winspool.drv
17471620.10b0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtNetworkVBox4.dll
17481620.10b0: supR3HardenedDllNotificationCallback: load 5c880000 LB 0x000e2000 C:\Program Files\Oracle\VirtualBox\QtNetworkVBox4.dll [fFlags=0x0]
17491620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtNetworkVBox4.dll
17501620.10b0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll
17511620.10b0: supR3HardenedDllNotificationCallback: load 5c640000 LB 0x000c1000 C:\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll [fFlags=0x0]
17521620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll
17531620.10b0: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18201_none_ec80f00e8593ece5\comctl32.dll'.
17541620.10b0: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18201_none_ec80f00e8593ece5\comctl32.dll' [rescheduled]
17551620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\imm32.dll
17561620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
17571620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
17581620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
17591620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
17601620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
17611620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
17621620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\imm32.dll (Input=imm32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=020ccde4:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
17631620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=76630000 'C:\Windows\system32\imm32.dll'
17641620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77880000 'C:\Program Files\Oracle\VirtualBox\VirtualBox.dll'
17651620.10b0: SUPR3HardenedMain: Calling TrustedMain (77881da0)...
17661620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
17671620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\winmm.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00767af4:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
17681620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=70ef0000 'C:\Windows\system32\winmm.dll'
17691620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000058c pwszName=\Device\HarddiskVolume2\Windows\System32\uxtheme.dll
17701620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00769d60
17711620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00769d60
17721620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=BCFB3B3EDEC8C54A3B95DACAFC19DCB9EA6969BD
17731620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\uxtheme.dll'
17741620.10b0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
17751620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
17761620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
17771620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'gdi32.dll'.
17781620.10b0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\uxtheme.dll)WinVerifyTrust
17791620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
17801620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
17811620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
17821620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
17831620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
17841620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
17851620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
17861620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=020b9c74:C:\Windows\system32;C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
17871620.10b0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
17881620.10b0: supR3HardenedDllNotificationCallback: load 73870000 LB 0x00040000 C:\Windows\system32\uxtheme.dll [fFlags=0x0]
17891620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
17901620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=73870000 'C:\Windows\system32\uxtheme.dll'
17911620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
17921620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=020b9c74:C:\Windows\system32;C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
17931620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=73870000 'C:\Windows\system32\uxtheme.dll'
17941620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
17951620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=020b9c74:C:\Windows\system32;C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
17961620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=73870000 'C:\Windows\system32\uxtheme.dll'
17971620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
17981620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=020b9c74:C:\Windows\system32;C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
17991620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=73870000 'C:\Windows\system32\uxtheme.dll'
18001620.10b0: \Device\HarddiskVolume2\Program Files\RocketDock\RocketDock.dll: Owner is administrators group.
18011620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000005ac pwszName=\Device\HarddiskVolume2\Program Files\RocketDock\RocketDock.dll
18021620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00769d60
18031620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00769d60
18041620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=81273098809FCD31253B469D42950416B2780B67
18051620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: Retrying with fresh context (CryptCATAdminEnumCatalogFromHash -> 1168; iCat=0x0)
18061620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: New context 00769d60
18071620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00769d60
18081620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=81273098809FCD31253B469D42950416B2780B67
18091620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: CryptCATAdminEnumCatalogFromHash failed ERRROR_NOT_FOUND (1168)
18101620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: New context 0076a1e0
18111620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0076a1e0
18121620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=32 wszDigest=43128DD7DB22429861BB1E0BA660C8C629F8E5E634B742B77A5E3ECEA2CF2D60
18131620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: CryptCATAdminEnumCatalogFromHash failed ERRROR_NOT_FOUND (1168)
18141620.10b0: supR3HardNtViCallWinVerifyTrustCatFile -> -22900 (org 22900)
18151620.10b0: supHardenedWinVerifyImageByHandle: -> -22900 (\Device\HarddiskVolume2\Program Files\RocketDock\RocketDock.dll)WinVerifyTrust
18161620.10b0: Error (rc=0):
18171620.10b0: supR3HardenedScreenImage/LdrLoadDll: rc=Unknown Status -22900 (0xffffa68c) fImage=1 fProtect=0x0 fAccess=0x0 \Device\HarddiskVolume2\Program Files\RocketDock\RocketDock.dll: Not signed.
18181620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\RocketDock\RocketDock.dll
18191620.10b0: Error (rc=0):
18201620.10b0: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\Program Files\RocketDock\RocketDock.dll' (C:\Program Files\RocketDock\RocketDock.dll): rcNt=0xc0000190
18211620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Program Files\RocketDock\RocketDock.dll'
18221620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status -22900 (0xffffa68c)) on \Device\HarddiskVolume2\Program Files\RocketDock\RocketDock.dll
18231620.10b0: Error (rc=0):
18241620.10b0: supR3HardenedScreenImage/LdrLoadDll: cached rc=Unknown Status -22900 (0xffffa68c) fImage=1 fProtect=0x0 fAccess=0x0 cHits=1 \Device\HarddiskVolume2\Program Files\RocketDock\RocketDock.dll
18251620.10b0: Error (rc=0):
18261620.10b0: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\Program Files\RocketDock\RocketDock.dll' (C:\Program Files\RocketDock\RocketDock.dll): rcNt=0xc0000190
18271620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Program Files\RocketDock\RocketDock.dll'
18281620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dwmapi.dll
18291620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\dwmapi.dll (Input=dwmapi.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0076784c:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
18301620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=732b0000 'C:\Windows\system32\dwmapi.dll'
18311620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cryptbase.dll
18321620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTBASE.dll (Input=CRYPTBASE.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0076784c:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
18331620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=750d0000 'C:\Windows\system32\CRYPTBASE.dll'
18341620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status -22900 (0xffffa68c)) on \Device\HarddiskVolume2\Program Files\RocketDock\RocketDock.dll
18351620.10b0: Error (rc=0):
18361620.10b0: supR3HardenedScreenImage/LdrLoadDll: cached rc=Unknown Status -22900 (0xffffa68c) fImage=1 fProtect=0x0 fAccess=0x0 cHits=2 \Device\HarddiskVolume2\Program Files\RocketDock\RocketDock.dll
18371620.10b0: Error (rc=0):
18381620.10b0: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\Program Files\RocketDock\RocketDock.dll' (C:\Program Files\RocketDock\RocketDock.dll): rcNt=0xc0000190
18391620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Program Files\RocketDock\RocketDock.dll'
18401620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
18411620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0076784c:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
18421620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=754d0000 'C:\Windows\system32\shell32.dll'
18431620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll
18441620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0076784c:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
18451620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=76670000 'C:\Windows\system32\kernel32.dll'
18461620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
18471620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0076784c:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
18481620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=73870000 'C:\Windows\system32\uxtheme.dll'
18491620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
18501620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0076784c:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
18511620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=73870000 'C:\Windows\system32\uxtheme.dll'
18521620.10b0: supR3HardenedMonitor_LdrLoadDll: error opening 'C:\Windows\system32\wintab32.dll': 0 (NtPath=\??\C:\Windows\system32\wintab32.dll; Input=C:\Windows\system32\wintab32.dll; rcNtGetDll=0x0
18531620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wintab32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0076784c:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
18541620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000135 'C:\Windows\system32\wintab32.dll'
18551620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=76450000 'C:\Windows\system32\user32.dll'
18561620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
18571620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0076784c:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
18581620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=73870000 'C:\Windows\system32\uxtheme.dll'
18591620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=76450000 'C:\Windows\system32\user32.dll'
18601620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=76780000 'C:\Windows\system32\advapi32.dll'
18611620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\userenv.dll
18621620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\userenv.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0076784c:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
18631620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=754b0000 'C:\Windows\system32\userenv.dll'
18641620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll
18651620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0076784c:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
18661620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=76670000 'C:\Windows\system32\kernel32.dll'
18671620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000003c4 pwszName=\Device\HarddiskVolume2\Windows\System32\clbcatq.dll
18681620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00769d60
18691620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00769d60
18701620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B560B8A95D275325C41DE5897E348BE60192127E
18711620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\clbcatq.dll'
18721620.10b0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
18731620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
18741620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'ole32.dll'.
18751620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
18761620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
18771620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
18781620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'rpcrt4.dll'.
18791620.10b0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\clbcatq.dll)WinVerifyTrust
18801620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\clbcatq.dll
18811620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
18821620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
18831620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
18841620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
18851620.10b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
18861620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
18871620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
18881620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
18891620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
18901620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
18911620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
18921620.10b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
18931620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
18941620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
18951620.10b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
18961620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CLBCatQ.DLL (Input=CLBCatQ.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0076784c:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
18971620.10b0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\clbcatq.dll
18981620.10b0: supR3HardenedDllNotificationCallback: load 76970000 LB 0x00083000 C:\Windows\system32\CLBCatQ.DLL [fFlags=0x0]
18991620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\clbcatq.dll
19001620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=76970000 'C:\Windows\system32\CLBCatQ.DLL'
19011620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=76780000 'C:\Windows\system32\ADVAPI32.dll'
19021620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cryptsp.dll
19031620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTSP.dll (Input=CRYPTSP.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00767d14:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
19041620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=74bf0000 'C:\Windows\system32\CRYPTSP.dll'
19051620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000003b0 pwszName=\Device\HarddiskVolume2\Windows\System32\RpcRtRemote.dll
19061620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00769d60
19071620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00769d60
19081620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=A397FD418538BAA1CB6D18B348447E74938F66EA
19091620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\RpcRtRemote.dll'
19101620.10b0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
19111620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'rpcrt4.dll'.
19121620.10b0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\RpcRtRemote.dll)WinVerifyTrust
19131620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\RpcRtRemote.dll
19141620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
19151620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
19161620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\RpcRtRemote.dll (Input=RpcRtRemote.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0076795c:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
19171620.10b0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\RpcRtRemote.dll
19181620.10b0: supR3HardenedDllNotificationCallback: load 75140000 LB 0x0000e000 C:\Windows\system32\RpcRtRemote.dll [fFlags=0x0]
19191620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\RpcRtRemote.dll
19201620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=75140000 'C:\Windows\system32\RpcRtRemote.dll'
19211620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000005c4 pwszName=\Device\HarddiskVolume2\Windows\System32\msiltcfg.dll
19221620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00769d60
19231620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00769d60
19241620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=AAE8C73E319858922705A3CB3C7B14413A48F03C
19251620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntph.cat'; file='\Device\HarddiskVolume2\Windows\System32\msiltcfg.dll'
19261620.10b0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
19271620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
19281620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
19291620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'version.dll'.
19301620.10b0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\msiltcfg.dll)WinVerifyTrust
19311620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msiltcfg.dll
19321620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'version.dll'...
19331620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'version.dll' -> '\Device\HarddiskVolume2\Windows\System32\version.dll' [rcNtRedir=0xc0150008]
19341620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000005c8 pwszName=\Device\HarddiskVolume2\Windows\System32\version.dll
19351620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00769d60
19361620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00769d60
19371620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=87F58E3B93CDFEB987BC8B5880D3F0366E3D8203
19381620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\version.dll'
19391620.10b0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
19401620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
19411620.10b0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\version.dll)WinVerifyTrust
19421620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\version.dll
19431620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
19441620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
19451620.10b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
19461620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
19471620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
19481620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
19491620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
19501620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\msiltcfg.dll (Input=msiltcfg.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00767054:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
19511620.10b0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msiltcfg.dll
19521620.10b0: supR3HardenedDllNotificationCallback: load 68dd0000 LB 0x00007000 C:\Windows\system32\msiltcfg.dll [fFlags=0x0]
19531620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msiltcfg.dll
19541620.10b0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\version.dll
19551620.10b0: supR3HardenedDllNotificationCallback: load 74660000 LB 0x00009000 C:\Windows\system32\VERSION.dll [fFlags=0x0]
19561620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\version.dll
19571620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=68dd0000 'C:\Windows\system32\msiltcfg.dll'
19581620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=76450000 'C:\Windows\system32\user32.dll'
19591620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000005dc pwszName=\Device\HarddiskVolume2\Windows\System32\msi.dll
19601620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00769d60
19611620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00769d60
19621620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=07FF9EA1F30B580AAE670896F5C0AC3E635F6C88
19631620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_40_for_KB3008627~31bf3856ad364e35~x86~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\Windows\System32\msi.dll'
19641620.10b0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
19651620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
19661620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
19671620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
19681620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'shell32.dll'.
19691620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'gdi32.dll'.
19701620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
19711620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'shlwapi.dll'.
19721620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'ole32.dll'.
19731620.10b0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\msi.dll)WinVerifyTrust
19741620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msi.dll
19751620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
19761620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
19771620.10b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
19781620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
19791620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
19801620.10b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll
19811620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
19821620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
19831620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
19841620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
19851620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
19861620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
19871620.10b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
19881620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
19891620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
19901620.10b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll
19911620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
19921620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
19931620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
19941620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
19951620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\msi.dll (Input=msi.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00767054:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
19961620.10b0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msi.dll
19971620.10b0: supR3HardenedDllNotificationCallback: load 6ec90000 LB 0x00245000 C:\Windows\system32\msi.dll [fFlags=0x0]
19981620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msi.dll
19991620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6ec90000 'C:\Windows\system32\msi.dll'
20001620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msiltcfg.dll
20011620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\msiltcfg.dll (Input=msiltcfg.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00767054:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
20021620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=68dd0000 'C:\Windows\system32\msiltcfg.dll'
20031620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=76400000 'C:\Windows\system32\gdi32.dll'
20041620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status -22900 (0xffffa68c)) on \Device\HarddiskVolume2\Program Files\RocketDock\RocketDock.dll
20051620.10b0: Error (rc=0):
20061620.10b0: supR3HardenedScreenImage/LdrLoadDll: cached rc=Unknown Status -22900 (0xffffa68c) fImage=1 fProtect=0x0 fAccess=0x0 cHits=3 \Device\HarddiskVolume2\Program Files\RocketDock\RocketDock.dll
20071620.10b0: Error (rc=0):
20081620.10b0: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\Program Files\RocketDock\RocketDock.dll' (C:\Program Files\RocketDock\RocketDock.dll): rcNt=0xc0000190
20091620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Program Files\RocketDock\RocketDock.dll'
20101620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status -22900 (0xffffa68c)) on \Device\HarddiskVolume2\Program Files\RocketDock\RocketDock.dll
20111620.10b0: Error (rc=0):
20121620.10b0: supR3HardenedScreenImage/LdrLoadDll: cached rc=Unknown Status -22900 (0xffffa68c) fImage=1 fProtect=0x0 fAccess=0x0 cHits=4 \Device\HarddiskVolume2\Program Files\RocketDock\RocketDock.dll
20131620.10b0: Error (rc=0):
20141620.10b0: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\Program Files\RocketDock\RocketDock.dll' (C:\Program Files\RocketDock\RocketDock.dll): rcNt=0xc0000190
20151620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Program Files\RocketDock\RocketDock.dll'
20161620.10b0: supR3HardenedMonitor_LdrLoadDll: error opening 'C:\Windows\system32\wintab32.dll': 0 (NtPath=\??\C:\Windows\system32\wintab32.dll; Input=C:\Windows\system32\wintab32.dll; rcNtGetDll=0x0
20171620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wintab32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=007677c4:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
20181620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000135 'C:\Windows\system32\wintab32.dll'
20191620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
20201620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=007677c4:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
20211620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=754d0000 'C:\Windows\system32\shell32.dll'
20221620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
20231620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=007677c4:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
20241620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=754d0000 'C:\Windows\system32\shell32.dll'
20251620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
20261620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=007677c4:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
20271620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=754d0000 'C:\Windows\system32\shell32.dll'
20281620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=754d0000 'C:\Windows\system32\shell32.dll'
20291620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=754d0000 'C:\Windows\system32\shell32.dll'
20301620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=754d0000 'C:\Windows\system32\shell32.dll'
20311620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=76450000 'C:\Windows\system32\user32.dll'
20321620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status -22900 (0xffffa68c)) on \Device\HarddiskVolume2\Program Files\RocketDock\RocketDock.dll
20331620.10b0: Error (rc=0):
20341620.10b0: supR3HardenedScreenImage/LdrLoadDll: cached rc=Unknown Status -22900 (0xffffa68c) fImage=1 fProtect=0x0 fAccess=0x0 cHits=5 \Device\HarddiskVolume2\Program Files\RocketDock\RocketDock.dll
20351620.10b0: Error (rc=0):
20361620.10b0: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\Program Files\RocketDock\RocketDock.dll' (C:\Program Files\RocketDock\RocketDock.dll): rcNt=0xc0000190
20371620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Program Files\RocketDock\RocketDock.dll'
20381620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=76780000 'C:\Windows\system32\ADVAPI32.dll'
20391620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status -22900 (0xffffa68c)) on \Device\HarddiskVolume2\Program Files\RocketDock\RocketDock.dll
20401620.10b0: Error (rc=0):
20411620.10b0: supR3HardenedScreenImage/LdrLoadDll: cached rc=Unknown Status -22900 (0xffffa68c) fImage=1 fProtect=0x0 fAccess=0x0 cHits=6 \Device\HarddiskVolume2\Program Files\RocketDock\RocketDock.dll
20421620.10b0: Error (rc=0):
20431620.10b0: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\Program Files\RocketDock\RocketDock.dll' (C:\Program Files\RocketDock\RocketDock.dll): rcNt=0xc0000190
20441620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Program Files\RocketDock\RocketDock.dll'
20451620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status -22900 (0xffffa68c)) on \Device\HarddiskVolume2\Program Files\RocketDock\RocketDock.dll
20461620.10b0: Error (rc=0):
20471620.10b0: supR3HardenedScreenImage/LdrLoadDll: cached rc=Unknown Status -22900 (0xffffa68c) fImage=1 fProtect=0x0 fAccess=0x0 cHits=7 \Device\HarddiskVolume2\Program Files\RocketDock\RocketDock.dll
20481620.10b0: Error (rc=0):
20491620.10b0: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\Program Files\RocketDock\RocketDock.dll' (C:\Program Files\RocketDock\RocketDock.dll): rcNt=0xc0000190
20501620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Program Files\RocketDock\RocketDock.dll'
20511620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
20521620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ole32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=007677c4:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
20531620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77060000 'C:\Windows\system32\ole32.dll'
20541620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status -22900 (0xffffa68c)) on \Device\HarddiskVolume2\Program Files\RocketDock\RocketDock.dll
20551620.10b0: Error (rc=0):
20561620.10b0: supR3HardenedScreenImage/LdrLoadDll: cached rc=Unknown Status -22900 (0xffffa68c) fImage=1 fProtect=0x0 fAccess=0x0 cHits=8 \Device\HarddiskVolume2\Program Files\RocketDock\RocketDock.dll
20571620.10b0: Error (rc=0):
20581620.10b0: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\Program Files\RocketDock\RocketDock.dll' (C:\Program Files\RocketDock\RocketDock.dll): rcNt=0xc0000190
20591620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Program Files\RocketDock\RocketDock.dll'
20601620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
20611620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ole32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=026dbe14:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
20621620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=77060000 'C:\Windows\system32\ole32.dll'
20631620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msctf.dll
20641620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\MSCTF.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=020ba954:C:\Windows\system32;C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
20651620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=76520000 'C:\Windows\system32\MSCTF.dll'
20661620.10b0: \Device\HarddiskVolume2\Program Files\Internet Download Manager\idmmkb.dll: Owner is administrators group.
20671620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
20681620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
20691620.10b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcrt.dll'.
20701620.10b0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Internet Download Manager\idmmkb.dll)WinVerifyTrust
20711620.10b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Internet Download Manager\idmmkb.dll
20721620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
20731620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
20741620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
20751620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
20761620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
20771620.10b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
20781620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Internet Download Manager\idmmkb.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00810974:C:\Program Files\Internet Download Manager;C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
20791620.10b0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Internet Download Manager\idmmkb.dll
20801620.10b0: supR3HardenedDllNotificationCallback: load 10000000 LB 0x00008000 C:\Program Files\Internet Download Manager\idmmkb.dll [fFlags=0x0]
20811620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Internet Download Manager\idmmkb.dll
20821620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=10000000 'C:\Program Files\Internet Download Manager\idmmkb.dll'
20831620.10b0: supR3HardenedMonitor_LdrLoadDll: 'C:\Windows\system32\comctl32.dll' -> 'C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18201_none_ec80f00e8593ece5\comctl32.dll' [redir]
20841620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18201_none_ec80f00e8593ece5\comctl32.dll [redoing WinVerifyTrust]
20851620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000004e0 pwszName=\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18201_none_ec80f00e8593ece5\comctl32.dll
20861620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00769d60
20871620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00769d60
20881620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B2DD5817E3C34BF2CE0D876EBC207250E2DB8A3A
20891620.10b0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_2_for_KB2864058~31bf3856ad364e35~x86~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18201_none_ec80f00e8593ece5\comctl32.dll'
20901620.10b0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
20911620.10b0: supR3HardenedScreenImage/LdrLoadDll: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18201_none_ec80f00e8593ece5\comctl32.dll'
20921620.10b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18201_none_ec80f00e8593ece5\comctl32.dll (Input=C:\Windows\system32\comctl32.dll, rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=026dbe14:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32 [calling]
20931620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=6bb70000 'C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18201_none_ec80f00e8593ece5\comctl32.dll'
20941620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status -22900 (0xffffa68c)) on \Device\HarddiskVolume2\Program Files\RocketDock\RocketDock.dll
20951620.10b0: Error (rc=0):
20961620.10b0: supR3HardenedScreenImage/LdrLoadDll: cached rc=Unknown Status -22900 (0xffffa68c) fImage=1 fProtect=0x0 fAccess=0x0 cHits=16 \Device\HarddiskVolume2\Program Files\RocketDock\RocketDock.dll
20971620.10b0: Error (rc=0):
20981620.10b0: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\Program Files\RocketDock\RocketDock.dll' (C:\Program Files\RocketDock\RocketDock.dll): rcNt=0xc0000190
20991620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Program Files\RocketDock\RocketDock.dll'
21001620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status -22900 (0xffffa68c)) on \Device\HarddiskVolume2\Program Files\RocketDock\RocketDock.dll
21011620.10b0: Error (rc=0):
21021620.10b0: supR3HardenedScreenImage/LdrLoadDll: cached rc=Unknown Status -22900 (0xffffa68c) fImage=1 fProtect=0x0 fAccess=0x0 cHits=32 \Device\HarddiskVolume2\Program Files\RocketDock\RocketDock.dll
21031620.10b0: Error (rc=0):
21041620.10b0: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\Program Files\RocketDock\RocketDock.dll' (C:\Program Files\RocketDock\RocketDock.dll): rcNt=0xc0000190
21051620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Program Files\RocketDock\RocketDock.dll'
21061620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status -22900 (0xffffa68c)) on \Device\HarddiskVolume2\Program Files\RocketDock\RocketDock.dll
21071620.10b0: Error (rc=0):
21081620.10b0: supR3HardenedScreenImage/LdrLoadDll: cached rc=Unknown Status -22900 (0xffffa68c) fImage=1 fProtect=0x0 fAccess=0x0 cHits=64 \Device\HarddiskVolume2\Program Files\RocketDock\RocketDock.dll
21091620.10b0: Error (rc=0):
21101620.10b0: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\Program Files\RocketDock\RocketDock.dll' (C:\Program Files\RocketDock\RocketDock.dll): rcNt=0xc0000190
21111620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Program Files\RocketDock\RocketDock.dll'
21121620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status -22900 (0xffffa68c)) on \Device\HarddiskVolume2\Program Files\RocketDock\RocketDock.dll
21131620.10b0: Error (rc=0):
21141620.10b0: supR3HardenedScreenImage/LdrLoadDll: cached rc=Unknown Status -22900 (0xffffa68c) fImage=1 fProtect=0x0 fAccess=0x0 cHits=128 \Device\HarddiskVolume2\Program Files\RocketDock\RocketDock.dll
21151620.10b0: Error (rc=0):
21161620.10b0: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\Program Files\RocketDock\RocketDock.dll' (C:\Program Files\RocketDock\RocketDock.dll): rcNt=0xc0000190
21171620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Program Files\RocketDock\RocketDock.dll'
21181620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status -22900 (0xffffa68c)) on \Device\HarddiskVolume2\Program Files\RocketDock\RocketDock.dll
21191620.10b0: Error (rc=0):
21201620.10b0: supR3HardenedScreenImage/LdrLoadDll: cached rc=Unknown Status -22900 (0xffffa68c) fImage=1 fProtect=0x0 fAccess=0x0 cHits=256 \Device\HarddiskVolume2\Program Files\RocketDock\RocketDock.dll
21211620.10b0: Error (rc=0):
21221620.10b0: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\Program Files\RocketDock\RocketDock.dll' (C:\Program Files\RocketDock\RocketDock.dll): rcNt=0xc0000190
21231620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Program Files\RocketDock\RocketDock.dll'
21241620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=76450000 'C:\Windows\system32\User32.dll'
21251620.10b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status -22900 (0xffffa68c)) on \Device\HarddiskVolume2\Program Files\RocketDock\RocketDock.dll
21261620.10b0: Error (rc=0):
21271620.10b0: supR3HardenedScreenImage/LdrLoadDll: cached rc=Unknown Status -22900 (0xffffa68c) fImage=1 fProtect=0x0 fAccess=0x0 cHits=512 \Device\HarddiskVolume2\Program Files\RocketDock\RocketDock.dll
21281620.10b0: Error (rc=0):
21291620.10b0: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\Program Files\RocketDock\RocketDock.dll' (C:\Program Files\RocketDock\RocketDock.dll): rcNt=0xc0000190
21301620.10b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Program Files\RocketDock\RocketDock.dll'
21311620.10b0: Terminating the normal way: rcExit=1
21323c4.d74: supR3HardNtChildWaitFor[2]: Quitting: ExitCode=0x1 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 9512 ms, the end);
2133a80.1634: supR3HardNtChildWaitFor[1]: Quitting: ExitCode=0x1 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 9926 ms, the end);

© 2024 Oracle Support Privacy / Do Not Sell My Info Terms of Use Trademark Policy Automated Access Etiquette