VirtualBox

Ticket #14556: VBoxStartup.log

File VBoxStartup.log, 326.9 KB (added by TronID, 9 years ago)
Line 
11dcc.1798: Log file opened: 5.0.2r102096 g_hStartupLog=0000000000000018 g_uNtVerCombined=0x63258000
21dcc.1798: \SystemRoot\System32\ntdll.dll:
31dcc.1798: CreationTime: 2014-03-18T10:14:36.739928900Z
41dcc.1798: LastWriteTime: 2014-03-18T10:14:36.943083200Z
51dcc.1798: ChangeTime: 2015-08-19T07:06:29.144737500Z
61dcc.1798: FileAttributes: 0x20
71dcc.1798: Size: 0x1a5d10
81dcc.1798: NT Headers: 0xe8
91dcc.1798: Timestamp: 0x530895af
101dcc.1798: Machine: 0x8664 - amd64
111dcc.1798: Timestamp: 0x530895af
121dcc.1798: Image Version: 6.3
131dcc.1798: SizeOfImage: 0x1aa000 (1744896)
141dcc.1798: Resource Dir: 0x145000 LB 0x62450
151dcc.1798: ProductName: Microsoft® Windows® Operating System
161dcc.1798: ProductVersion: 6.3.9600.17031
171dcc.1798: FileVersion: 6.3.9600.17031 (winblue_gdr.140221-1952)
181dcc.1798: FileDescription: NT Layer DLL
191dcc.1798: \SystemRoot\System32\kernel32.dll:
201dcc.1798: CreationTime: 2014-05-15T02:05:12.262422000Z
211dcc.1798: LastWriteTime: 2014-05-15T02:05:12.264422100Z
221dcc.1798: ChangeTime: 2015-08-27T15:32:12.520359400Z
231dcc.1798: FileAttributes: 0x20
241dcc.1798: Size: 0x13b3c0
251dcc.1798: NT Headers: 0xe8
261dcc.1798: Timestamp: 0x532a419c
271dcc.1798: Machine: 0x8664 - amd64
281dcc.1798: Timestamp: 0x532a419c
291dcc.1798: Image Version: 6.3
301dcc.1798: SizeOfImage: 0x13a000 (1286144)
311dcc.1798: Resource Dir: 0x12a000 LB 0x520
321dcc.1798: ProductName: Microsoft® Windows® Operating System
331dcc.1798: ProductVersion: 6.3.9600.17056
341dcc.1798: FileVersion: 6.3.9600.17056 (winblue_gdr.140319-1520)
351dcc.1798: FileDescription: Windows NT BASE API Client DLL
361dcc.1798: \SystemRoot\System32\KernelBase.dll:
371dcc.1798: CreationTime: 2014-05-15T02:05:12.106301200Z
381dcc.1798: LastWriteTime: 2014-05-15T02:05:12.107301500Z
391dcc.1798: ChangeTime: 2015-08-27T15:33:18.448366100Z
401dcc.1798: FileAttributes: 0x20
411dcc.1798: Size: 0x10f9d8
421dcc.1798: NT Headers: 0xf0
431dcc.1798: Timestamp: 0x532954fb
441dcc.1798: Machine: 0x8664 - amd64
451dcc.1798: Timestamp: 0x532954fb
461dcc.1798: Image Version: 6.3
471dcc.1798: SizeOfImage: 0x10f000 (1110016)
481dcc.1798: Resource Dir: 0x10a000 LB 0x3530
491dcc.1798: ProductName: Microsoft® Windows® Operating System
501dcc.1798: ProductVersion: 6.3.9600.17055
511dcc.1798: FileVersion: 6.3.9600.17055 (winblue_gdr.140318-1651)
521dcc.1798: FileDescription: Windows NT BASE API Client DLL
531dcc.1798: \SystemRoot\System32\apisetschema.dll:
541dcc.1798: CreationTime: 2013-08-22T12:13:09.745625900Z
551dcc.1798: LastWriteTime: 2013-08-22T12:35:12.091034400Z
561dcc.1798: ChangeTime: 2015-08-19T18:20:31.227258500Z
571dcc.1798: FileAttributes: 0x20
581dcc.1798: Size: 0x11360
591dcc.1798: NT Headers: 0xd0
601dcc.1798: Timestamp: 0x52160049
611dcc.1798: Machine: 0x8664 - amd64
621dcc.1798: Timestamp: 0x52160049
631dcc.1798: Image Version: 6.3
641dcc.1798: SizeOfImage: 0x13000 (77824)
651dcc.1798: Resource Dir: 0x11000 LB 0x3f8
661dcc.1798: ProductName: Microsoft® Windows® Operating System
671dcc.1798: ProductVersion: 6.3.9600.16384
681dcc.1798: FileVersion: 6.3.9600.16384 (winblue_rtm.130821-1623)
691dcc.1798: FileDescription: ApiSet Schema DLL
701dcc.1798: NtOpenDirectoryObject failed on \Driver: 0xc0000022
711dcc.1798: supR3HardenedWinFindAdversaries: 0x100
721dcc.1798: \SystemRoot\System32\drivers\avgrkx64.sys:
731dcc.1798: CreationTime: 2015-03-20T05:18:18.000000000Z
741dcc.1798: LastWriteTime: 2015-03-20T05:18:18.000000000Z
751dcc.1798: ChangeTime: 2015-08-19T04:34:54.848403100Z
761dcc.1798: FileAttributes: 0x20
771dcc.1798: Size: 0x9fe0
781dcc.1798: NT Headers: 0xe8
791dcc.1798: Timestamp: 0x550bf3e7
801dcc.1798: Machine: 0x8664 - amd64
811dcc.1798: Timestamp: 0x550bf3e7
821dcc.1798: Image Version: 6.2
831dcc.1798: SizeOfImage: 0xa000 (40960)
841dcc.1798: Resource Dir: 0x9000 LB 0x510
851dcc.1798: ProductName: AVG Internet Security
861dcc.1798: ProductVersion: 15.0.0.5908
871dcc.1798: FileVersion: 15.0.0.5908
881dcc.1798: SpecialBuild: AvCompile_2015_0320_111532(5908), SVNRev 18c4578e1c294cb8006a179b834157155925d4af (release/SmallUpdate2015-04_beta), av
891dcc.1798: PrivateBuild: x64 Release_Unicode_DRIVER
901dcc.1798: FileDescription: AVG Anti-Rootkit Driver
911dcc.1798: \SystemRoot\System32\drivers\avgmfx64.sys:
921dcc.1798: CreationTime: 2015-08-04T04:32:32.000000000Z
931dcc.1798: LastWriteTime: 2015-08-04T04:32:32.000000000Z
941dcc.1798: ChangeTime: 2015-08-27T14:54:10.509488100Z
951dcc.1798: FileAttributes: 0x20
961dcc.1798: Size: 0x3d3b0
971dcc.1798: NT Headers: 0xe0
981dcc.1798: Timestamp: 0x55c086ac
991dcc.1798: Machine: 0x8664 - amd64
1001dcc.1798: Timestamp: 0x55c086ac
1011dcc.1798: Image Version: 6.2
1021dcc.1798: SizeOfImage: 0x3e000 (253952)
1031dcc.1798: Resource Dir: 0x3c000 LB 0x52c
1041dcc.1798: ProductName: AVG Internet Security
1051dcc.1798: ProductVersion: 15.0.0.6132
1061dcc.1798: FileVersion: 15.0.0.6132
1071dcc.1798: SpecialBuild: AvCompile_2015_0804_112815(6132), SVNRev cbac1c769cb9b6888db1f1065b4133bf3c9ce40f (release/SmallUpdate2015-08_beta), av
1081dcc.1798: PrivateBuild: x64 Release_Unicode_DRIVER
1091dcc.1798: FileDescription: AVG Resident Shield Minifilter Driver
1101dcc.1798: \SystemRoot\System32\drivers\avgidsdrivera.sys:
1111dcc.1798: CreationTime: 2015-08-19T04:52:30.000000000Z
1121dcc.1798: LastWriteTime: 2015-08-19T04:52:30.000000000Z
1131dcc.1798: ChangeTime: 2015-08-27T14:54:13.654218400Z
1141dcc.1798: FileAttributes: 0x20
1151dcc.1798: Size: 0x4c7b0
1161dcc.1798: NT Headers: 0xe8
1171dcc.1798: Timestamp: 0x55d451da
1181dcc.1798: Machine: 0x8664 - amd64
1191dcc.1798: Timestamp: 0x55d451da
1201dcc.1798: Image Version: 6.2
1211dcc.1798: SizeOfImage: 0x53000 (339968)
1221dcc.1798: Resource Dir: 0x51000 LB 0x554
1231dcc.1798: ProductName: AVG Internet Security
1241dcc.1798: ProductVersion: 15.0.0.6137
1251dcc.1798: FileVersion: 15.0.0.6137
1261dcc.1798: SpecialBuild: AvCompile_2015_0819_113418(6137), SVNRev 7ade868631072664eb184732ae422a4307e58f68 (release/SmallUpdate2015-08_release), av
1271dcc.1798: PrivateBuild: x64 Release_Unicode_DRIVER
1281dcc.1798: FileDescription: AVG IDS Application Activity Monitor Driver.
1291dcc.1798: \SystemRoot\System32\drivers\avgidsha.sys:
1301dcc.1798: CreationTime: 2015-08-19T04:53:56.000000000Z
1311dcc.1798: LastWriteTime: 2015-08-19T04:53:56.000000000Z
1321dcc.1798: ChangeTime: 2015-08-27T14:54:13.507210600Z
1331dcc.1798: FileAttributes: 0x20
1341dcc.1798: Size: 0x48bb0
1351dcc.1798: NT Headers: 0xd8
1361dcc.1798: Timestamp: 0x55d45230
1371dcc.1798: Machine: 0x8664 - amd64
1381dcc.1798: Timestamp: 0x55d45230
1391dcc.1798: Image Version: 6.2
1401dcc.1798: SizeOfImage: 0x49000 (299008)
1411dcc.1798: Resource Dir: 0x47000 LB 0x548
1421dcc.1798: ProductName: AVG Internet Security
1431dcc.1798: ProductVersion: 15.0.0.6137
1441dcc.1798: FileVersion: 15.0.0.6137
1451dcc.1798: SpecialBuild: AvCompile_2015_0819_113418(6137), SVNRev 7ade868631072664eb184732ae422a4307e58f68 (release/SmallUpdate2015-08_release), av
1461dcc.1798: PrivateBuild: x64 Release_Unicode_DRIVER
1471dcc.1798: FileDescription: AVG Application Activity Monitor Helper Driver
1481dcc.1798: \SystemRoot\System32\drivers\avgloga.sys:
1491dcc.1798: CreationTime: 2015-05-07T06:50:22.000000000Z
1501dcc.1798: LastWriteTime: 2015-05-07T06:50:22.000000000Z
1511dcc.1798: ChangeTime: 2015-08-19T04:34:46.033632900Z
1521dcc.1798: FileAttributes: 0x20
1531dcc.1798: Size: 0x5c5e0
1541dcc.1798: NT Headers: 0xf0
1551dcc.1798: Timestamp: 0x554b5179
1561dcc.1798: Machine: 0x8664 - amd64
1571dcc.1798: Timestamp: 0x554b5179
1581dcc.1798: Image Version: 6.2
1591dcc.1798: SizeOfImage: 0x5b000 (372736)
1601dcc.1798: Resource Dir: 0x59000 LB 0x4ec
1611dcc.1798: ProductName: AVG Internet Security
1621dcc.1798: ProductVersion: 15.0.0.5957
1631dcc.1798: FileVersion: 15.0.0.5957
1641dcc.1798: SpecialBuild: AvCompile_2015_0507_134328(5957), SVNRev bcddc515e1405c8e35481b16de334020e451ec3e (release/HotFix2015-05), av
1651dcc.1798: PrivateBuild: x64 Release_Unicode_DRIVER
1661dcc.1798: FileDescription: AVG Logging Driver
1671dcc.1798: \SystemRoot\System32\drivers\avgldx64.sys:
1681dcc.1798: CreationTime: 2015-06-16T08:55:04.000000000Z
1691dcc.1798: LastWriteTime: 2015-06-16T08:55:04.000000000Z
1701dcc.1798: ChangeTime: 2015-08-19T04:34:54.973401800Z
1711dcc.1798: FileAttributes: 0x20
1721dcc.1798: Size: 0x3f3e0
1731dcc.1798: NT Headers: 0xe0
1741dcc.1798: Timestamp: 0x55802aaf
1751dcc.1798: Machine: 0x8664 - amd64
1761dcc.1798: Timestamp: 0x55802aaf
1771dcc.1798: Image Version: 6.2
1781dcc.1798: SizeOfImage: 0x42000 (270336)
1791dcc.1798: Resource Dir: 0x40000 LB 0x50c
1801dcc.1798: ProductName: AVG Internet Security
1811dcc.1798: ProductVersion: 15.0.0.6055
1821dcc.1798: FileVersion: 15.0.0.6055
1831dcc.1798: SpecialBuild: AvCompile_2015_0616_154836(6055), SVNRev 309d50c06d2885375935ac1c0a79cdb255cb7045 (release/SmallUpdate2015-06_beta), av
1841dcc.1798: PrivateBuild: x64 Release_Unicode_DRIVER
1851dcc.1798: FileDescription: AVG AVI Loader Driver
1861dcc.1798: \SystemRoot\System32\drivers\avgdiska.sys:
1871dcc.1798: CreationTime: 2015-03-11T05:16:06.000000000Z
1881dcc.1798: LastWriteTime: 2015-03-11T05:16:06.000000000Z
1891dcc.1798: ChangeTime: 2015-08-19T04:34:57.366208700Z
1901dcc.1798: FileAttributes: 0x20
1911dcc.1798: Size: 0x27be0
1921dcc.1798: NT Headers: 0xe0
1931dcc.1798: Timestamp: 0x550015e3
1941dcc.1798: Machine: 0x8664 - amd64
1951dcc.1798: Timestamp: 0x550015e3
1961dcc.1798: Image Version: 6.2
1971dcc.1798: SizeOfImage: 0x29000 (167936)
1981dcc.1798: Resource Dir: 0x27000 LB 0x4e0
1991dcc.1798: ProductName: AVG Internet Security
2001dcc.1798: ProductVersion: 15.0.0.5902
2011dcc.1798: FileVersion: 15.0.0.5902
2021dcc.1798: SpecialBuild: AvCompile_2015_0311_110513(5902), SVNRev d57888a6d0541615b2b2c643813a0b67abc3acba (av/devel), av
2031dcc.1798: PrivateBuild: x64 Release_Unicode_DRIVER
2041dcc.1798: FileDescription: AVG File Vault Driver
2051dcc.1798: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox'
2061dcc.1798: Calling main()
2071dcc.1798: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
2081dcc.1798: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox'
2091dcc.1798: SUPR3HardenedMain: Respawn #1
2101dcc.1798: System32: \Device\HarddiskVolume4\Windows\System32
2111dcc.1798: WinSxS: \Device\HarddiskVolume4\Windows\WinSxS
2121dcc.1798: KnownDllPath: C:\Windows\system32
2131dcc.1798: '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
2141dcc.1798: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe)
2151dcc.1798: supR3HardNtEnableThreadCreation:
2161dcc.1798: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007fffe9de6a4c pvNtTerminateThread=00007fffe9e2b0b0
2171dcc.1798: supR3HardenedWinDoReSpawn(1): New child c8c.ec4 [kernel32].
2181dcc.1798: supR3HardNtChildGatherData: PebBaseAddress=00007ff7cedfb000 cbPeb=0x388
2191dcc.1798: supR3HardNtPuChFindNtdll: uNtDllParentAddr=00007fffe9d90000 uNtDllChildAddr=00007fffe9d90000
2201dcc.1798: supR3HardenedWinSetupChildInit: uLdrInitThunk=00007fffe9de6a4c
2211dcc.1798: supR3HardenedWinSetupChildInit: Start child.
2221dcc.1798: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
2231dcc.1798: supR3HardNtChildPurify: Startup delay kludge #1/0: 513 ms, 58 sleeps
2241dcc.1798: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
2251dcc.1798: *0000000000000000-ffffffffffc9ffff 0x0001/0x0000 0x0000000
2261dcc.1798: *0000000000360000-000000000033ffff 0x0004/0x0004 0x0020000
2271dcc.1798: *0000000000380000-0000000000370fff 0x0002/0x0002 0x0040000
2281dcc.1798: 000000000038f000-000000000038dfff 0x0001/0x0000 0x0000000
2291dcc.1798: *0000000000390000-0000000000293fff 0x0000/0x0004 0x0020000
2301dcc.1798: 000000000048c000-0000000000488fff 0x0104/0x0004 0x0020000
2311dcc.1798: 000000000048f000-000000000048dfff 0x0004/0x0004 0x0020000
2321dcc.1798: *0000000000490000-000000000048bfff 0x0002/0x0002 0x0040000
2331dcc.1798: 0000000000494000-0000000000487fff 0x0001/0x0000 0x0000000
2341dcc.1798: *00000000004a0000-000000000049dfff 0x0004/0x0004 0x0020000
2351dcc.1798: 00000000004a2000-ffffffff80963fff 0x0001/0x0000 0x0000000
2361dcc.1798: *000000007ffe0000-000000007ffdefff 0x0002/0x0002 0x0020000
2371dcc.1798: 000000007ffe1000-000000007ffd1fff 0x0000/0x0002 0x0020000
2381dcc.1798: 000000007fff0000-ffff80093120ffff 0x0001/0x0000 0x0000000
2391dcc.1798: *00007ff7cedd0000-00007ff7cedacfff 0x0002/0x0002 0x0040000
2401dcc.1798: 00007ff7cedf3000-00007ff7cedeafff 0x0001/0x0000 0x0000000
2411dcc.1798: *00007ff7cedfb000-00007ff7cedf9fff 0x0004/0x0004 0x0020000
2421dcc.1798: 00007ff7cedfc000-00007ff7cedf9fff 0x0001/0x0000 0x0000000
2431dcc.1798: *00007ff7cedfe000-00007ff7cedfbfff 0x0004/0x0004 0x0020000
2441dcc.1798: 00007ff7cee00000-00007ff7ce39ffff 0x0001/0x0000 0x0000000
2451dcc.1798: *00007ff7cf860000-00007ff7cf860fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
2461dcc.1798: 00007ff7cf861000-00007ff7cf8e6fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
2471dcc.1798: 00007ff7cf8e7000-00007ff7cf8e7fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
2481dcc.1798: 00007ff7cf8e8000-00007ff7cf931fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
2491dcc.1798: 00007ff7cf932000-00007ff7cf932fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
2501dcc.1798: 00007ff7cf933000-00007ff7cf933fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
2511dcc.1798: 00007ff7cf934000-00007ff7cf935fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
2521dcc.1798: 00007ff7cf936000-00007ff7cf936fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
2531dcc.1798: 00007ff7cf937000-00007ff7cf937fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
2541dcc.1798: 00007ff7cf938000-00007ff7cf93bfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
2551dcc.1798: 00007ff7cf93c000-00007ff7cf985fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
2561dcc.1798: 00007ff7cf986000-00007fefb557bfff 0x0001/0x0000 0x0000000
2571dcc.1798: *00007fffe9d90000-00007fffe9d90fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
2581dcc.1798: 00007fffe9d91000-00007fffe9eb9fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
2591dcc.1798: 00007fffe9eba000-00007fffe9ec2fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
2601dcc.1798: 00007fffe9ec3000-00007fffe9ecffff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
2611dcc.1798: 00007fffe9ed0000-00007fffe9ed0fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
2621dcc.1798: 00007fffe9ed1000-00007fffe9ed1fff 0x0010/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
2631dcc.1798: 00007fffe9ed2000-00007fffe9f39fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
2641dcc.1798: 00007fffe9f3a000-00007fffd3e93fff 0x0001/0x0000 0x0000000
2651dcc.1798: *00007ffffffe0000-00007ffffffcffff 0x0001/0x0002 0x0020000
2661dcc.1798: VirtualBox.exe: timestamp 0x55ccc4d5 (rc=VINF_SUCCESS)
2671dcc.1798: '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
2681dcc.1798: '\Device\HarddiskVolume4\Windows\System32\ntdll.dll' has no imports
2691dcc.1798: supR3HardNtChildPurify: Done after 572 ms and 0 fixes (loop #0).
270c8c.ec4: Log file opened: 5.0.2r102096 g_hStartupLog=0000000000000004 g_uNtVerCombined=0x63258000
271c8c.ec4: supR3HardenedVmProcessInit: uNtDllAddr=00007fffe9d90000
272c8c.ec4: ntdll.dll: timestamp 0x530895af (rc=VINF_SUCCESS)
273c8c.ec4: New simple heap: #1 00000000005b0000 LB 0x400000 (for 1744896 allocation)
2741dcc.1798: supR3HardNtEnableThreadCreation:
275c8c.ec4: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox'
276c8c.ec4: System32: \Device\HarddiskVolume4\Windows\System32
277c8c.ec4: WinSxS: \Device\HarddiskVolume4\Windows\WinSxS
278c8c.ec4: KnownDllPath: C:\Windows\system32
279c8c.ec4: supR3HardenedVmProcessInit: Opening vboxdrv stub...
280c8c.ec4: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
281c8c.ec4: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
282c8c.ec4: Registered Dll notification callback with NTDLL.
283c8c.ec4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\kernel32.dll)
284c8c.ec4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\kernel32.dll
285c8c.ec4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\KERNEL32.DLL (Input=KERNEL32.DLL, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000801:<flags> [calling]
286c8c.ec4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
287c8c.ec4: supR3HardenedDllNotificationCallback: load 00007fffe5ec0000 LB 0x0010f000 C:\Windows\system32\KERNELBASE.dll [fFlags=0x0]
288c8c.ec4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\KernelBase.dll)
289c8c.ec4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\KernelBase.dll
290c8c.ec4: supR3HardenedDllNotificationCallback: load 00007fffe6f30000 LB 0x0013a000 C:\Windows\system32\KERNEL32.DLL [fFlags=0x0]
291c8c.ec4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
292c8c.ec4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6f30000 'C:\Windows\system32\KERNEL32.DLL'
293c8c.ec4: supR3HardenedDllNotificationCallback: load 00007ff7cf860000 LB 0x00126000 C:\Program Files\Oracle\VirtualBox\VirtualBox.exe [fFlags=0x0]
294c8c.ec4: '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
295c8c.ec4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe)
296c8c.ec4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
297c8c.ec4: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007fffe9de6a4c pvNtTerminateThread=00007fffe9e2b0b0
2981dcc.1798: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 124 ms.
299c8c.ec4: \SystemRoot\System32\ntdll.dll:
300c8c.ec4: CreationTime: 2014-03-18T10:14:36.739928900Z
301c8c.ec4: LastWriteTime: 2014-03-18T10:14:36.943083200Z
302c8c.ec4: ChangeTime: 2015-08-19T07:06:29.144737500Z
303c8c.ec4: FileAttributes: 0x20
304c8c.ec4: Size: 0x1a5d10
305c8c.ec4: NT Headers: 0xe8
306c8c.ec4: Timestamp: 0x530895af
307c8c.ec4: Machine: 0x8664 - amd64
308c8c.ec4: Timestamp: 0x530895af
309c8c.ec4: Image Version: 6.3
310c8c.ec4: SizeOfImage: 0x1aa000 (1744896)
311c8c.ec4: Resource Dir: 0x145000 LB 0x62450
312c8c.ec4: ProductName: Microsoft® Windows® Operating System
313c8c.ec4: ProductVersion: 6.3.9600.17031
314c8c.ec4: FileVersion: 6.3.9600.17031 (winblue_gdr.140221-1952)
315c8c.ec4: FileDescription: NT Layer DLL
316c8c.ec4: \SystemRoot\System32\kernel32.dll:
317c8c.ec4: CreationTime: 2014-05-15T02:05:12.262422000Z
318c8c.ec4: LastWriteTime: 2014-05-15T02:05:12.264422100Z
319c8c.ec4: ChangeTime: 2015-08-27T15:32:12.520359400Z
320c8c.ec4: FileAttributes: 0x20
321c8c.ec4: Size: 0x13b3c0
322c8c.ec4: NT Headers: 0xe8
323c8c.ec4: Timestamp: 0x532a419c
324c8c.ec4: Machine: 0x8664 - amd64
325c8c.ec4: Timestamp: 0x532a419c
326c8c.ec4: Image Version: 6.3
327c8c.ec4: SizeOfImage: 0x13a000 (1286144)
328c8c.ec4: Resource Dir: 0x12a000 LB 0x520
329c8c.ec4: ProductName: Microsoft® Windows® Operating System
330c8c.ec4: ProductVersion: 6.3.9600.17056
331c8c.ec4: FileVersion: 6.3.9600.17056 (winblue_gdr.140319-1520)
332c8c.ec4: FileDescription: Windows NT BASE API Client DLL
333c8c.ec4: \SystemRoot\System32\KernelBase.dll:
334c8c.ec4: CreationTime: 2014-05-15T02:05:12.106301200Z
335c8c.ec4: LastWriteTime: 2014-05-15T02:05:12.107301500Z
336c8c.ec4: ChangeTime: 2015-08-27T15:33:18.448366100Z
337c8c.ec4: FileAttributes: 0x20
338c8c.ec4: Size: 0x10f9d8
339c8c.ec4: NT Headers: 0xf0
340c8c.ec4: Timestamp: 0x532954fb
341c8c.ec4: Machine: 0x8664 - amd64
342c8c.ec4: Timestamp: 0x532954fb
343c8c.ec4: Image Version: 6.3
344c8c.ec4: SizeOfImage: 0x10f000 (1110016)
345c8c.ec4: Resource Dir: 0x10a000 LB 0x3530
346c8c.ec4: ProductName: Microsoft® Windows® Operating System
347c8c.ec4: ProductVersion: 6.3.9600.17055
348c8c.ec4: FileVersion: 6.3.9600.17055 (winblue_gdr.140318-1651)
349c8c.ec4: FileDescription: Windows NT BASE API Client DLL
350c8c.ec4: \SystemRoot\System32\apisetschema.dll:
351c8c.ec4: CreationTime: 2013-08-22T12:13:09.745625900Z
352c8c.ec4: LastWriteTime: 2013-08-22T12:35:12.091034400Z
353c8c.ec4: ChangeTime: 2015-08-19T18:20:31.227258500Z
354c8c.ec4: FileAttributes: 0x20
355c8c.ec4: Size: 0x11360
356c8c.ec4: NT Headers: 0xd0
357c8c.ec4: Timestamp: 0x52160049
358c8c.ec4: Machine: 0x8664 - amd64
359c8c.ec4: Timestamp: 0x52160049
360c8c.ec4: Image Version: 6.3
361c8c.ec4: SizeOfImage: 0x13000 (77824)
362c8c.ec4: Resource Dir: 0x11000 LB 0x3f8
363c8c.ec4: ProductName: Microsoft® Windows® Operating System
364c8c.ec4: ProductVersion: 6.3.9600.16384
365c8c.ec4: FileVersion: 6.3.9600.16384 (winblue_rtm.130821-1623)
366c8c.ec4: FileDescription: ApiSet Schema DLL
367c8c.ec4: NtOpenDirectoryObject failed on \Driver: 0xc0000022
368c8c.ec4: supR3HardenedWinFindAdversaries: 0x100
369c8c.ec4: \SystemRoot\System32\drivers\avgrkx64.sys:
370c8c.ec4: CreationTime: 2015-03-20T05:18:18.000000000Z
371c8c.ec4: LastWriteTime: 2015-03-20T05:18:18.000000000Z
372c8c.ec4: ChangeTime: 2015-08-19T04:34:54.848403100Z
373c8c.ec4: FileAttributes: 0x20
374c8c.ec4: Size: 0x9fe0
375c8c.ec4: NT Headers: 0xe8
376c8c.ec4: Timestamp: 0x550bf3e7
377c8c.ec4: Machine: 0x8664 - amd64
378c8c.ec4: Timestamp: 0x550bf3e7
379c8c.ec4: Image Version: 6.2
380c8c.ec4: SizeOfImage: 0xa000 (40960)
381c8c.ec4: Resource Dir: 0x9000 LB 0x510
382c8c.ec4: ProductName: AVG Internet Security
383c8c.ec4: ProductVersion: 15.0.0.5908
384c8c.ec4: FileVersion: 15.0.0.5908
385c8c.ec4: SpecialBuild: AvCompile_2015_0320_111532(5908), SVNRev 18c4578e1c294cb8006a179b834157155925d4af (release/SmallUpdate2015-04_beta), av
386c8c.ec4: PrivateBuild: x64 Release_Unicode_DRIVER
387c8c.ec4: FileDescription: AVG Anti-Rootkit Driver
388c8c.ec4: \SystemRoot\System32\drivers\avgmfx64.sys:
389c8c.ec4: CreationTime: 2015-08-04T04:32:32.000000000Z
390c8c.ec4: LastWriteTime: 2015-08-04T04:32:32.000000000Z
391c8c.ec4: ChangeTime: 2015-08-27T14:54:10.509488100Z
392c8c.ec4: FileAttributes: 0x20
393c8c.ec4: Size: 0x3d3b0
394c8c.ec4: NT Headers: 0xe0
395c8c.ec4: Timestamp: 0x55c086ac
396c8c.ec4: Machine: 0x8664 - amd64
397c8c.ec4: Timestamp: 0x55c086ac
398c8c.ec4: Image Version: 6.2
399c8c.ec4: SizeOfImage: 0x3e000 (253952)
400c8c.ec4: Resource Dir: 0x3c000 LB 0x52c
401c8c.ec4: ProductName: AVG Internet Security
402c8c.ec4: ProductVersion: 15.0.0.6132
403c8c.ec4: FileVersion: 15.0.0.6132
404c8c.ec4: SpecialBuild: AvCompile_2015_0804_112815(6132), SVNRev cbac1c769cb9b6888db1f1065b4133bf3c9ce40f (release/SmallUpdate2015-08_beta), av
405c8c.ec4: PrivateBuild: x64 Release_Unicode_DRIVER
406c8c.ec4: FileDescription: AVG Resident Shield Minifilter Driver
407c8c.ec4: \SystemRoot\System32\drivers\avgidsdrivera.sys:
408c8c.ec4: CreationTime: 2015-08-19T04:52:30.000000000Z
409c8c.ec4: LastWriteTime: 2015-08-19T04:52:30.000000000Z
410c8c.ec4: ChangeTime: 2015-08-27T14:54:13.654218400Z
411c8c.ec4: FileAttributes: 0x20
412c8c.ec4: Size: 0x4c7b0
413c8c.ec4: NT Headers: 0xe8
414c8c.ec4: Timestamp: 0x55d451da
415c8c.ec4: Machine: 0x8664 - amd64
416c8c.ec4: Timestamp: 0x55d451da
417c8c.ec4: Image Version: 6.2
418c8c.ec4: SizeOfImage: 0x53000 (339968)
419c8c.ec4: Resource Dir: 0x51000 LB 0x554
420c8c.ec4: ProductName: AVG Internet Security
421c8c.ec4: ProductVersion: 15.0.0.6137
422c8c.ec4: FileVersion: 15.0.0.6137
423c8c.ec4: SpecialBuild: AvCompile_2015_0819_113418(6137), SVNRev 7ade868631072664eb184732ae422a4307e58f68 (release/SmallUpdate2015-08_release), av
424c8c.ec4: PrivateBuild: x64 Release_Unicode_DRIVER
425c8c.ec4: FileDescription: AVG IDS Application Activity Monitor Driver.
426c8c.ec4: \SystemRoot\System32\drivers\avgidsha.sys:
427c8c.ec4: CreationTime: 2015-08-19T04:53:56.000000000Z
428c8c.ec4: LastWriteTime: 2015-08-19T04:53:56.000000000Z
429c8c.ec4: ChangeTime: 2015-08-27T14:54:13.507210600Z
430c8c.ec4: FileAttributes: 0x20
431c8c.ec4: Size: 0x48bb0
432c8c.ec4: NT Headers: 0xd8
433c8c.ec4: Timestamp: 0x55d45230
434c8c.ec4: Machine: 0x8664 - amd64
435c8c.ec4: Timestamp: 0x55d45230
436c8c.ec4: Image Version: 6.2
437c8c.ec4: SizeOfImage: 0x49000 (299008)
438c8c.ec4: Resource Dir: 0x47000 LB 0x548
439c8c.ec4: ProductName: AVG Internet Security
440c8c.ec4: ProductVersion: 15.0.0.6137
441c8c.ec4: FileVersion: 15.0.0.6137
442c8c.ec4: SpecialBuild: AvCompile_2015_0819_113418(6137), SVNRev 7ade868631072664eb184732ae422a4307e58f68 (release/SmallUpdate2015-08_release), av
443c8c.ec4: PrivateBuild: x64 Release_Unicode_DRIVER
444c8c.ec4: FileDescription: AVG Application Activity Monitor Helper Driver
445c8c.ec4: \SystemRoot\System32\drivers\avgloga.sys:
446c8c.ec4: CreationTime: 2015-05-07T06:50:22.000000000Z
447c8c.ec4: LastWriteTime: 2015-05-07T06:50:22.000000000Z
448c8c.ec4: ChangeTime: 2015-08-19T04:34:46.033632900Z
449c8c.ec4: FileAttributes: 0x20
450c8c.ec4: Size: 0x5c5e0
451c8c.ec4: NT Headers: 0xf0
452c8c.ec4: Timestamp: 0x554b5179
453c8c.ec4: Machine: 0x8664 - amd64
454c8c.ec4: Timestamp: 0x554b5179
455c8c.ec4: Image Version: 6.2
456c8c.ec4: SizeOfImage: 0x5b000 (372736)
457c8c.ec4: Resource Dir: 0x59000 LB 0x4ec
458c8c.ec4: ProductName: AVG Internet Security
459c8c.ec4: ProductVersion: 15.0.0.5957
460c8c.ec4: FileVersion: 15.0.0.5957
461c8c.ec4: SpecialBuild: AvCompile_2015_0507_134328(5957), SVNRev bcddc515e1405c8e35481b16de334020e451ec3e (release/HotFix2015-05), av
462c8c.ec4: PrivateBuild: x64 Release_Unicode_DRIVER
463c8c.ec4: FileDescription: AVG Logging Driver
464c8c.ec4: \SystemRoot\System32\drivers\avgldx64.sys:
465c8c.ec4: CreationTime: 2015-06-16T08:55:04.000000000Z
466c8c.ec4: LastWriteTime: 2015-06-16T08:55:04.000000000Z
467c8c.ec4: ChangeTime: 2015-08-19T04:34:54.973401800Z
468c8c.ec4: FileAttributes: 0x20
469c8c.ec4: Size: 0x3f3e0
470c8c.ec4: NT Headers: 0xe0
471c8c.ec4: Timestamp: 0x55802aaf
472c8c.ec4: Machine: 0x8664 - amd64
473c8c.ec4: Timestamp: 0x55802aaf
474c8c.ec4: Image Version: 6.2
475c8c.ec4: SizeOfImage: 0x42000 (270336)
476c8c.ec4: Resource Dir: 0x40000 LB 0x50c
477c8c.ec4: ProductName: AVG Internet Security
478c8c.ec4: ProductVersion: 15.0.0.6055
479c8c.ec4: FileVersion: 15.0.0.6055
480c8c.ec4: SpecialBuild: AvCompile_2015_0616_154836(6055), SVNRev 309d50c06d2885375935ac1c0a79cdb255cb7045 (release/SmallUpdate2015-06_beta), av
481c8c.ec4: PrivateBuild: x64 Release_Unicode_DRIVER
482c8c.ec4: FileDescription: AVG AVI Loader Driver
483c8c.ec4: \SystemRoot\System32\drivers\avgdiska.sys:
484c8c.ec4: CreationTime: 2015-03-11T05:16:06.000000000Z
485c8c.ec4: LastWriteTime: 2015-03-11T05:16:06.000000000Z
486c8c.ec4: ChangeTime: 2015-08-19T04:34:57.366208700Z
487c8c.ec4: FileAttributes: 0x20
488c8c.ec4: Size: 0x27be0
489c8c.ec4: NT Headers: 0xe0
490c8c.ec4: Timestamp: 0x550015e3
491c8c.ec4: Machine: 0x8664 - amd64
492c8c.ec4: Timestamp: 0x550015e3
493c8c.ec4: Image Version: 6.2
494c8c.ec4: SizeOfImage: 0x29000 (167936)
495c8c.ec4: Resource Dir: 0x27000 LB 0x4e0
496c8c.ec4: ProductName: AVG Internet Security
497c8c.ec4: ProductVersion: 15.0.0.5902
498c8c.ec4: FileVersion: 15.0.0.5902
499c8c.ec4: SpecialBuild: AvCompile_2015_0311_110513(5902), SVNRev d57888a6d0541615b2b2c643813a0b67abc3acba (av/devel), av
500c8c.ec4: PrivateBuild: x64 Release_Unicode_DRIVER
501c8c.ec4: FileDescription: AVG File Vault Driver
502c8c.ec4: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox'
503c8c.ec4: Calling main()
504c8c.ec4: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
505c8c.ec4: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox'
506c8c.ec4: '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
507c8c.ec4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe)
508c8c.ec4: SUPR3HardenedMain: Respawn #2
509c8c.ec4: supR3HardNtEnableThreadCreation:
510c8c.ec4: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007fffe9de6a4c pvNtTerminateThread=00007fffe9e2b0b0
511c8c.ec4: supR3HardenedWinDoReSpawn(2): New child 10a4.2c8 [kernel32].
512c8c.ec4: supR3HardenedWinReSpawn: NtSetInformationThread/ThreadHideFromDebugger failed: 0xc0000022 (harmless)
513c8c.ec4: supR3HardNtChildGatherData: PebBaseAddress=00007ff7cf0e4000 cbPeb=0x388
514c8c.ec4: supR3HardNtPuChFindNtdll: uNtDllParentAddr=00007fffe9d90000 uNtDllChildAddr=00007fffe9d90000
515c8c.ec4: supR3HardenedWinSetupChildInit: uLdrInitThunk=00007fffe9de6a4c
516c8c.ec4: supR3HardenedWinSetupChildInit: Start child.
517c8c.ec4: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
518c8c.ec4: supR3HardNtChildPurify: Startup delay kludge #1/0: 518 ms, 57 sleeps
519c8c.ec4: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
520c8c.ec4: *0000000000000000-ffffffffff8dffff 0x0001/0x0000 0x0000000
521c8c.ec4: *0000000000720000-00000000006fffff 0x0004/0x0004 0x0020000
522c8c.ec4: *0000000000740000-0000000000730fff 0x0002/0x0002 0x0040000
523c8c.ec4: 000000000074f000-000000000074dfff 0x0001/0x0000 0x0000000
524c8c.ec4: *0000000000750000-0000000000653fff 0x0000/0x0004 0x0020000
525c8c.ec4: 000000000084c000-0000000000848fff 0x0104/0x0004 0x0020000
526c8c.ec4: 000000000084f000-000000000084dfff 0x0004/0x0004 0x0020000
527c8c.ec4: *0000000000850000-000000000084bfff 0x0002/0x0002 0x0040000
528c8c.ec4: 0000000000854000-0000000000847fff 0x0001/0x0000 0x0000000
529c8c.ec4: *0000000000860000-000000000085dfff 0x0004/0x0004 0x0020000
530c8c.ec4: 0000000000862000-ffffffff810e3fff 0x0001/0x0000 0x0000000
531c8c.ec4: *000000007ffe0000-000000007ffdefff 0x0002/0x0002 0x0020000
532c8c.ec4: 000000007ffe1000-000000007ffd1fff 0x0000/0x0002 0x0020000
533c8c.ec4: 000000007fff0000-ffff800930f1ffff 0x0001/0x0000 0x0000000
534c8c.ec4: *00007ff7cf0c0000-00007ff7cf09cfff 0x0002/0x0002 0x0040000
535c8c.ec4: 00007ff7cf0e3000-00007ff7cf0e1fff 0x0001/0x0000 0x0000000
536c8c.ec4: *00007ff7cf0e4000-00007ff7cf0e2fff 0x0004/0x0004 0x0020000
537c8c.ec4: 00007ff7cf0e5000-00007ff7cf0dbfff 0x0001/0x0000 0x0000000
538c8c.ec4: *00007ff7cf0ee000-00007ff7cf0ebfff 0x0004/0x0004 0x0020000
539c8c.ec4: 00007ff7cf0f0000-00007ff7ce97ffff 0x0001/0x0000 0x0000000
540c8c.ec4: *00007ff7cf860000-00007ff7cf860fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
541c8c.ec4: 00007ff7cf861000-00007ff7cf8e6fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
542c8c.ec4: 00007ff7cf8e7000-00007ff7cf8e7fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
543c8c.ec4: 00007ff7cf8e8000-00007ff7cf931fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
544c8c.ec4: 00007ff7cf932000-00007ff7cf932fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
545c8c.ec4: 00007ff7cf933000-00007ff7cf933fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
546c8c.ec4: 00007ff7cf934000-00007ff7cf935fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
547c8c.ec4: 00007ff7cf936000-00007ff7cf936fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
548c8c.ec4: 00007ff7cf937000-00007ff7cf937fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
549c8c.ec4: 00007ff7cf938000-00007ff7cf93bfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
550c8c.ec4: 00007ff7cf93c000-00007ff7cf985fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
551c8c.ec4: 00007ff7cf986000-00007fefb557bfff 0x0001/0x0000 0x0000000
552c8c.ec4: *00007fffe9d90000-00007fffe9d90fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
553c8c.ec4: 00007fffe9d91000-00007fffe9eb9fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
554c8c.ec4: 00007fffe9eba000-00007fffe9ec2fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
555c8c.ec4: 00007fffe9ec3000-00007fffe9ecffff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
556c8c.ec4: 00007fffe9ed0000-00007fffe9ed0fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
557c8c.ec4: 00007fffe9ed1000-00007fffe9ed1fff 0x0010/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
558c8c.ec4: 00007fffe9ed2000-00007fffe9f39fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
559c8c.ec4: 00007fffe9f3a000-00007fffd3e93fff 0x0001/0x0000 0x0000000
560c8c.ec4: *00007ffffffe0000-00007ffffffcffff 0x0001/0x0002 0x0020000
561c8c.ec4: VirtualBox.exe: timestamp 0x55ccc4d5 (rc=VINF_SUCCESS)
562c8c.ec4: '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
563c8c.ec4: '\Device\HarddiskVolume4\Windows\System32\ntdll.dll' has no imports
564c8c.ec4: supR3HardNtChildPurify: Done after 576 ms and 0 fixes (loop #0).
56510a4.2c8: Log file opened: 5.0.2r102096 g_hStartupLog=0000000000000004 g_uNtVerCombined=0x63258000
56610a4.2c8: supR3HardenedVmProcessInit: uNtDllAddr=00007fffe9d90000
56710a4.2c8: ntdll.dll: timestamp 0x530895af (rc=VINF_SUCCESS)
56810a4.2c8: New simple heap: #1 0000000000970000 LB 0x400000 (for 1744896 allocation)
569c8c.ec4: supR3HardenedEarlyCompact: Removed heap 1 (0x000000005b0000 LB 0x400000)
570c8c.ec4: supR3HardNtEnableThreadCreation:
57110a4.2c8: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox'
57210a4.2c8: System32: \Device\HarddiskVolume4\Windows\System32
57310a4.2c8: WinSxS: \Device\HarddiskVolume4\Windows\WinSxS
57410a4.2c8: KnownDllPath: C:\Windows\system32
57510a4.2c8: supR3HardenedVmProcessInit: Opening vboxdrv...
57610a4.2c8: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
57710a4.2c8: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
57810a4.2c8: Registered Dll notification callback with NTDLL.
57910a4.2c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\kernel32.dll)
58010a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\kernel32.dll
58110a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\KERNEL32.DLL (Input=KERNEL32.DLL, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000801:<flags> [calling]
58210a4.2c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
58310a4.2c8: supR3HardenedDllNotificationCallback: load 00007fffe5ec0000 LB 0x0010f000 C:\Windows\system32\KERNELBASE.dll [fFlags=0x0]
58410a4.2c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\KernelBase.dll)
58510a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\KernelBase.dll
58610a4.2c8: supR3HardenedDllNotificationCallback: load 00007fffe6f30000 LB 0x0013a000 C:\Windows\system32\KERNEL32.DLL [fFlags=0x0]
58710a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
58810a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6f30000 'C:\Windows\system32\KERNEL32.DLL'
58910a4.2c8: supR3HardenedDllNotificationCallback: load 00007ff7cf860000 LB 0x00126000 C:\Program Files\Oracle\VirtualBox\VirtualBox.exe [fFlags=0x0]
59010a4.2c8: '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
59110a4.2c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe)
59210a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
59310a4.2c8: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007fffe9de6a4c pvNtTerminateThread=00007fffe9e2b0b0
594c8c.ec4: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 129 ms.
59510a4.2c8: \SystemRoot\System32\ntdll.dll:
59610a4.2c8: CreationTime: 2014-03-18T10:14:36.739928900Z
59710a4.2c8: LastWriteTime: 2014-03-18T10:14:36.943083200Z
59810a4.2c8: ChangeTime: 2015-08-19T07:06:29.144737500Z
59910a4.2c8: FileAttributes: 0x20
60010a4.2c8: Size: 0x1a5d10
60110a4.2c8: NT Headers: 0xe8
60210a4.2c8: Timestamp: 0x530895af
60310a4.2c8: Machine: 0x8664 - amd64
60410a4.2c8: Timestamp: 0x530895af
60510a4.2c8: Image Version: 6.3
60610a4.2c8: SizeOfImage: 0x1aa000 (1744896)
60710a4.2c8: Resource Dir: 0x145000 LB 0x62450
60810a4.2c8: ProductName: Microsoft® Windows® Operating System
60910a4.2c8: ProductVersion: 6.3.9600.17031
61010a4.2c8: FileVersion: 6.3.9600.17031 (winblue_gdr.140221-1952)
61110a4.2c8: FileDescription: NT Layer DLL
61210a4.2c8: \SystemRoot\System32\kernel32.dll:
61310a4.2c8: CreationTime: 2014-05-15T02:05:12.262422000Z
61410a4.2c8: LastWriteTime: 2014-05-15T02:05:12.264422100Z
61510a4.2c8: ChangeTime: 2015-08-27T15:32:12.520359400Z
61610a4.2c8: FileAttributes: 0x20
61710a4.2c8: Size: 0x13b3c0
61810a4.2c8: NT Headers: 0xe8
61910a4.2c8: Timestamp: 0x532a419c
62010a4.2c8: Machine: 0x8664 - amd64
62110a4.2c8: Timestamp: 0x532a419c
62210a4.2c8: Image Version: 6.3
62310a4.2c8: SizeOfImage: 0x13a000 (1286144)
62410a4.2c8: Resource Dir: 0x12a000 LB 0x520
62510a4.2c8: ProductName: Microsoft® Windows® Operating System
62610a4.2c8: ProductVersion: 6.3.9600.17056
62710a4.2c8: FileVersion: 6.3.9600.17056 (winblue_gdr.140319-1520)
62810a4.2c8: FileDescription: Windows NT BASE API Client DLL
62910a4.2c8: \SystemRoot\System32\KernelBase.dll:
63010a4.2c8: CreationTime: 2014-05-15T02:05:12.106301200Z
63110a4.2c8: LastWriteTime: 2014-05-15T02:05:12.107301500Z
63210a4.2c8: ChangeTime: 2015-08-27T15:33:18.448366100Z
63310a4.2c8: FileAttributes: 0x20
63410a4.2c8: Size: 0x10f9d8
63510a4.2c8: NT Headers: 0xf0
63610a4.2c8: Timestamp: 0x532954fb
63710a4.2c8: Machine: 0x8664 - amd64
63810a4.2c8: Timestamp: 0x532954fb
63910a4.2c8: Image Version: 6.3
64010a4.2c8: SizeOfImage: 0x10f000 (1110016)
64110a4.2c8: Resource Dir: 0x10a000 LB 0x3530
64210a4.2c8: ProductName: Microsoft® Windows® Operating System
64310a4.2c8: ProductVersion: 6.3.9600.17055
64410a4.2c8: FileVersion: 6.3.9600.17055 (winblue_gdr.140318-1651)
64510a4.2c8: FileDescription: Windows NT BASE API Client DLL
64610a4.2c8: \SystemRoot\System32\apisetschema.dll:
64710a4.2c8: CreationTime: 2013-08-22T12:13:09.745625900Z
64810a4.2c8: LastWriteTime: 2013-08-22T12:35:12.091034400Z
64910a4.2c8: ChangeTime: 2015-08-19T18:20:31.227258500Z
65010a4.2c8: FileAttributes: 0x20
65110a4.2c8: Size: 0x11360
65210a4.2c8: NT Headers: 0xd0
65310a4.2c8: Timestamp: 0x52160049
65410a4.2c8: Machine: 0x8664 - amd64
65510a4.2c8: Timestamp: 0x52160049
65610a4.2c8: Image Version: 6.3
65710a4.2c8: SizeOfImage: 0x13000 (77824)
65810a4.2c8: Resource Dir: 0x11000 LB 0x3f8
65910a4.2c8: ProductName: Microsoft® Windows® Operating System
66010a4.2c8: ProductVersion: 6.3.9600.16384
66110a4.2c8: FileVersion: 6.3.9600.16384 (winblue_rtm.130821-1623)
66210a4.2c8: FileDescription: ApiSet Schema DLL
66310a4.2c8: NtOpenDirectoryObject failed on \Driver: 0xc0000022
66410a4.2c8: supR3HardenedWinFindAdversaries: 0x100
66510a4.2c8: \SystemRoot\System32\drivers\avgrkx64.sys:
66610a4.2c8: CreationTime: 2015-03-20T05:18:18.000000000Z
66710a4.2c8: LastWriteTime: 2015-03-20T05:18:18.000000000Z
66810a4.2c8: ChangeTime: 2015-08-19T04:34:54.848403100Z
66910a4.2c8: FileAttributes: 0x20
67010a4.2c8: Size: 0x9fe0
67110a4.2c8: NT Headers: 0xe8
67210a4.2c8: Timestamp: 0x550bf3e7
67310a4.2c8: Machine: 0x8664 - amd64
67410a4.2c8: Timestamp: 0x550bf3e7
67510a4.2c8: Image Version: 6.2
67610a4.2c8: SizeOfImage: 0xa000 (40960)
67710a4.2c8: Resource Dir: 0x9000 LB 0x510
67810a4.2c8: ProductName: AVG Internet Security
67910a4.2c8: ProductVersion: 15.0.0.5908
68010a4.2c8: FileVersion: 15.0.0.5908
68110a4.2c8: SpecialBuild: AvCompile_2015_0320_111532(5908), SVNRev 18c4578e1c294cb8006a179b834157155925d4af (release/SmallUpdate2015-04_beta), av
68210a4.2c8: PrivateBuild: x64 Release_Unicode_DRIVER
68310a4.2c8: FileDescription: AVG Anti-Rootkit Driver
68410a4.2c8: \SystemRoot\System32\drivers\avgmfx64.sys:
68510a4.2c8: CreationTime: 2015-08-04T04:32:32.000000000Z
68610a4.2c8: LastWriteTime: 2015-08-04T04:32:32.000000000Z
68710a4.2c8: ChangeTime: 2015-08-27T14:54:10.509488100Z
68810a4.2c8: FileAttributes: 0x20
68910a4.2c8: Size: 0x3d3b0
69010a4.2c8: NT Headers: 0xe0
69110a4.2c8: Timestamp: 0x55c086ac
69210a4.2c8: Machine: 0x8664 - amd64
69310a4.2c8: Timestamp: 0x55c086ac
69410a4.2c8: Image Version: 6.2
69510a4.2c8: SizeOfImage: 0x3e000 (253952)
69610a4.2c8: Resource Dir: 0x3c000 LB 0x52c
69710a4.2c8: ProductName: AVG Internet Security
69810a4.2c8: ProductVersion: 15.0.0.6132
69910a4.2c8: FileVersion: 15.0.0.6132
70010a4.2c8: SpecialBuild: AvCompile_2015_0804_112815(6132), SVNRev cbac1c769cb9b6888db1f1065b4133bf3c9ce40f (release/SmallUpdate2015-08_beta), av
70110a4.2c8: PrivateBuild: x64 Release_Unicode_DRIVER
70210a4.2c8: FileDescription: AVG Resident Shield Minifilter Driver
70310a4.2c8: \SystemRoot\System32\drivers\avgidsdrivera.sys:
70410a4.2c8: CreationTime: 2015-08-19T04:52:30.000000000Z
70510a4.2c8: LastWriteTime: 2015-08-19T04:52:30.000000000Z
70610a4.2c8: ChangeTime: 2015-08-27T14:54:13.654218400Z
70710a4.2c8: FileAttributes: 0x20
70810a4.2c8: Size: 0x4c7b0
70910a4.2c8: NT Headers: 0xe8
71010a4.2c8: Timestamp: 0x55d451da
71110a4.2c8: Machine: 0x8664 - amd64
71210a4.2c8: Timestamp: 0x55d451da
71310a4.2c8: Image Version: 6.2
71410a4.2c8: SizeOfImage: 0x53000 (339968)
71510a4.2c8: Resource Dir: 0x51000 LB 0x554
71610a4.2c8: ProductName: AVG Internet Security
71710a4.2c8: ProductVersion: 15.0.0.6137
71810a4.2c8: FileVersion: 15.0.0.6137
71910a4.2c8: SpecialBuild: AvCompile_2015_0819_113418(6137), SVNRev 7ade868631072664eb184732ae422a4307e58f68 (release/SmallUpdate2015-08_release), av
72010a4.2c8: PrivateBuild: x64 Release_Unicode_DRIVER
72110a4.2c8: FileDescription: AVG IDS Application Activity Monitor Driver.
72210a4.2c8: \SystemRoot\System32\drivers\avgidsha.sys:
72310a4.2c8: CreationTime: 2015-08-19T04:53:56.000000000Z
72410a4.2c8: LastWriteTime: 2015-08-19T04:53:56.000000000Z
72510a4.2c8: ChangeTime: 2015-08-27T14:54:13.507210600Z
72610a4.2c8: FileAttributes: 0x20
72710a4.2c8: Size: 0x48bb0
72810a4.2c8: NT Headers: 0xd8
72910a4.2c8: Timestamp: 0x55d45230
73010a4.2c8: Machine: 0x8664 - amd64
73110a4.2c8: Timestamp: 0x55d45230
73210a4.2c8: Image Version: 6.2
73310a4.2c8: SizeOfImage: 0x49000 (299008)
73410a4.2c8: Resource Dir: 0x47000 LB 0x548
73510a4.2c8: ProductName: AVG Internet Security
73610a4.2c8: ProductVersion: 15.0.0.6137
73710a4.2c8: FileVersion: 15.0.0.6137
73810a4.2c8: SpecialBuild: AvCompile_2015_0819_113418(6137), SVNRev 7ade868631072664eb184732ae422a4307e58f68 (release/SmallUpdate2015-08_release), av
73910a4.2c8: PrivateBuild: x64 Release_Unicode_DRIVER
74010a4.2c8: FileDescription: AVG Application Activity Monitor Helper Driver
74110a4.2c8: \SystemRoot\System32\drivers\avgloga.sys:
74210a4.2c8: CreationTime: 2015-05-07T06:50:22.000000000Z
74310a4.2c8: LastWriteTime: 2015-05-07T06:50:22.000000000Z
74410a4.2c8: ChangeTime: 2015-08-19T04:34:46.033632900Z
74510a4.2c8: FileAttributes: 0x20
74610a4.2c8: Size: 0x5c5e0
74710a4.2c8: NT Headers: 0xf0
74810a4.2c8: Timestamp: 0x554b5179
74910a4.2c8: Machine: 0x8664 - amd64
75010a4.2c8: Timestamp: 0x554b5179
75110a4.2c8: Image Version: 6.2
75210a4.2c8: SizeOfImage: 0x5b000 (372736)
75310a4.2c8: Resource Dir: 0x59000 LB 0x4ec
75410a4.2c8: ProductName: AVG Internet Security
75510a4.2c8: ProductVersion: 15.0.0.5957
75610a4.2c8: FileVersion: 15.0.0.5957
75710a4.2c8: SpecialBuild: AvCompile_2015_0507_134328(5957), SVNRev bcddc515e1405c8e35481b16de334020e451ec3e (release/HotFix2015-05), av
75810a4.2c8: PrivateBuild: x64 Release_Unicode_DRIVER
75910a4.2c8: FileDescription: AVG Logging Driver
76010a4.2c8: \SystemRoot\System32\drivers\avgldx64.sys:
76110a4.2c8: CreationTime: 2015-06-16T08:55:04.000000000Z
76210a4.2c8: LastWriteTime: 2015-06-16T08:55:04.000000000Z
76310a4.2c8: ChangeTime: 2015-08-19T04:34:54.973401800Z
76410a4.2c8: FileAttributes: 0x20
76510a4.2c8: Size: 0x3f3e0
76610a4.2c8: NT Headers: 0xe0
76710a4.2c8: Timestamp: 0x55802aaf
76810a4.2c8: Machine: 0x8664 - amd64
76910a4.2c8: Timestamp: 0x55802aaf
77010a4.2c8: Image Version: 6.2
77110a4.2c8: SizeOfImage: 0x42000 (270336)
77210a4.2c8: Resource Dir: 0x40000 LB 0x50c
77310a4.2c8: ProductName: AVG Internet Security
77410a4.2c8: ProductVersion: 15.0.0.6055
77510a4.2c8: FileVersion: 15.0.0.6055
77610a4.2c8: SpecialBuild: AvCompile_2015_0616_154836(6055), SVNRev 309d50c06d2885375935ac1c0a79cdb255cb7045 (release/SmallUpdate2015-06_beta), av
77710a4.2c8: PrivateBuild: x64 Release_Unicode_DRIVER
77810a4.2c8: FileDescription: AVG AVI Loader Driver
77910a4.2c8: \SystemRoot\System32\drivers\avgdiska.sys:
78010a4.2c8: CreationTime: 2015-03-11T05:16:06.000000000Z
78110a4.2c8: LastWriteTime: 2015-03-11T05:16:06.000000000Z
78210a4.2c8: ChangeTime: 2015-08-19T04:34:57.366208700Z
78310a4.2c8: FileAttributes: 0x20
78410a4.2c8: Size: 0x27be0
78510a4.2c8: NT Headers: 0xe0
78610a4.2c8: Timestamp: 0x550015e3
78710a4.2c8: Machine: 0x8664 - amd64
78810a4.2c8: Timestamp: 0x550015e3
78910a4.2c8: Image Version: 6.2
79010a4.2c8: SizeOfImage: 0x29000 (167936)
79110a4.2c8: Resource Dir: 0x27000 LB 0x4e0
79210a4.2c8: ProductName: AVG Internet Security
79310a4.2c8: ProductVersion: 15.0.0.5902
79410a4.2c8: FileVersion: 15.0.0.5902
79510a4.2c8: SpecialBuild: AvCompile_2015_0311_110513(5902), SVNRev d57888a6d0541615b2b2c643813a0b67abc3acba (av/devel), av
79610a4.2c8: PrivateBuild: x64 Release_Unicode_DRIVER
79710a4.2c8: FileDescription: AVG File Vault Driver
79810a4.2c8: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox'
79910a4.2c8: Calling main()
80010a4.2c8: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
80110a4.2c8: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox'
80210a4.2c8: '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
80310a4.2c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe)
80410a4.2c8: SUPR3HardenedMain: Final process, opening VBoxDrv...
80510a4.2c8: supR3HardenedEarlyCompact: Removed heap 1 (0x00000000970000 LB 0x400000)
80610a4.2c8: supR3HardNtEnableThreadCreation:
80710a4.2c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSupLib.dll)
80810a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSupLib.dll
80910a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
81010a4.2c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
81110a4.2c8: supR3HardenedDllNotificationCallback: load 00007fffe9780000 LB 0x00005000 C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL [fFlags=0x0]
81210a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
81310a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
81410a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
81510a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe9780000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
81610a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
81710a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
81810a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe9780000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
81910a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe9780000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
82010a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
82110a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'crypt32.dll'.
82210a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #19 'msasn1.dll'.
82310a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #22 'rpcrt4.dll'.
82410a4.2c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\wintrust.dll)
82510a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\wintrust.dll
82610a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
82710a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
82810a4.2c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll)
82910a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll
83010a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
83110a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume4\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
83210a4.2c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\msasn1.dll)
83310a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\msasn1.dll
83410a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
83510a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume4\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
83610a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
83710a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #28 'msasn1.dll'.
83810a4.2c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\crypt32.dll)
83910a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\crypt32.dll
84010a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
84110a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
84210a4.2c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\msvcrt.dll)
84310a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\msvcrt.dll
84410a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
84510a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume4\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
84610a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
84710a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
84810a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
84910a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
85010a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
85110a4.2c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
85210a4.2c8: supR3HardenedDllNotificationCallback: load 00007fffe6c80000 LB 0x000a7000 C:\Windows\system32\msvcrt.dll [fFlags=0x0]
85310a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
85410a4.2c8: supR3HardenedDllNotificationCallback: load 00007fffe5ea0000 LB 0x00012000 C:\Windows\system32\MSASN1.dll [fFlags=0x0]
85510a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
85610a4.2c8: supR3HardenedDllNotificationCallback: load 00007fffe6020000 LB 0x001d7000 C:\Windows\system32\CRYPT32.dll [fFlags=0x0]
85710a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
85810a4.2c8: supR3HardenedDllNotificationCallback: load 00007fffe6300000 LB 0x00136000 C:\Windows\system32\RPCRT4.dll [fFlags=0x0]
85910a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
86010a4.2c8: supR3HardenedDllNotificationCallback: load 00007fffe6200000 LB 0x0004c000 C:\Windows\system32\Wintrust.dll [fFlags=0x0]
86110a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
86210a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6200000 'C:\Windows\system32\Wintrust.dll'
86310a4.2c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\bcrypt.dll)
86410a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\bcrypt.dll
86510a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcrypt.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
86610a4.2c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
86710a4.2c8: supR3HardenedDllNotificationCallback: load 00007fffe58e0000 LB 0x00026000 C:\Windows\system32\bcrypt.dll [fFlags=0x0]
86810a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
86910a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe58e0000 'C:\Windows\system32\bcrypt.dll'
87010a4.2c8: bcrypt.dll loaded at 00007fffe58e0000, BCryptOpenAlgorithmProvider at 00007fffe58e2ce0, preloading providers:
87110a4.2c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\bcryptprimitives.dll)
87210a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\bcryptprimitives.dll
87310a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcryptprimitives.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
87410a4.2c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
87510a4.2c8: supR3HardenedDllNotificationCallback: load 00007fffe5c00000 LB 0x00060000 C:\Windows\system32\bcryptprimitives.dll [fFlags=0x0]
87610a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
87710a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe5c00000 'C:\Windows\system32\bcryptprimitives.dll'
87810a4.2c8: BCryptOpenAlgorithmProvider(,'MD2',0,0) -> 0x0 (hAlgo=0000000000db87d0)
87910a4.2c8: BCryptOpenAlgorithmProvider(,'MD4',0,0) -> 0x0 (hAlgo=0000000000db8bc0)
88010a4.2c8: BCryptOpenAlgorithmProvider(,'MD5',0,0) -> 0x0 (hAlgo=0000000000db8ce0)
88110a4.2c8: BCryptOpenAlgorithmProvider(,'SHA1',0,0) -> 0x0 (hAlgo=0000000000db8f30)
88210a4.2c8: BCryptOpenAlgorithmProvider(,'SHA256',0,0) -> 0x0 (hAlgo=0000000000db9050)
88310a4.2c8: BCryptOpenAlgorithmProvider(,'SHA512',0,0) -> 0x0 (hAlgo=0000000000db91c0)
88410a4.2c8: BCryptOpenAlgorithmProvider(,'RSA',0,0) -> 0x0 (hAlgo=0000000000db9760)
88510a4.2c8: BCryptOpenAlgorithmProvider(,'DSA',0,0) -> 0x0 (hAlgo=0000000000db9880)
88610a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
88710a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
88810a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6200000 'C:\Windows\System32\WINTRUST.DLL'
88910a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
89010a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
89110a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6200000 'C:\Windows\System32\WINTRUST.DLL'
89210a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
89310a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
89410a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6200000 'C:\Windows\System32\WINTRUST.DLL'
89510a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
89610a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
89710a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6200000 'C:\Windows\System32\WINTRUST.DLL'
89810a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
89910a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
90010a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6200000 'C:\Windows\System32\WINTRUST.DLL'
90110a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
90210a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
90310a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6200000 'C:\Windows\System32\WINTRUST.DLL'
90410a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
90510a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6200000 'C:\Windows\System32\WINTRUST.DLL'
90610a4.2c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\cryptsp.dll)
90710a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\cryptsp.dll
90810a4.2c8: supR3HardenedDllNotificationCallback: load 00007fffe5670000 LB 0x0001e000 C:\Windows\SYSTEM32\CRYPTSP.dll [fFlags=0x0]
90910a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
91010a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'bcrypt.dll'.
91110a4.2c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\rsaenh.dll)
91210a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\rsaenh.dll
91310a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
91410a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume4\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
91510a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
91610a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
91710a4.2c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
91810a4.2c8: supR3HardenedDllNotificationCallback: load 00007fffe52f0000 LB 0x00035000 C:\Windows\system32\rsaenh.dll [fFlags=0x0]
91910a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
92010a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
92110a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'bcryptprimitives.dll'.
92210a4.2c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\cryptbase.dll)
92310a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\cryptbase.dll
92410a4.2c8: supR3HardenedDllNotificationCallback: load 00007fffe5c60000 LB 0x0000a000 C:\Windows\SYSTEM32\CRYPTBASE.dll [fFlags=0x0]
92510a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\cryptbase.dll [lacks WinVerifyTrust]
92610a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
92710a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcryptprimitives.dll'...
92810a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcryptprimitives.dll' -> '\Device\HarddiskVolume4\Windows\System32\bcryptprimitives.dll' [rcNtRedir=0xc0150008]
92910a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
93010a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
93110a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6f30000 'C:\Windows\system32\kernel32.dll'
93210a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
93310a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6200000 'C:\Windows\System32\WINTRUST.DLL'
93410a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
93510a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPT32.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
93610a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\CRYPT32.dll'
93710a4.2c8: supR3HardenedDllNotificationCallback: load 00007fffe6d30000 LB 0x00015000 C:\Windows\system32\imagehlp.dll [fFlags=0x0]
93810a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
93910a4.2c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\imagehlp.dll)
94010a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\imagehlp.dll
94110a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
94210a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
94310a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
94410a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
94510a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
94610a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
94710a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'bcrypt.dll'.
94810a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'ntasn1.dll'.
94910a4.2c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\ncrypt.dll)
95010a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\ncrypt.dll
95110a4.2c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\ntasn1.dll)
95210a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\ntasn1.dll
95310a4.2c8: supR3HardenedDllNotificationCallback: load 00007fffe5870000 LB 0x0003a000 C:\Windows\SYSTEM32\NTASN1.dll [fFlags=0x0]
95410a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ntasn1.dll [lacks WinVerifyTrust]
95510a4.2c8: supR3HardenedDllNotificationCallback: load 00007fffe58b0000 LB 0x00024000 C:\Windows\SYSTEM32\ncrypt.dll [fFlags=0x0]
95610a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ncrypt.dll [lacks WinVerifyTrust]
95710a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'rpcrt4.dll'.
95810a4.2c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\sechost.dll)
95910a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\sechost.dll
96010a4.2c8: supR3HardenedDllNotificationCallback: load 00007fffe6a10000 LB 0x00057000 C:\Windows\SYSTEM32\sechost.dll [fFlags=0x0]
96110a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\sechost.dll [lacks WinVerifyTrust]
96210a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
96310a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'rpcrt4.dll'.
96410a4.2c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\gpapi.dll)
96510a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\gpapi.dll
96610a4.2c8: supR3HardenedDllNotificationCallback: load 00007fffe4ff0000 LB 0x00022000 C:\Windows\SYSTEM32\gpapi.dll [fFlags=0x0]
96710a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gpapi.dll [lacks WinVerifyTrust]
96810a4.2c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\profapi.dll)
96910a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\profapi.dll
97010a4.2c8: supR3HardenedDllNotificationCallback: load 00007fffe5df0000 LB 0x00014000 C:\Windows\SYSTEM32\profapi.dll [fFlags=0x0]
97110a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\profapi.dll [lacks WinVerifyTrust]
97210a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
97310a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'crypt32.dll'.
97410a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'wldap32.dll'.
97510a4.2c8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\System32\cryptnet.dll)
97610a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\cryptnet.dll
97710a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wldap32.dll'...
97810a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'wldap32.dll' -> '\Device\HarddiskVolume4\Windows\System32\wldap32.dll' [rcNtRedir=0xc0150008]
97910a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
98010a4.2c8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\System32\Wldap32.dll)
98110a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\Wldap32.dll
98210a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
98310a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume4\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
98410a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
98510a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
98610a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
98710a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
98810a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
98910a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
99010a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
99110a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
99210a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
99310a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
99410a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
99510a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
99610a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
99710a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntasn1.dll'...
99810a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntasn1.dll' -> '\Device\HarddiskVolume4\Windows\System32\ntasn1.dll' [rcNtRedir=0xc0150008]
99910a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ntasn1.dll [lacks WinVerifyTrust]
100010a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
100110a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume4\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
100210a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
100310a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
100410a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
100510a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
100610a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (Input=cryptnet.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
100710a4.2c8: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
100810a4.2c8: supR3HardenedDllNotificationCallback: load 00007fffe7360000 LB 0x0005a000 C:\Windows\system32\WLDAP32.dll [fFlags=0x0]
100910a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\Wldap32.dll [lacks WinVerifyTrust]
101010a4.2c8: supR3HardenedDllNotificationCallback: load 00007fffe3f80000 LB 0x00034000 C:\Windows\system32\cryptnet.dll [fFlags=0x0]
101110a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
101210a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
101310a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
101410a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe3f80000 'C:\Windows\system32\cryptnet.dll'
101510a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
101610a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
101710a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe3f80000 'C:\Windows\system32\cryptnet.dll'
101810a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
101910a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
102010a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe3f80000 'C:\Windows\system32\cryptnet.dll'
102110a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
102210a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
102310a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe3f80000 'C:\Windows\system32\cryptnet.dll'
102410a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
102510a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
102610a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe3f80000 'C:\Windows\system32\cryptnet.dll'
102710a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
102810a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
102910a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe3f80000 'C:\Windows\system32\cryptnet.dll'
103010a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
103110a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe3f80000 'C:\Windows\system32\cryptnet.dll'
103210a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
103310a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe3f80000 'C:\Windows\system32\cryptnet.dll'
103410a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
103510a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe3f80000 'C:\Windows\system32\cryptnet.dll'
103610a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
103710a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe3f80000 'C:\Windows\system32\cryptnet.dll'
103810a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
103910a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe3f80000 'C:\Windows\system32\cryptnet.dll'
104010a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe3f80000 'C:\Windows\system32\cryptnet.dll'
104110a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
104210a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe3f80000 'C:\Windows\System32\cryptnet.dll'
104310a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
104410a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'sechost.dll'.
104510a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'rpcrt4.dll'.
104610a4.2c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\advapi32.dll)
104710a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\advapi32.dll
104810a4.2c8: supR3HardenedDllNotificationCallback: load 00007fffe6bc0000 LB 0x000a5000 C:\Windows\SYSTEM32\advapi32.dll [fFlags=0x0]
104910a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
105010a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
105110a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
105210a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
105310a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
105410a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'sechost.dll'...
105510a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'sechost.dll' -> '\Device\HarddiskVolume4\Windows\System32\sechost.dll' [rcNtRedir=0xc0150008]
105610a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\sechost.dll [lacks WinVerifyTrust]
105710a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
105810a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
105910a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
106010a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
106110a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
106210a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
106310a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
106410a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
106510a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000000 pwszName=\SystemRoot\System32\ntdll.dll
106610a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: New context 0000000000dbf310
106710a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000dbf310
106810a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F325E8C3600C621144505768DFED418BF47A6F51
106910a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
107010a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rpcrt4.dll (Input=rpcrt4.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
107110a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6300000 'C:\Windows\system32\rpcrt4.dll'
107210a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
107310a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6200000 'C:\Windows\System32\WINTRUST.DLL'
107410a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
107510a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6200000 'C:\Windows\System32\WINTRUST.DLL'
107610a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
107710a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6200000 'C:\Windows\System32\WINTRUST.DLL'
107810a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
107910a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6200000 'C:\Windows\System32\WINTRUST.DLL'
108010a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
108110a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6200000 'C:\Windows\System32\WINTRUST.DLL'
108210a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
108310a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
108410a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6200000 'C:\Windows\System32\WINTRUST.DLL'
108510a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
108610a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6200000 'C:\Windows\System32\WINTRUST.DLL'
108710a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
108810a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
108910a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
109010a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
109110a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
109210a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
109310a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_2215_for_KB2919355~31bf3856ad364e35~amd64~~6.3.1.14.cat'; file='\SystemRoot\System32\ntdll.dll'
109410a4.2c8: g_pfnWinVerifyTrust=00007fffe6201040
109510a4.2c8: supR3HardenedScreenImage/preload: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll [redoing WinVerifyTrust]
109610a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
109710a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
109810a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
109910a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
110010a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
110110a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
110210a4.2c8: supR3HardenedScreenImage/preload: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\crypt32.dll'
110310a4.2c8: supR3HardenedScreenImage/preload: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [redoing WinVerifyTrust]
110410a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
110510a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
110610a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
110710a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll
110810a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
110910a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
111010a4.2c8: supR3HardenedScreenImage/preload: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\wintrust.dll'
111110a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
111210a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
111310a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
111410a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
111510a4.2c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\advapi32.dll'
111610a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000384 pwszName=\Device\HarddiskVolume4\Windows\System32\Wldap32.dll
111710a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000dbf310
111810a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000dbf310
111910a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=69524339B1646CCE03C83E941C787D6C1E6B6703
112010a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
112110a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
112210a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
112310a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-CoreSystem-DS-Package~31bf3856ad364e35~amd64~~6.3.9600.16384.cat'; file='\Device\HarddiskVolume4\Windows\System32\Wldap32.dll'
112410a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
112510a4.2c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\Wldap32.dll'
112610a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000380 pwszName=\Device\HarddiskVolume4\Windows\System32\cryptnet.dll
112710a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000dbf310
112810a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000dbf310
112910a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=0315578F0B76A9760FEA2715053C51E46A277B04
113010a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
113110a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
113210a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
113310a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-CoreSystem-DS-Package~31bf3856ad364e35~amd64~~6.3.9600.16384.cat'; file='\Device\HarddiskVolume4\Windows\System32\cryptnet.dll'
113410a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
113510a4.2c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\cryptnet.dll'
113610a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
113710a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
113810a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
113910a4.2c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\profapi.dll'
114010a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
114110a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
114210a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
114310a4.2c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\gpapi.dll'
114410a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
114510a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
114610a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
114710a4.2c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\sechost.dll'
114810a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
114910a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
115010a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
115110a4.2c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\ntasn1.dll'
115210a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
115310a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
115410a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll
115510a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
115610a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
115710a4.2c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\ncrypt.dll'
115810a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
115910a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
116010a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
116110a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
116210a4.2c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\imagehlp.dll'
116310a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
116410a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
116510a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
116610a4.2c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\cryptbase.dll'
116710a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
116810a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
116910a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
117010a4.2c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\rsaenh.dll'
117110a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
117210a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
117310a4.2c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\cryptsp.dll'
117410a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
117510a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
117610a4.2c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\bcryptprimitives.dll'
117710a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
117810a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
117910a4.2c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\bcrypt.dll'
118010a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
118110a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
118210a4.2c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll'
118310a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
118410a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
118510a4.2c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\msasn1.dll'
118610a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
118710a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
118810a4.2c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll'
118910a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
119010a4.2c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSupLib.dll'
119110a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
119210a4.2c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe'
119310a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
119410a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
119510a4.2c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\KernelBase.dll'
119610a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
119710a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
119810a4.2c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\kernel32.dll'
119910a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
120010a4.2c8: supR3HardenedWinIsDesiredRootCA: Adding 0x5ad46780fa5df300 DC=com, DC=microsoft, CN=Microsoft Root Certificate Authority
120110a4.2c8: supR3HardenedWinIsDesiredRootCA: Adding 0xea5386456178582b C=ZA, ST=Western Cape, L=Durbanville, O=Thawte, OU=Thawte Certification, CN=Thawte Timestamping CA
120210a4.2c8: supR3HardenedWinIsDesiredRootCA: Adding 0x3be670c1bd02a900 OU=Copyright (c) 1997 Microsoft Corp., OU=Microsoft Corporation, CN=Microsoft Root Authority
120310a4.2c8: supR3HardenedWinIsDesiredRootCA: Adding 0x4d3835aa4180b200 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2011
120410a4.2c8: supR3HardenedWinIsDesiredRootCA: Adding 0x10e0229c091abf00 C=CZ, ST=Moravia, L=Brno, O=AVG Technologies cz, OU=Engineering, CN=AVG Technologies
120510a4.2c8: supR3HardenedWinIsDesiredRootCA: Adding 0x646e3fe3ba08df00 C=US, O=MSFT, CN=Microsoft Authenticode(tm) Root Authority
120610a4.2c8: supR3HardenedWinIsDesiredRootCA: Adding 0xece4e4289e08b900 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010
120710a4.2c8: supR3HardenedWinIsDesiredRootCA: Adding 0x43a9cc371ff5385a O=Microsoft Trust Network, OU=Microsoft Corporation, OU=Microsoft Time Stamping Service Root, OU=Copyright (c) 1997 Microsoft Corp.
120810a4.2c8: supR3HardenedWinIsDesiredRootCA: Adding 0x2e2d2c7c68f0202e O=VeriSign Trust Network, OU=VeriSign, Inc., OU=VeriSign Time Stamping Service Root, OU=NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.
120910a4.2c8: supR3HardenedWinIsDesiredRootCA: Adding 0x61a3a33f81aace00 C=US, ST=UT, L=Salt Lake City, O=The USERTRUST Network, OU=http://www.usertrust.com, CN=UTN-USERFirst-Object
121010a4.2c8: supR3HardenedWinIsDesiredRootCA: Adding 0xf4fd306318ccda00 C=US, O=GeoTrust Inc., CN=GeoTrust Global CA
121110a4.2c8: supR3HardenedWinIsDesiredRootCA: Adding 0x3d98ab22bb04a300 C=IE, O=Baltimore, OU=CyberTrust, CN=Baltimore CyberTrust Root
121210a4.2c8: supR3HardenedWinIsDesiredRootCA: Adding 0xa0ee62086758b15d C=US, O=Equifax, OU=Equifax Secure Certificate Authority
121310a4.2c8: supR3HardenedWinIsDesiredRootCA: Adding 0xa3ce8d99e60eda00 C=BE, O=GlobalSign nv-sa, OU=Root CA, CN=GlobalSign Root CA
121410a4.2c8: supR3HardenedWinIsDesiredRootCA: Adding 0xa8de7211e13be200 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root CA
121510a4.2c8: supR3HardenedWinIsDesiredRootCA: Adding 0x7ae89c50f0b6a00f C=US, O=GTE Corporation, OU=GTE CyberTrust Solutions, Inc., CN=GTE CyberTrust Global Root
121610a4.2c8: supR3HardenedWinIsDesiredRootCA: Adding 0xd45980fbf0a0ac00 C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2006 thawte, Inc. - For authorized use only, CN=thawte Primary Root CA
121710a4.2c8: supR3HardenedWinIsDesiredRootCA: Adding 0x14018a1bf29e595c C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority
121810a4.2c8: supR3HardenedWinIsDesiredRootCA: Adding 0x9e5bc2d78b6a3636 C=ZA, ST=Western Cape, L=Cape Town, O=Thawte Consulting cc, OU=Certification Services Division, CN=Thawte Premium Server CA, Email=premium-server@thawte.com
121910a4.2c8: supR3HardenedWinIsDesiredRootCA: Adding 0xd4fbe673e5ccc600 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA
122010a4.2c8: supR3HardenedWinIsDesiredRootCA: Adding 0x357a29080824af00 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2006 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G5
122110a4.2c8: supR3HardenedWinIsDesiredRootCA: Adding 0x59faf1086271bf00 C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com, Inc., CN=Go Daddy Root Certificate Authority - G2
122210a4.2c8: supR3HardenedWinIsDesiredRootCA: Adding 0x466cbc09db88c100 C=IL, O=StartCom Ltd., OU=Secure Digital Certificate Signing, CN=StartCom Certification Authority
122310a4.2c8: supR3HardenedWinIsDesiredRootCA: Adding 0x491857ead79dde00 C=US, O=The Go Daddy Group, Inc., OU=Go Daddy Class 2 Certification Authority
122410a4.2c8: supR3HardenedWinIsDesiredRootCA: Adding 0x8043e4ce150ead00 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID Root CA
122510a4.2c8: supR3HardenedWinIsDesiredRootCA: Adding 0xf2e6331af7b700 C=SE, O=AddTrust AB, OU=AddTrust External TTP Network, CN=AddTrust External CA Root
122610a4.2c8: supR3HardenedWinRetrieveTrustedRootCAs: cAdded=26
122710a4.2c8: SUPR3HardenedMain: Load Runtime...
122810a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
122910a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
123010a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
123110a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ws2_32.dll'.
123210a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'rpcrt4.dll'.
123310a4.2c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll) WinVerifyTrust
123410a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
123510a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
123610a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
123710a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll
123810a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
123910a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
124010a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
124110a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
124210a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #22 'nsi.dll'.
124310a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #24 'rpcrt4.dll'.
124410a4.2c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\ws2_32.dll) WinVerifyTrust
124510a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\ws2_32.dll
124610a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
124710a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
124810a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
124910a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
125010a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll
125110a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
125210a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume4\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
125310a4.2c8: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\nsi.dll'.
125410a4.2c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\nsi.dll)
125510a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\nsi.dll
125610a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
125710a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
125810a4.2c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll) WinVerifyTrust
125910a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll
126010a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
126110a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
126210a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll
126310a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
126410a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
126510a4.2c8: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll'.
126610a4.2c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll)
126710a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll
126810a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
126910a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
127010a4.2c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll) WinVerifyTrust
127110a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000a01:<flags> [calling]
127210a4.2c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
127310a4.2c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll [avoiding WinVerifyTrust]
127410a4.2c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll
127510a4.2c8: supR3HardenedDllNotificationCallback: load 0000000077910000 LB 0x000d2000 C:\Program Files\Oracle\VirtualBox\MSVCR100.dll [fFlags=0x0]
127610a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll [avoiding WinVerifyTrust]
127710a4.2c8: supR3HardenedDllNotificationCallback: load 0000000077870000 LB 0x00098000 C:\Program Files\Oracle\VirtualBox\MSVCP100.dll [fFlags=0x0]
127810a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll
127910a4.2c8: supR3HardenedDllNotificationCallback: load 00007fffe7250000 LB 0x00009000 C:\Windows\system32\NSI.dll [fFlags=0x0]
128010a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\nsi.dll [avoiding WinVerifyTrust]
128110a4.2c8: supR3HardenedDllNotificationCallback: load 00007fffe6690000 LB 0x00058000 C:\Windows\system32\WS2_32.dll [fFlags=0x0]
128210a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ws2_32.dll
128310a4.2c8: supR3HardenedDllNotificationCallback: load 00007fffe91a0000 LB 0x00543000 C:\Program Files\Oracle\VirtualBox\VBoxRT.dll [fFlags=0x0]
128410a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
128510a4.2c8: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll'.
128610a4.2c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
128710a4.2c8: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\nsi.dll'.
128810a4.2c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\nsi.dll' [rescheduled]
128910a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
129010a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
129110a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe91a0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
129210a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
129310a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
129410a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe91a0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
129510a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
129610a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
129710a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe91a0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
129810a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
129910a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
130010a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe91a0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
130110a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
130210a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
130310a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe91a0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
130410a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
130510a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
130610a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe91a0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
130710a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe91a0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
130810a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe91a0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
130910a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe91a0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
131010a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe91a0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
131110a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe91a0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
131210a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe91a0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
131310a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe91a0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
131410a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
131510a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
131610a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe91a0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
131710a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe91a0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
131810a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe91a0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
131910a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe91a0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
132010a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe91a0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
132110a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe91a0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
132210a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe91a0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
132310a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe91a0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
132410a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe91a0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
132510a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe91a0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
132610a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe91a0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
132710a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe91a0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
132810a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe91a0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
132910a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe91a0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
133010a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe91a0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
133110a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe91a0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
133210a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
133310a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
133410a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe91a0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
133510a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe91a0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
133610a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe91a0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
133710a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe91a0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
133810a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6200000 'C:\Windows\system32\Wintrust.dll'
133910a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
134010a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
134110a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
134210a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
134310a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll
134410a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\crypt32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
134510a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
134610a4.2c8: SUPR3HardenedMain: Load TrustedMain...
134710a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
134810a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'opengl32.dll'.
134910a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
135010a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcp100.dll'.
135110a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcr100.dll'.
135210a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qtcorevbox4.dll'.
135310a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'qtguivbox4.dll'.
135410a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'qtnetworkvbox4.dll'.
135510a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'qtopenglvbox4.dll'.
135610a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'user32.dll'.
135710a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'gdi32.dll'.
135810a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'advapi32.dll'.
135910a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'shell32.dll'.
136010a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'ole32.dll'.
136110a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'oleaut32.dll'.
136210a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #15 'comdlg32.dll'.
136310a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'winmm.dll'.
136410a4.2c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.dll) WinVerifyTrust
136510a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.dll
136610a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
136710a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume4\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
136810a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
136910a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
137010a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'winmmbase.dll'.
137110a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcrt.dll'.
137210a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'user32.dll'.
137310a4.2c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\winmm.dll) WinVerifyTrust
137410a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\winmm.dll
137510a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comdlg32.dll'...
137610a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'comdlg32.dll' -> '\Device\HarddiskVolume4\Windows\System32\comdlg32.dll' [rcNtRedir=0xc0150008]
137710a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000474 pwszName=\Device\HarddiskVolume4\Windows\System32\comdlg32.dll
137810a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000dbf310
137910a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000dbf310
138010a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=60247C73B442DC5C383C0B76D9A2D4B13B1CFCB5
138110a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
138210a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
138310a4.2c8: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\user32.dll'.
138410a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #29 'gdi32.dll'.
138510a4.2c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\user32.dll)
138610a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\user32.dll
138710a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
138810a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
138910a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll
139010a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmmbase.dll'...
139110a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmmbase.dll' -> '\Device\HarddiskVolume4\Windows\System32\winmmbase.dll' [rcNtRedir=0xc0150008]
139210a4.2c8: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\winmmbase.dll'.
139310a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
139410a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #22 'devobj.dll'.
139510a4.2c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\winmmbase.dll)
139610a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\winmmbase.dll
139710a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'devobj.dll'...
139810a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'devobj.dll' -> '\Device\HarddiskVolume4\Windows\System32\devobj.dll' [rcNtRedir=0xc0150008]
139910a4.2c8: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\devobj.dll'.
140010a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
140110a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'cfgmgr32.dll'.
140210a4.2c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\devobj.dll)
140310a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\devobj.dll
140410a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
140510a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
140610a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
140710a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
140810a4.2c8: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\gdi32.dll'.
140910a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #21 'user32.dll'.
141010a4.2c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\gdi32.dll)
141110a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\gdi32.dll
141210a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
141310a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
141410a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll [lacks WinVerifyTrust]
141510a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
141610a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
141710a4.2c8: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll'.
141810a4.2c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll)
141910a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll
142010a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
142110a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
142210a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
142310a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
142410a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_2551_for_KB2919355~31bf3856ad364e35~amd64~~6.3.1.14.cat'; file='\Device\HarddiskVolume4\Windows\System32\comdlg32.dll'
142510a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
142610a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
142710a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'shlwapi.dll'.
142810a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
142910a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'gdi32.dll'.
143010a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'comctl32.dll'.
143110a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'shell32.dll'.
143210a4.2c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\comdlg32.dll) WinVerifyTrust
143310a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\comdlg32.dll
143410a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
143510a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume4\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
143610a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
143710a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume4\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
143810a4.2c8: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\shell32.dll'.
143910a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
144010a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #55 'user32.dll'.
144110a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #57 'shlwapi.dll'.
144210a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #59 'gdi32.dll'.
144310a4.2c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\shell32.dll)
144410a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\shell32.dll
144510a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comctl32.dll'...
144610a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'comctl32.dll' -> '\Device\HarddiskVolume4\Windows\System32\comctl32.dll' [rcNtRedir=0x0]
144710a4.2c8: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume4\Windows\System32\comctl32.dll'.
144810a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'advapi32.dll'.
144910a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
145010a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
145110a4.2c8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\System32\comctl32.dll)
145210a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\comctl32.dll
145310a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
145410a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
145510a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
145610a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
145710a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
145810a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll [lacks WinVerifyTrust]
145910a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
146010a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume4\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
146110a4.2c8: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\shlwapi.dll'.
146210a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
146310a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #37 'user32.dll'.
146410a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #38 'gdi32.dll'.
146510a4.2c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\shlwapi.dll)
146610a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\shlwapi.dll
146710a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
146810a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
146910a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
147010a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
147110a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
147210a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
147310a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
147410a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll [lacks WinVerifyTrust]
147510a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
147610a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
147710a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
147810a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
147910a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll [lacks WinVerifyTrust]
148010a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
148110a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
148210a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
148310a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
148410a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
148510a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\advapi32.dll
148610a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
148710a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
148810a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
148910a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
149010a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume4\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
149110a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\shlwapi.dll [lacks WinVerifyTrust]
149210a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
149310a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
149410a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll [lacks WinVerifyTrust]
149510a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
149610a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
149710a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
149810a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
149910a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
150010a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'combase.dll'.
150110a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'rpcrt4.dll'.
150210a4.2c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\oleaut32.dll) WinVerifyTrust
150310a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\oleaut32.dll
150410a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
150510a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
150610a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
150710a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
150810a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll
150910a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
151010a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume4\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
151110a4.2c8: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\combase.dll'.
151210a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
151310a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
151410a4.2c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\combase.dll)
151510a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\combase.dll
151610a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
151710a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
151810a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
151910a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
152010a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
152110a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
152210a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
152310a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
152410a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
152510a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'rpcrt4.dll'.
152610a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #36 'gdi32.dll'.
152710a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #37 'user32.dll'.
152810a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #38 'combase.dll'.
152910a4.2c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\ole32.dll) WinVerifyTrust
153010a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\ole32.dll
153110a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
153210a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume4\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
153310a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\shell32.dll [redoing WinVerifyTrust]
153410a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
153510a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume4\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
153610a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\combase.dll [lacks WinVerifyTrust]
153710a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
153810a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
153910a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll [lacks WinVerifyTrust]
154010a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
154110a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
154210a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
154310a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
154410a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
154510a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
154610a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
154710a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll
154810a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
154910a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
155010a4.2c8: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\shell32.dll'
155110a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
155210a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
155310a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\advapi32.dll
155410a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
155510a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
155610a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gdi32.dll [redoing WinVerifyTrust]
155710a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
155810a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
155910a4.2c8: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\gdi32.dll'
156010a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
156110a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
156210a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll [redoing WinVerifyTrust]
156310a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
156410a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
156510a4.2c8: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\user32.dll'
156610a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtopenglvbox4.dll'...
156710a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtopenglvbox4.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qtopenglvbox4.dll' [rcNtRedir=0xc0150008]
156810a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
156910a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'opengl32.dll'.
157010a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
157110a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
157210a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qtguivbox4.dll'.
157310a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qtcorevbox4.dll'.
157410a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcr100.dll'.
157510a4.2c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll) WinVerifyTrust
157610a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll
157710a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtnetworkvbox4.dll'...
157810a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtnetworkvbox4.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qtnetworkvbox4.dll' [rcNtRedir=0xc0150008]
157910a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
158010a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
158110a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
158210a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtcorevbox4.dll'...
158310a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtcorevbox4.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qtcorevbox4.dll' [rcNtRedir=0xc0150008]
158410a4.2c8: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll'.
158510a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
158610a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'ole32.dll'.
158710a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
158810a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ws2_32.dll'.
158910a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcp100.dll'.
159010a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcr100.dll'.
159110a4.2c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll)
159210a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll
159310a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtguivbox4.dll'...
159410a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtguivbox4.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qtguivbox4.dll' [rcNtRedir=0xc0150008]
159510a4.2c8: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll'.
159610a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
159710a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'comdlg32.dll'.
159810a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'oleaut32.dll'.
159910a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'imm32.dll'.
160010a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'winmm.dll'.
160110a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'winspool.drv'.
160210a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ole32.dll'.
160310a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'user32.dll'.
160410a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'advapi32.dll'.
160510a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'shell32.dll'.
160610a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'qtcorevbox4.dll'.
160710a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'msvcp100.dll'.
160810a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'msvcr100.dll'.
160910a4.2c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll)
161010a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll
161110a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
161210a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
161310a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll
161410a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
161510a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
161610a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gdi32.dll
161710a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
161810a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume4\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
161910a4.2c8: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume4\Windows\System32\opengl32.dll'.
162010a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
162110a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
162210a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'gdi32.dll'.
162310a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'glu32.dll'.
162410a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ddraw.dll'.
162510a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'user32.dll'.
162610a4.2c8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\System32\opengl32.dll)
162710a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\opengl32.dll
162810a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
162910a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
163010a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ddraw.dll'...
163110a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ddraw.dll' -> '\Device\HarddiskVolume4\Windows\System32\ddraw.dll' [rcNtRedir=0xc0150008]
163210a4.2c8: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume4\Windows\System32\ddraw.dll'.
163310a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
163410a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'user32.dll'.
163510a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'gdi32.dll'.
163610a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'dciman32.dll'.
163710a4.2c8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\System32\ddraw.dll)
163810a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\ddraw.dll
163910a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'glu32.dll'...
164010a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'glu32.dll' -> '\Device\HarddiskVolume4\Windows\System32\glu32.dll' [rcNtRedir=0xc0150008]
164110a4.2c8: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume4\Windows\System32\glu32.dll'.
164210a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
164310a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'opengl32.dll'.
164410a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
164510a4.2c8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\System32\glu32.dll)
164610a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\glu32.dll
164710a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
164810a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
164910a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gdi32.dll
165010a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
165110a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
165210a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\advapi32.dll
165310a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
165410a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
165510a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
165610a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
165710a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
165810a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
165910a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
166010a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll
166110a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtcorevbox4.dll'...
166210a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtcorevbox4.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qtcorevbox4.dll' [rcNtRedir=0xc0150008]
166310a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll [lacks WinVerifyTrust]
166410a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
166510a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume4\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
166610a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\shell32.dll
166710a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
166810a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
166910a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\advapi32.dll
167010a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
167110a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
167210a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
167310a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
167410a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ole32.dll
167510a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winspool.drv'...
167610a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'winspool.drv' -> '\Device\HarddiskVolume4\Windows\System32\winspool.drv' [rcNtRedir=0xc0150008]
167710a4.2c8: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume4\Windows\System32\winspool.drv'.
167810a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
167910a4.2c8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\System32\winspool.drv)
168010a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\winspool.drv
168110a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
168210a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume4\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
168310a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmm.dll
168410a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
168510a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume4\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
168610a4.2c8: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\imm32.dll'.
168710a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'user32.dll'.
168810a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #21 'msctf.dll'.
168910a4.2c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\imm32.dll)
169010a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\imm32.dll
169110a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
169210a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume4\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
169310a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\oleaut32.dll
169410a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comdlg32.dll'...
169510a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'comdlg32.dll' -> '\Device\HarddiskVolume4\Windows\System32\comdlg32.dll' [rcNtRedir=0xc0150008]
169610a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\comdlg32.dll
169710a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
169810a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
169910a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
170010a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
170110a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
170210a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
170310a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
170410a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll
170510a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
170610a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
170710a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ws2_32.dll
170810a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
170910a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
171010a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\advapi32.dll
171110a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
171210a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
171310a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ole32.dll
171410a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
171510a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
171610a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msctf.dll'...
171710a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msctf.dll' -> '\Device\HarddiskVolume4\Windows\System32\msctf.dll' [rcNtRedir=0xc0150008]
171810a4.2c8: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\msctf.dll'.
171910a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
172010a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'user32.dll'.
172110a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #24 'gdi32.dll'.
172210a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'imm32.dll'.
172310a4.2c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\msctf.dll)
172410a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\msctf.dll
172510a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
172610a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
172710a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
172810a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
172910a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
173010a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
173110a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
173210a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume4\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
173310a4.2c8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\opengl32.dll [lacks WinVerifyTrust]
173410a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
173510a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
173610a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dciman32.dll'...
173710a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'dciman32.dll' -> '\Device\HarddiskVolume4\Windows\System32\dciman32.dll' [rcNtRedir=0xc0150008]
173810a4.2c8: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume4\Windows\System32\dciman32.dll'.
173910a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
174010a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'gdi32.dll'.
174110a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
174210a4.2c8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\System32\dciman32.dll)
174310a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\dciman32.dll
174410a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
174510a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
174610a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
174710a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
174810a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
174910a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
175010a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
175110a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
175210a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
175310a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
175410a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
175510a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
175610a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
175710a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume4\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
175810a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\imm32.dll [lacks WinVerifyTrust]
175910a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
176010a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
176110a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
176210a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
176310a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll
176410a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
176510a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
176610a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
176710a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ws2_32.dll'.
176810a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'qtcorevbox4.dll'.
176910a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcr100.dll'.
177010a4.2c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtNetworkVBox4.dll) WinVerifyTrust
177110a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtNetworkVBox4.dll
177210a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtguivbox4.dll'...
177310a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtguivbox4.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qtguivbox4.dll' [rcNtRedir=0xc0150008]
177410a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll [redoing WinVerifyTrust]
177510a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
177610a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
177710a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
177810a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtcorevbox4.dll'...
177910a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtcorevbox4.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qtcorevbox4.dll' [rcNtRedir=0xc0150008]
178010a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll [lacks WinVerifyTrust]
178110a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
178210a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
178310a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ws2_32.dll
178410a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
178510a4.2c8: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll'
178610a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtcorevbox4.dll'...
178710a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtcorevbox4.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qtcorevbox4.dll' [rcNtRedir=0xc0150008]
178810a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll [redoing WinVerifyTrust]
178910a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
179010a4.2c8: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll'
179110a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
179210a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
179310a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll [redoing WinVerifyTrust]
179410a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
179510a4.2c8: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll'
179610a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
179710a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
179810a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll
179910a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
180010a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
180110a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
180210a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume4\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
180310a4.2c8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\opengl32.dll [redoing WinVerifyTrust]
180410a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000003bc pwszName=\Device\HarddiskVolume4\Windows\System32\opengl32.dll
180510a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000dbf310
180610a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000dbf310
180710a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=E7B21317A30D467EC23A2D5AE5A00919E81ECF45
180810a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
180910a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
181010a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package-AutoMerged-windows~31bf3856ad364e35~amd64~~6.3.9600.16384.cat'; file='\Device\HarddiskVolume4\Windows\System32\opengl32.dll'
181110a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
181210a4.2c8: supR3HardenedScreenImage/Imports: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\opengl32.dll'
181310a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VirtualBox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000a01:<flags> [calling]
181410a4.2c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.dll
181510a4.2c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\opengl32.dll
181610a4.2c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll
181710a4.2c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll
181810a4.2c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtNetworkVBox4.dll
181910a4.2c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll
182010a4.2c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmm.dll
182110a4.2c8: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\glu32.dll [avoiding WinVerifyTrust]
182210a4.2c8: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\ddraw.dll [avoiding WinVerifyTrust]
182310a4.2c8: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\winspool.drv [avoiding WinVerifyTrust]
182410a4.2c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\combase.dll [avoiding WinVerifyTrust]
182510a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'advapi32.dll'.
182610a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
182710a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
182810a4.2c8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.9600.16384_none_34a8918f959016ea\comctl32.dll)
182910a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.9600.16384_none_34a8918f959016ea\comctl32.dll
183010a4.2c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmmbase.dll [avoiding WinVerifyTrust]
183110a4.2c8: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\dciman32.dll [avoiding WinVerifyTrust]
183210a4.2c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll [avoiding WinVerifyTrust]
183310a4.2c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\devobj.dll [avoiding WinVerifyTrust]
183410a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
183510a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #33 'combase.dll'.
183610a4.2c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\SHCore.dll)
183710a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\SHCore.dll
183810a4.2c8: supR3HardenedDllNotificationCallback: load 00007fffe70d0000 LB 0x00171000 C:\Windows\system32\USER32.dll [fFlags=0x0]
183910a4.2c8: supR3HardenedDllNotificationCallback: load 00007fffe6a70000 LB 0x00145000 C:\Windows\system32\GDI32.dll [fFlags=0x0]
184010a4.2c8: supR3HardenedDllNotificationCallback: load 00007fffe2a10000 LB 0x00009000 C:\Windows\SYSTEM32\DCIMAN32.dll [fFlags=0x0]
184110a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\dciman32.dll [avoiding WinVerifyTrust]
184210a4.2c8: supR3HardenedDllNotificationCallback: load 00007fffdc5a0000 LB 0x000f4000 C:\Windows\SYSTEM32\DDRAW.dll [fFlags=0x0]
184310a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\ddraw.dll [avoiding WinVerifyTrust]
184410a4.2c8: supR3HardenedDllNotificationCallback: load 00007fffe2a20000 LB 0x0002c000 C:\Windows\SYSTEM32\GLU32.dll [fFlags=0x0]
184510a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\glu32.dll [avoiding WinVerifyTrust]
184610a4.2c8: supR3HardenedDllNotificationCallback: load 00007fffdd430000 LB 0x00121000 C:\Windows\SYSTEM32\OPENGL32.dll [fFlags=0x0]
184710a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\opengl32.dll
184810a4.2c8: supR3HardenedDllNotificationCallback: load 00007fffe88a0000 LB 0x001d6000 C:\Windows\SYSTEM32\combase.dll [fFlags=0x0]
184910a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\combase.dll [avoiding WinVerifyTrust]
185010a4.2c8: supR3HardenedDllNotificationCallback: load 00007fffe6890000 LB 0x00178000 C:\Windows\system32\ole32.dll [fFlags=0x0]
185110a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ole32.dll
185210a4.2c8: supR3HardenedDllNotificationCallback: load 0000000077590000 LB 0x002de000 C:\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll [fFlags=0x0]
185310a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll
185410a4.2c8: supR3HardenedDllNotificationCallback: load 00007fffe7260000 LB 0x00051000 C:\Windows\system32\SHLWAPI.dll [fFlags=0x0]
185510a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\shlwapi.dll [avoiding WinVerifyTrust]
185610a4.2c8: supR3HardenedDllNotificationCallback: load 00007fffe6250000 LB 0x000a1000 C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.9600.16384_none_34a8918f959016ea\COMCTL32.dll [fFlags=0x0]
185710a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.9600.16384_none_34a8918f959016ea\comctl32.dll [avoiding WinVerifyTrust]
185810a4.2c8: supR3HardenedDllNotificationCallback: load 00007fffe73c0000 LB 0x01420000 C:\Windows\system32\SHELL32.dll [fFlags=0x0]
185910a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\shell32.dll
186010a4.2c8: supR3HardenedDllNotificationCallback: load 00007fffe46c0000 LB 0x0009f000 C:\Windows\SYSTEM32\SHCORE.DLL [fFlags=0x0]
186110a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\SHCore.dll [avoiding WinVerifyTrust]
186210a4.2c8: supR3HardenedDllNotificationCallback: load 00007fffe72c0000 LB 0x0009a000 C:\Windows\system32\COMDLG32.dll [fFlags=0x0]
186310a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\comdlg32.dll
186410a4.2c8: supR3HardenedDllNotificationCallback: load 00007fffe87e0000 LB 0x000b7000 C:\Windows\system32\OLEAUT32.dll [fFlags=0x0]
186510a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\oleaut32.dll
186610a4.2c8: supR3HardenedDllNotificationCallback: load 00007fffe6510000 LB 0x00139000 C:\Windows\system32\MSCTF.dll [fFlags=0x0]
186710a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msctf.dll [avoiding WinVerifyTrust]
186810a4.2c8: supR3HardenedDllNotificationCallback: load 00007fffe6650000 LB 0x00034000 C:\Windows\system32\IMM32.dll [fFlags=0x0]
186910a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\imm32.dll [avoiding WinVerifyTrust]
187010a4.2c8: supR3HardenedDllNotificationCallback: load 00007fffe5fd0000 LB 0x0004a000 C:\Windows\SYSTEM32\cfgmgr32.dll [fFlags=0x0]
187110a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll [avoiding WinVerifyTrust]
187210a4.2c8: supR3HardenedDllNotificationCallback: load 00007fffe4ca0000 LB 0x00026000 C:\Windows\SYSTEM32\DEVOBJ.dll [fFlags=0x0]
187310a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\devobj.dll [avoiding WinVerifyTrust]
187410a4.2c8: supR3HardenedDllNotificationCallback: load 00007fffe3850000 LB 0x0002a000 C:\Windows\SYSTEM32\WINMMBASE.dll [fFlags=0x0]
187510a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmmbase.dll [avoiding WinVerifyTrust]
187610a4.2c8: supR3HardenedDllNotificationCallback: load 00007fffe3880000 LB 0x0001f000 C:\Windows\SYSTEM32\WINMM.dll [fFlags=0x0]
187710a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmm.dll
187810a4.2c8: supR3HardenedDllNotificationCallback: load 00007fffdf3b0000 LB 0x0007b000 C:\Windows\SYSTEM32\WINSPOOL.DRV [fFlags=0x0]
187910a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\winspool.drv [avoiding WinVerifyTrust]
188010a4.2c8: supR3HardenedDllNotificationCallback: load 0000000076c20000 LB 0x0096c000 C:\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll [fFlags=0x0]
188110a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll
188210a4.2c8: supR3HardenedDllNotificationCallback: load 0000000076b10000 LB 0x00105000 C:\Program Files\Oracle\VirtualBox\QtNetworkVBox4.dll [fFlags=0x0]
188310a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtNetworkVBox4.dll
188410a4.2c8: supR3HardenedDllNotificationCallback: load 0000000076a30000 LB 0x000dc000 C:\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll [fFlags=0x0]
188510a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll
188610a4.2c8: supR3HardenedDllNotificationCallback: load 00007fffbbbb0000 LB 0x00ab1000 C:\Program Files\Oracle\VirtualBox\VirtualBox.dll [fFlags=0x0]
188710a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.dll
188810a4.2c8: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\SHCore.dll'.
188910a4.2c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\SHCore.dll' [rescheduled]
189010a4.2c8: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume4\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.9600.16384_none_34a8918f959016ea\comctl32.dll'.
189110a4.2c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.9600.16384_none_34a8918f959016ea\comctl32.dll' [rescheduled]
189210a4.2c8: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume4\Windows\System32\dciman32.dll'.
189310a4.2c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\dciman32.dll' [rescheduled]
189410a4.2c8: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\msctf.dll'.
189510a4.2c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\msctf.dll' [rescheduled]
189610a4.2c8: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\imm32.dll'.
189710a4.2c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\imm32.dll' [rescheduled]
189810a4.2c8: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume4\Windows\System32\winspool.drv'.
189910a4.2c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\winspool.drv' [rescheduled]
190010a4.2c8: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume4\Windows\System32\glu32.dll'.
190110a4.2c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\glu32.dll' [rescheduled]
190210a4.2c8: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume4\Windows\System32\ddraw.dll'.
190310a4.2c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\ddraw.dll' [rescheduled]
190410a4.2c8: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\combase.dll'.
190510a4.2c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\combase.dll' [rescheduled]
190610a4.2c8: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\shlwapi.dll'.
190710a4.2c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\shlwapi.dll' [rescheduled]
190810a4.2c8: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume4\Windows\System32\comctl32.dll'.
190910a4.2c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\comctl32.dll' [rescheduled]
191010a4.2c8: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll'.
191110a4.2c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll' [rescheduled]
191210a4.2c8: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\devobj.dll'.
191310a4.2c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\devobj.dll' [rescheduled]
191410a4.2c8: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\winmmbase.dll'.
191510a4.2c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\winmmbase.dll' [rescheduled]
191610a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\imm32.dll [redoing WinVerifyTrust]
191710a4.2c8: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\imm32.dll'.
191810a4.2c8: supR3HardenedScreenImage/LdrLoadDll: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume4\Windows\System32\imm32.dll
191910a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
192010a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume4\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
192110a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\combase.dll [redoing WinVerifyTrust]
192210a4.2c8: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\combase.dll'.
192310a4.2c8: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume4\Windows\System32\combase.dll
192410a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
192510a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
192610a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
192710a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
192810a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
192910a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
193010a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
193110a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
193210a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\advapi32.dll
193310a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\imm32.dll (Input=imm32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
193410a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6650000 'C:\Windows\system32\imm32.dll'
193510a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffbbbb0000 'C:\Program Files\Oracle\VirtualBox\VirtualBox.dll'
193610a4.2c8: SUPR3HardenedMain: Calling TrustedMain (00007fffbbbb1770)...
193710a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmm.dll
193810a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\winmm.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
193910a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe3880000 'C:\Windows\system32\winmm.dll'
194010a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000600 pwszName=\Device\HarddiskVolume4\Windows\System32\uxtheme.dll
194110a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000dbf310
194210a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000dbf310
194310a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=4235D21C52BC6FC9D5B6A7B3CE61ED85F804B2B7
194410a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
194510a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
194610a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_2550_for_KB2919355~31bf3856ad364e35~amd64~~6.3.1.14.cat'; file='\Device\HarddiskVolume4\Windows\System32\uxtheme.dll'
194710a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
194810a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
194910a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'user32.dll'.
195010a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'gdi32.dll'.
195110a4.2c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\uxtheme.dll) WinVerifyTrust
195210a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\uxtheme.dll
195310a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
195410a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
195510a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
195610a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
195710a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
195810a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
195910a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
196010a4.2c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\uxtheme.dll
196110a4.2c8: supR3HardenedDllNotificationCallback: load 00007fffe4b50000 LB 0x00121000 C:\Windows\system32\uxtheme.dll [fFlags=0x0]
196210a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\uxtheme.dll
196310a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe4b50000 'C:\Windows\system32\uxtheme.dll'
196410a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\uxtheme.dll
196510a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
196610a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe4b50000 'C:\Windows\system32\uxtheme.dll'
196710a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\uxtheme.dll
196810a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
196910a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe4b50000 'C:\Windows\system32\uxtheme.dll'
197010a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\uxtheme.dll
197110a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
197210a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe4b50000 'C:\Windows\system32\uxtheme.dll'
197310a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
197410a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'user32.dll'.
197510a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #15 'gdi32.dll'.
197610a4.2c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\dwmapi.dll)
197710a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\dwmapi.dll
197810a4.2c8: supR3HardenedDllNotificationCallback: load 00007fffe44f0000 LB 0x00020000 C:\Windows\system32\dwmapi.dll [fFlags=0x0]
197910a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\dwmapi.dll [avoiding WinVerifyTrust]
198010a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcrt.dll'.
198110a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'rpcrt4.dll'.
198210a4.2c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\kernel.appcore.dll)
198310a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\kernel.appcore.dll
198410a4.2c8: supR3HardenedDllNotificationCallback: load 00007fffe4b40000 LB 0x0000a000 C:\Windows\SYSTEM32\kernel.appcore.dll [fFlags=0x0]
198510a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\kernel.appcore.dll [avoiding WinVerifyTrust]
198610a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
198710a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
198810a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
198910a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
199010a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
199110a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
199210a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gdi32.dll
199310a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
199410a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
199510a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
199610a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
199710a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
199810a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
199910a4.2c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\kernel.appcore.dll'
200010a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
200110a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
200210a4.2c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\dwmapi.dll'
200310a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\shell32.dll
200410a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
200510a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe73c0000 'C:\Windows\system32\shell32.dll'
200610a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\kernel32.dll
200710a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
200810a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6f30000 'C:\Windows\system32\kernel32.dll'
200910a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\uxtheme.dll
201010a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
201110a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe4b50000 'C:\Windows\system32\uxtheme.dll'
201210a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\uxtheme.dll
201310a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
201410a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe4b50000 'C:\Windows\system32\uxtheme.dll'
201510a4.2c8: supR3HardenedMonitor_LdrLoadDll: error opening 'C:\Windows\system32\wintab32.dll': 0 (NtPath=\??\C:\Windows\system32\wintab32.dll; Input=C:\Windows\system32\wintab32.dll; rcNtGetDll=0x0
201610a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wintab32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
201710a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000135 'C:\Windows\system32\wintab32.dll'
201810a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe70d0000 'C:\Windows\system32\user32.dll'
201910a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\uxtheme.dll
202010a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
202110a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe4b50000 'C:\Windows\system32\uxtheme.dll'
202210a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe70d0000 'C:\Windows\system32\user32.dll'
202310a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\advapi32.dll
202410a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\advapi32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
202510a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6bc0000 'C:\Windows\system32\advapi32.dll'
202610a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
202710a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
202810a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
202910a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rpcrt4.dll'.
203010a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #21 'profapi.dll'.
203110a4.2c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\userenv.dll) WinVerifyTrust
203210a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\userenv.dll
203310a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'profapi.dll'...
203410a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'profapi.dll' -> '\Device\HarddiskVolume4\Windows\System32\profapi.dll' [rcNtRedir=0xc0150008]
203510a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\profapi.dll
203610a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
203710a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
203810a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
203910a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
204010a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\userenv.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
204110a4.2c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\userenv.dll
204210a4.2c8: supR3HardenedDllNotificationCallback: load 00007fffe5400000 LB 0x0001e000 C:\Windows\system32\userenv.dll [fFlags=0x0]
204310a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\userenv.dll
204410a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe5400000 'C:\Windows\system32\userenv.dll'
204510a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\kernel32.dll
204610a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
204710a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6f30000 'C:\Windows\system32\kernel32.dll'
204810a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
204910a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'rpcrt4.dll'.
205010a4.2c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\clbcatq.dll)
205110a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\clbcatq.dll
205210a4.2c8: supR3HardenedDllNotificationCallback: load 00007fffe6450000 LB 0x000a4000 C:\Windows\SYSTEM32\clbcatq.dll [fFlags=0x0]
205310a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\clbcatq.dll [avoiding WinVerifyTrust]
205410a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
205510a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
205610a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
205710a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
205810a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
205910a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
206010a4.2c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\clbcatq.dll'
206110a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
206210a4.ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
206310a4.ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
206410a4.ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
206510a4.ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'psapi.dll'.
206610a4.ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vboxrt.dll'.
206710a4.ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'advapi32.dll'.
206810a4.ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'version.dll'.
206910a4.ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'ws2_32.dll'.
207010a4.ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'ole32.dll'.
207110a4.ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'oleaut32.dll'.
207210a4.ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxC.dll) WinVerifyTrust
207310a4.ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxC.dll
207410a4.ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
207510a4.ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume4\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
207610a4.ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\oleaut32.dll
207710a4.ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
207810a4.ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
207910a4.ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ole32.dll
208010a4.ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
208110a4.ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
208210a4.ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ws2_32.dll
208310a4.ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'version.dll'...
208410a4.ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'version.dll' -> '\Device\HarddiskVolume4\Windows\System32\version.dll' [rcNtRedir=0xc0150008]
208510a4.ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
208610a4.ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
208710a4.ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
208810a4.ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\version.dll) WinVerifyTrust
208910a4.ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\version.dll
209010a4.ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
209110a4.ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
209210a4.ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
209310a4.ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
209410a4.ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'psapi.dll'...
209510a4.ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'psapi.dll' -> '\Device\HarddiskVolume4\Windows\System32\psapi.dll' [rcNtRedir=0xc0150008]
209610a4.ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
209710a4.ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
209810a4.ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
209910a4.ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
210010a4.ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\psapi.dll) WinVerifyTrust
210110a4.ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\psapi.dll
210210a4.ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
210310a4.ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
210410a4.ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll
210510a4.ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
210610a4.ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
210710a4.ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll
210810a4.ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxC.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
210910a4.ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxC.dll
211010a4.ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\version.dll
211110a4.ac: supR3HardenedDllNotificationCallback: load 00007fffe6c70000 LB 0x00007000 C:\Windows\system32\PSAPI.DLL [fFlags=0x0]
211210a4.ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\psapi.dll
211310a4.ac: supR3HardenedDllNotificationCallback: load 00007fffe38a0000 LB 0x0000a000 C:\Windows\SYSTEM32\VERSION.dll [fFlags=0x0]
211410a4.ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\version.dll
211510a4.ac: supR3HardenedDllNotificationCallback: load 00007fffbc820000 LB 0x005d6000 C:\Program Files\Oracle\VirtualBox\VBoxC.dll [fFlags=0x0]
211610a4.ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxC.dll
211710a4.ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffbc820000 'C:\Program Files\Oracle\VirtualBox\VBoxC.dll'
211810a4.ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\oleaut32.dll
211910a4.ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\oleaut32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
212010a4.ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe87e0000 'C:\Windows\System32\oleaut32.dll'
212110a4.ac: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\System32\sxs.dll)
212210a4.ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\sxs.dll
212310a4.ac: supR3HardenedDllNotificationCallback: load 00007fffe5c70000 LB 0x00097000 C:\Windows\SYSTEM32\sxs.dll [fFlags=0x0]
212410a4.ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\sxs.dll [avoiding WinVerifyTrust]
212510a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000072c pwszName=\Device\HarddiskVolume4\Windows\System32\sxs.dll
212610a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000dbf310
212710a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000dbf310
212810a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=687F47861CE02066FB64E8228B3C4D091FA20854
212910a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
213010a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
213110a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntph.cat'; file='\Device\HarddiskVolume4\Windows\System32\sxs.dll'
213210a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
213310a4.2c8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\sxs.dll'
213410a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\oleaut32.dll
213510a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\OLEAUT32.dll (Input=OLEAUT32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
213610a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe87e0000 'C:\Windows\system32\OLEAUT32.dll'
213710a4.2c8: supR3HardenedMonitor_LdrLoadDll: error opening 'C:\Windows\system32\wintab32.dll': 0 (NtPath=\??\C:\Windows\system32\wintab32.dll; Input=C:\Windows\system32\wintab32.dll; rcNtGetDll=0x0
213810a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wintab32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
213910a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000135 'C:\Windows\system32\wintab32.dll'
214010a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6a70000 'C:\Windows\system32\gdi32.dll'
214110a4.828: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
214210a4.828: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
214310a4.828: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
214410a4.828: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
214510a4.828: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
214610a4.828: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMain.dll) WinVerifyTrust
214710a4.828: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMain.dll
214810a4.828: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
214910a4.828: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
215010a4.828: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
215110a4.828: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
215210a4.828: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.amd64/VBoxPuelMain.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
215310a4.828: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMain.dll
215410a4.828: supR3HardenedDllNotificationCallback: load 00007fffe9740000 LB 0x0000d000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMain.DLL [fFlags=0x0]
215510a4.828: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMain.dll
215610a4.828: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe9740000 'C:\Program Files\Oracle\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.amd64/VBoxPuelMain.DLL'
215710a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe70d0000 'C:\Windows\system32\user32.dll'
215810a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\shell32.dll
215910a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
216010a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe73c0000 'C:\Windows\system32\shell32.dll'
216110a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ole32.dll
216210a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ole32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
216310a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6890000 'C:\Windows\system32\ole32.dll'
216410a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ole32.dll
216510a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ole32.dll (Input=ole32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
216610a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6890000 'C:\Windows\system32\ole32.dll'
216710a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\oleaut32.dll
216810a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\OLEAUT32.dll (Input=OLEAUT32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
216910a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe87e0000 'C:\Windows\system32\OLEAUT32.dll'
217010a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000ae0 pwszName=\Device\HarddiskVolume4\Windows\System32\wbem\wbemprox.dll
217110a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000dbf310
217210a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000dbf310
217310a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=9DDE8958CF9B37EEDE4BB8E28DDA8308284C8A55
217410a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
217510a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
217610a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package-AutoMerged-admin~31bf3856ad364e35~amd64~~6.3.9600.16384.cat'; file='\Device\HarddiskVolume4\Windows\System32\wbem\wbemprox.dll'
217710a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
217810a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
217910a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ws2_32.dll'.
218010a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'wbemcomn.dll'.
218110a4.2c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\wbem\wbemprox.dll) WinVerifyTrust
218210a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\wbem\wbemprox.dll
218310a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wbemcomn.dll'...
218410a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'wbemcomn.dll' -> '\Device\HarddiskVolume4\Windows\System32\wbemcomn.dll' [rcNtRedir=0xc0150008]
218510a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000b4c pwszName=\Device\HarddiskVolume4\Windows\System32\wbemcomn.dll
218610a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000dbf310
218710a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000dbf310
218810a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=C8CF4605B4B026F3426876C8B971F3B65D680FCA
218910a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
219010a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
219110a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package-AutoMerged-admin~31bf3856ad364e35~amd64~~6.3.9600.16384.cat'; file='\Device\HarddiskVolume4\Windows\System32\wbemcomn.dll'
219210a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
219310a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
219410a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #15 'ws2_32.dll'.
219510a4.2c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\wbemcomn.dll) WinVerifyTrust
219610a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\wbemcomn.dll
219710a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
219810a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
219910a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ws2_32.dll
220010a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
220110a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
220210a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
220310a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
220410a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ws2_32.dll
220510a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
220610a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
220710a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wbem\wbemprox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
220810a4.2c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wbem\wbemprox.dll
220910a4.2c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wbemcomn.dll
221010a4.2c8: supR3HardenedDllNotificationCallback: load 00007fffdeb20000 LB 0x0007f000 C:\Windows\SYSTEM32\wbemcomn.dll [fFlags=0x0]
221110a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wbemcomn.dll
221210a4.2c8: supR3HardenedDllNotificationCallback: load 00007fffdcab0000 LB 0x0000f000 C:\Windows\system32\wbem\wbemprox.dll [fFlags=0x0]
221310a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wbem\wbemprox.dll
221410a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Core-LocalRegistry-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
221510a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe5ec0000 'API-MS-Win-Core-LocalRegistry-L1-1-0.dll'
221610a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffdcab0000 'C:\Windows\system32\wbem\wbemprox.dll'
221710a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000a3c pwszName=\Device\HarddiskVolume4\Windows\System32\wbem\wbemsvc.dll
221810a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000dbf310
221910a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000dbf310
222010a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=5505CC12F45E4619D5CC78CCE8BF1B3C49D7BE0E
222110a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll
222210a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
222310a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
222410a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
222510a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package-AutoMerged-admin~31bf3856ad364e35~amd64~~6.3.9600.16384.cat'; file='\Device\HarddiskVolume4\Windows\System32\wbem\wbemsvc.dll'
222610a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
222710a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
222810a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'rpcrt4.dll'.
222910a4.2c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\wbem\wbemsvc.dll) WinVerifyTrust
223010a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\wbem\wbemsvc.dll
223110a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
223210a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
223310a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
223410a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
223510a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll
223610a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wbem\wbemsvc.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
223710a4.2c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wbem\wbemsvc.dll
223810a4.2c8: supR3HardenedDllNotificationCallback: load 00007fffde310000 LB 0x00014000 C:\Windows\system32\wbem\wbemsvc.dll [fFlags=0x0]
223910a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wbem\wbemsvc.dll
224010a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffde310000 'C:\Windows\system32\wbem\wbemsvc.dll'
224110a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-l1-2-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
224210a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe5ec0000 'api-ms-win-core-localization-l1-2-0.dll'
224310a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-obsolete-l1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
224410a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe5ec0000 'api-ms-win-core-localization-obsolete-l1-1-0.dll'
224510a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000a4c pwszName=\Device\HarddiskVolume4\Windows\System32\wbem\fastprox.dll
224610a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000dbf310
224710a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000dbf310
224810a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=3F29F8F4F858A7AFDF4CD047A78948C26E8333B6
224910a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
225010a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
225110a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package-AutoMerged-admin~31bf3856ad364e35~amd64~~6.3.9600.16384.cat'; file='\Device\HarddiskVolume4\Windows\System32\wbem\fastprox.dll'
225210a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
225310a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
225410a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'wbemcomn.dll'.
225510a4.2c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\wbem\fastprox.dll) WinVerifyTrust
225610a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\wbem\fastprox.dll
225710a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wbemcomn.dll'...
225810a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'wbemcomn.dll' -> '\Device\HarddiskVolume4\Windows\System32\wbemcomn.dll' [rcNtRedir=0xc0150008]
225910a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wbemcomn.dll
226010a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
226110a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
226210a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wbem\fastprox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
226310a4.2c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wbem\fastprox.dll
226410a4.2c8: supR3HardenedDllNotificationCallback: load 00007fffde330000 LB 0x000e4000 C:\Windows\system32\wbem\fastprox.dll [fFlags=0x0]
226510a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wbem\fastprox.dll
226610a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffde330000 'C:\Windows\system32\wbem\fastprox.dll'
226710a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\oleaut32.dll
226810a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\OLEAUT32.dll (Input=OLEAUT32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
226910a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe87e0000 'C:\Windows\system32\OLEAUT32.dll'
227010a4.478: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
227110a4.478: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
227210a4.478: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrem.dll'.
227310a4.478: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
227410a4.478: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxVMM.dll) WinVerifyTrust
227510a4.478: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxVMM.dll
227610a4.478: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
227710a4.478: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
227810a4.478: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrem.dll'...
227910a4.478: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrem.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrem.dll' [rcNtRedir=0xc0150008]
228010a4.478: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
228110a4.478: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'vboxrt.dll'.
228210a4.478: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
228310a4.478: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcrt.dll'.
228410a4.478: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxREM.dll) WinVerifyTrust
228510a4.478: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxREM.dll
228610a4.478: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
228710a4.478: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
228810a4.478: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
228910a4.478: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
229010a4.478: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
229110a4.478: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
229210a4.478: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxVMM.dll
229310a4.478: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
229410a4.478: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
229510a4.478: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
229610a4.478: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxVMM.dll
229710a4.478: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxREM.dll
229810a4.478: supR3HardenedDllNotificationCallback: load 0000000076570000 LB 0x0010a000 C:\Program Files\Oracle\VirtualBox\VBoxREM.dll [fFlags=0x0]
229910a4.478: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxREM.dll
230010a4.478: supR3HardenedDllNotificationCallback: load 00007fffd4de0000 LB 0x00293000 C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL [fFlags=0x0]
230110a4.478: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxVMM.dll
230210a4.478: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffd4de0000 'C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL'
230310a4.530: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
230410a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ndis.sys'.
230510a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'ntoskrnl.exe'.
230610a4.530: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\drivers\VBoxNetAdp6.sys)
230710a4.530: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\drivers\VBoxNetAdp6.sys
230810a4.530: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\drivers\VBoxNetAdp6.sys [avoiding WinVerifyTrust]
230910a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
231010a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'ndis.sys'.
231110a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'netio.sys'.
231210a4.530: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\drivers\VBoxNetLwf.sys)
231310a4.530: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\drivers\VBoxNetLwf.sys
231410a4.530: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\drivers\VBoxNetLwf.sys [avoiding WinVerifyTrust]
231510a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
231610a4.530: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\drivers\VBoxUSBMon.sys)
231710a4.530: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\drivers\VBoxUSBMon.sys
231810a4.530: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\drivers\VBoxUSBMon.sys [avoiding WinVerifyTrust]
231910a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
232010a4.530: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\drivers\VBoxDrv.sys)
232110a4.530: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\drivers\VBoxDrv.sys
232210a4.530: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\drivers\VBoxDrv.sys [avoiding WinVerifyTrust]
232310a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
232410a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume4\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
232510a4.134c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\ntoskrnl.exe'.
232610a4.134c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'pshed.dll'.
232710a4.134c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'hal.dll'.
232810a4.134c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'bootvid.dll'.
232910a4.134c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'kdcom.dll'.
233010a4.134c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'ci.dll'.
233110a4.134c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'msrpc.sys'.
233210a4.134c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\ntoskrnl.exe)
233310a4.134c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\ntoskrnl.exe
233410a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
233510a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume4\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
233610a4.134c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ntoskrnl.exe [lacks WinVerifyTrust]
233710a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'netio.sys'...
233810a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: 'netio.sys' -> '\Device\HarddiskVolume4\Windows\System32\drivers\netio.sys' [rcNtRedir=0xc0150008]
233910a4.134c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\drivers\netio.sys'.
234010a4.134c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
234110a4.134c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'ndis.sys'.
234210a4.134c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msrpc.sys'.
234310a4.134c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\drivers\netio.sys)
234410a4.134c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\drivers\netio.sys
234510a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ndis.sys'...
234610a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ndis.sys' -> '\Device\HarddiskVolume4\Windows\System32\drivers\ndis.sys' [rcNtRedir=0xc0150008]
234710a4.134c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\drivers\ndis.sys'.
234810a4.134c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
234910a4.134c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'hal.dll'.
235010a4.134c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'netio.sys'.
235110a4.134c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\drivers\ndis.sys)
235210a4.134c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\drivers\ndis.sys
235310a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
235410a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume4\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
235510a4.134c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ntoskrnl.exe [lacks WinVerifyTrust]
235610a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
235710a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume4\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
235810a4.134c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ntoskrnl.exe [lacks WinVerifyTrust]
235910a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ndis.sys'...
236010a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ndis.sys' -> '\Device\HarddiskVolume4\Windows\System32\drivers\ndis.sys' [rcNtRedir=0xc0150008]
236110a4.134c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\drivers\ndis.sys [lacks WinVerifyTrust]
236210a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'netio.sys'...
236310a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: 'netio.sys' -> '\Device\HarddiskVolume4\Windows\System32\drivers\netio.sys' [rcNtRedir=0xc0150008]
236410a4.134c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\drivers\netio.sys [lacks WinVerifyTrust]
236510a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'hal.dll'...
236610a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: 'hal.dll' -> '\Device\HarddiskVolume4\Windows\System32\hal.dll' [rcNtRedir=0xc0150008]
236710a4.134c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\hal.dll'.
236810a4.134c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
236910a4.134c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'kdcom.dll'.
237010a4.134c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'pshed.dll'.
237110a4.134c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\hal.dll)
237210a4.134c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\hal.dll
237310a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
237410a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume4\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
237510a4.134c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ntoskrnl.exe [lacks WinVerifyTrust]
237610a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msrpc.sys'...
237710a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msrpc.sys' -> '\Device\HarddiskVolume4\Windows\System32\drivers\msrpc.sys' [rcNtRedir=0xc0150008]
237810a4.134c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\drivers\msrpc.sys'.
237910a4.134c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
238010a4.134c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\drivers\msrpc.sys)
238110a4.134c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\drivers\msrpc.sys
238210a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ndis.sys'...
238310a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ndis.sys' -> '\Device\HarddiskVolume4\Windows\System32\drivers\ndis.sys' [rcNtRedir=0xc0150008]
238410a4.134c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\drivers\ndis.sys [lacks WinVerifyTrust]
238510a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
238610a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume4\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
238710a4.134c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ntoskrnl.exe [lacks WinVerifyTrust]
238810a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msrpc.sys'...
238910a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: Failed to locate 'msrpc.sys'
239010a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ci.dll'...
239110a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ci.dll' -> '\Device\HarddiskVolume4\Windows\System32\ci.dll' [rcNtRedir=0xc0150008]
239210a4.134c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\ci.dll'.
239310a4.134c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
239410a4.134c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\ci.dll)
239510a4.134c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\ci.dll
239610a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'kdcom.dll'...
239710a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: 'kdcom.dll' -> '\Device\HarddiskVolume4\Windows\System32\kdcom.dll' [rcNtRedir=0xc0150008]
239810a4.134c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\kdcom.dll'.
239910a4.134c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
240010a4.134c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'hal.dll'.
240110a4.134c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\kdcom.dll)
240210a4.134c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\kdcom.dll
240310a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bootvid.dll'...
240410a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: 'bootvid.dll' -> '\Device\HarddiskVolume4\Windows\System32\bootvid.dll' [rcNtRedir=0xc0150008]
240510a4.134c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\BOOTVID.DLL'.
240610a4.134c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
240710a4.134c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\BOOTVID.DLL)
240810a4.134c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\BOOTVID.DLL
240910a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'hal.dll'...
241010a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: 'hal.dll' -> '\Device\HarddiskVolume4\Windows\System32\hal.dll' [rcNtRedir=0xc0150008]
241110a4.134c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\hal.dll [lacks WinVerifyTrust]
241210a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'pshed.dll'...
241310a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: 'pshed.dll' -> '\Device\HarddiskVolume4\Windows\System32\pshed.dll' [rcNtRedir=0xc0150008]
241410a4.134c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\PSHED.DLL'.
241510a4.134c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
241610a4.134c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'hal.dll'.
241710a4.134c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\PSHED.DLL)
241810a4.134c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\PSHED.DLL
241910a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'hal.dll'...
242010a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: 'hal.dll' -> '\Device\HarddiskVolume4\Windows\System32\hal.dll' [rcNtRedir=0xc0150008]
242110a4.134c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\hal.dll [lacks WinVerifyTrust]
242210a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
242310a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume4\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
242410a4.134c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ntoskrnl.exe [lacks WinVerifyTrust]
242510a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
242610a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume4\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
242710a4.134c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ntoskrnl.exe [lacks WinVerifyTrust]
242810a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'hal.dll'...
242910a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: 'hal.dll' -> '\Device\HarddiskVolume4\Windows\System32\hal.dll' [rcNtRedir=0xc0150008]
243010a4.134c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\hal.dll [lacks WinVerifyTrust]
243110a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
243210a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume4\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
243310a4.134c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ntoskrnl.exe [lacks WinVerifyTrust]
243410a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
243510a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume4\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
243610a4.134c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ntoskrnl.exe [lacks WinVerifyTrust]
243710a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
243810a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume4\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
243910a4.134c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ntoskrnl.exe [lacks WinVerifyTrust]
244010a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'pshed.dll'...
244110a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: 'pshed.dll' -> '\Device\HarddiskVolume4\Windows\System32\pshed.dll' [rcNtRedir=0xc0150008]
244210a4.134c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\PSHED.DLL [lacks WinVerifyTrust]
244310a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'kdcom.dll'...
244410a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: 'kdcom.dll' -> '\Device\HarddiskVolume4\Windows\System32\kdcom.dll' [rcNtRedir=0xc0150008]
244510a4.134c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\kdcom.dll [lacks WinVerifyTrust]
244610a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
244710a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume4\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
244810a4.134c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ntoskrnl.exe [lacks WinVerifyTrust]
244910a4.134c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
245010a4.134c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\drivers\VBoxDrv.sys'
245110a4.134c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
245210a4.134c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\drivers\VBoxUSBMon.sys'
245310a4.134c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
245410a4.134c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\drivers\VBoxNetLwf.sys'
245510a4.134c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
245610a4.134c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\drivers\VBoxNetAdp6.sys'
245710a4.134c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
245810a4.134c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
245910a4.134c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\PSHED.DLL'
246010a4.134c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
246110a4.134c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
246210a4.134c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\BOOTVID.DLL'
246310a4.134c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
246410a4.134c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
246510a4.134c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\kdcom.dll'
246610a4.134c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
246710a4.134c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
246810a4.134c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\ci.dll'
246910a4.134c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
247010a4.134c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
247110a4.134c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\drivers\msrpc.sys'
247210a4.134c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
247310a4.134c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
247410a4.134c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\hal.dll'
247510a4.134c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
247610a4.134c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
247710a4.134c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\drivers\ndis.sys'
247810a4.134c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
247910a4.134c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
248010a4.134c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\drivers\netio.sys'
248110a4.134c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
248210a4.2c8: supR3HardenedMonitor_LdrLoadDll: 'C:\Windows\system32\comctl32.dll' -> 'C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.9600.16384_none_34a8918f959016ea\comctl32.dll' [redir]
248310a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.9600.16384_none_34a8918f959016ea\comctl32.dll [redoing WinVerifyTrust]
248410a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000548 pwszName=\Device\HarddiskVolume4\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.9600.16384_none_34a8918f959016ea\comctl32.dll
248510a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000dbf310
248610a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000dbf310
248710a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=0B6F85C85728A0522988F3BA15B32993C5E6F65A
248810a4.134c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
248910a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
249010a4.134c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\ntoskrnl.exe'
249110a4.134c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
249210a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
249310a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package-AutoMerged-shell~31bf3856ad364e35~amd64~~6.3.9600.16384.cat'; file='\Device\HarddiskVolume4\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.9600.16384_none_34a8918f959016ea\comctl32.dll'
249410a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
249510a4.2c8: supR3HardenedScreenImage/LdrLoadDll: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.9600.16384_none_34a8918f959016ea\comctl32.dll'
249610a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.9600.16384_none_34a8918f959016ea\comctl32.dll (Input=C:\Windows\system32\comctl32.dll, rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
249710a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6250000 'C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.9600.16384_none_34a8918f959016ea\comctl32.dll'
249810a4.134c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
249910a4.134c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
250010a4.134c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
250110a4.134c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
250210a4.134c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll) WinVerifyTrust
250310a4.134c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll
250410a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
250510a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
250610a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
250710a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
250810a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
250910a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
251010a4.134c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxVMM.dll
251110a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
251210a4.134c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
251310a4.134c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
251410a4.134c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll
251510a4.134c: supR3HardenedDllNotificationCallback: load 00007fffe9750000 LB 0x0000a000 C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL [fFlags=0x0]
251610a4.134c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll
251710a4.134c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe9750000 'C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL'
251810a4.83c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
251910a4.83c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
252010a4.83c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
252110a4.83c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
252210a4.83c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll) WinVerifyTrust
252310a4.83c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll
252410a4.83c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
252510a4.83c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
252610a4.83c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
252710a4.83c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
252810a4.83c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll
252910a4.83c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
253010a4.83c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
253110a4.83c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
253210a4.83c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll
253310a4.83c: supR3HardenedDllNotificationCallback: load 00007fffe9720000 LB 0x0000d000 C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL [fFlags=0x0]
253410a4.83c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll
253510a4.83c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe9720000 'C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL'
253610a4.10dc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
253710a4.10dc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
253810a4.10dc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
253910a4.10dc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
254010a4.10dc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll) WinVerifyTrust
254110a4.10dc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll
254210a4.10dc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
254310a4.10dc: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
254410a4.10dc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
254510a4.10dc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
254610a4.10dc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll
254710a4.10dc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
254810a4.10dc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
254910a4.10dc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
255010a4.10dc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll
255110a4.10dc: supR3HardenedDllNotificationCallback: load 00007fffe9710000 LB 0x0000f000 C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL [fFlags=0x0]
255210a4.10dc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll
255310a4.10dc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe9710000 'C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL'
255410a4.1300: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
255510a4.1300: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
255610a4.1300: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
255710a4.1300: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
255810a4.1300: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll) WinVerifyTrust
255910a4.1300: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll
256010a4.1300: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
256110a4.1300: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
256210a4.1300: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
256310a4.1300: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
256410a4.1300: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
256510a4.1300: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
256610a4.1300: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
256710a4.1300: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll
256810a4.1300: supR3HardenedDllNotificationCallback: load 00007fffe90c0000 LB 0x0000e000 C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL [fFlags=0x0]
256910a4.1300: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll
257010a4.1300: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe90c0000 'C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL'
257110a4.530: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\shell32.dll
257210a4.530: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32/Shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
257310a4.530: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe73c0000 'C:\Windows\system32/Shell32.dll'
257410a4.530: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxVMM.dll
257510a4.530: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
257610a4.530: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffd4de0000 'C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL'
257710a4.530: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
257810a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
257910a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
258010a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
258110a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ole32.dll'.
258210a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
258310a4.530: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll) WinVerifyTrust
258410a4.530: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
258510a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
258610a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume4\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
258710a4.530: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\oleaut32.dll
258810a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
258910a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
259010a4.530: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ole32.dll
259110a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
259210a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
259310a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
259410a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
259510a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
259610a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
259710a4.530: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.amd64/VBoxHostWebcam.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
259810a4.530: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
259910a4.530: supR3HardenedDllNotificationCallback: load 00007fffe9080000 LB 0x00033000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL [fFlags=0x0]
260010a4.530: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
260110a4.530: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe9080000 'C:\Program Files\Oracle\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.amd64/VBoxHostWebcam.DLL'
260210a4.530: supR3HardenedDllNotificationCallback: Unload 00007fffe9080000 LB 0x00033000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL [flags=0x0]
260310a4.530: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
260410a4.530: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
260510a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
260610a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'dsound.dll'.
260710a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxvmm.dll'.
260810a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vboxrt.dll'.
260910a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'vboxddu.dll'.
261010a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'vboxdd2.dll'.
261110a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'user32.dll'.
261210a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'setupapi.dll'.
261310a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'ws2_32.dll'.
261410a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'ole32.dll'.
261510a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'iphlpapi.dll'.
261610a4.530: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDD.dll) WinVerifyTrust
261710a4.530: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDD.dll
261810a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'iphlpapi.dll'...
261910a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'iphlpapi.dll' -> '\Device\HarddiskVolume4\Windows\System32\iphlpapi.dll' [rcNtRedir=0xc0150008]
262010a4.530: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
262110a4.530: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
262210a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'nsi.dll'.
262310a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'winnsi.dll'.
262410a4.530: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\IPHLPAPI.DLL) WinVerifyTrust
262510a4.530: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\IPHLPAPI.DLL
262610a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
262710a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
262810a4.530: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ole32.dll
262910a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
263010a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
263110a4.530: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ws2_32.dll
263210a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
263310a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume4\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
263410a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winnsi.dll'...
263510a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'winnsi.dll' -> '\Device\HarddiskVolume4\Windows\System32\winnsi.dll' [rcNtRedir=0xc0150008]
263610a4.530: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\winnsi.dll'.
263710a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'rpcrt4.dll'.
263810a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'nsi.dll'.
263910a4.530: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\winnsi.dll)
264010a4.530: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\winnsi.dll
264110a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
264210a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume4\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
264310a4.530: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\nsi.dll [lacks WinVerifyTrust]
264410a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
264510a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume4\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
264610a4.530: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\nsi.dll [lacks WinVerifyTrust]
264710a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
264810a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
264910a4.530: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
265010a4.530: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll
265110a4.530: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
265210a4.530: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
265310a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'cfgmgr32.dll'.
265410a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
265510a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #22 'rpcrt4.dll'.
265610a4.530: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\setupapi.dll) WinVerifyTrust
265710a4.530: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\setupapi.dll
265810a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
265910a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
266010a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxdd2.dll'...
266110a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxdd2.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxdd2.dll' [rcNtRedir=0xc0150008]
266210a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
266310a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
266410a4.530: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll
266510a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
266610a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
266710a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
266810a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
266910a4.530: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll [lacks WinVerifyTrust]
267010a4.530: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
267110a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
267210a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
267310a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
267410a4.530: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDD2.dll) WinVerifyTrust
267510a4.530: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDD2.dll
267610a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxddu.dll'...
267710a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxddu.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxddu.dll' [rcNtRedir=0xc0150008]
267810a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
267910a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
268010a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
268110a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
268210a4.530: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxVMM.dll
268310a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
268410a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
268510a4.530: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll
268610a4.530: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
268710a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
268810a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
268910a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
269010a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'setupapi.dll'.
269110a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'newdev.dll'.
269210a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'advapi32.dll'.
269310a4.530: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDDU.dll) WinVerifyTrust
269410a4.530: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDDU.dll
269510a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
269610a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
269710a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
269810a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
269910a4.530: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxVMM.dll
270010a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dsound.dll'...
270110a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'dsound.dll' -> '\Device\HarddiskVolume4\Windows\System32\dsound.dll' [rcNtRedir=0xc0150008]
270210a4.530: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000d90 pwszName=\Device\HarddiskVolume4\Windows\System32\dsound.dll
270310a4.530: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000dbf310
270410a4.530: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000dbf310
270510a4.530: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=ADB542ACB56917DACFC9792CAC57CDEED29A58E5
270610a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
270710a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
270810a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'newdev.dll'...
270910a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'newdev.dll' -> '\Device\HarddiskVolume4\Windows\System32\newdev.dll' [rcNtRedir=0xc0150008]
271010a4.530: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume4\Windows\System32\newdev.dll'.
271110a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
271210a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
271310a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
271410a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
271510a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'uxtheme.dll'.
271610a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'cfgmgr32.dll'.
271710a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'setupapi.dll'.
271810a4.530: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\System32\newdev.dll)
271910a4.530: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\newdev.dll
272010a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
272110a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume4\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
272210a4.530: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\setupapi.dll
272310a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
272410a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
272510a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
272610a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
272710a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
272810a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
272910a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
273010a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume4\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
273110a4.530: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\setupapi.dll
273210a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
273310a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
273410a4.530: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll [lacks WinVerifyTrust]
273510a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'uxtheme.dll'...
273610a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'uxtheme.dll' -> '\Device\HarddiskVolume4\Windows\System32\uxtheme.dll' [rcNtRedir=0xc0150008]
273710a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
273810a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
273910a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
274010a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
274110a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
274210a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
274310a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
274410a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
274510a4.530: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
274610a4.530: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
274710a4.530: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package-AutoMerged-avcore~31bf3856ad364e35~amd64~~6.3.9600.16384.cat'; file='\Device\HarddiskVolume4\Windows\System32\dsound.dll'
274810a4.530: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
274910a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
275010a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
275110a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
275210a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ole32.dll'.
275310a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'winmm.dll'.
275410a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'powrprof.dll'.
275510a4.530: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\dsound.dll) WinVerifyTrust
275610a4.530: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\dsound.dll
275710a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
275810a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
275910a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'powrprof.dll'...
276010a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'powrprof.dll' -> '\Device\HarddiskVolume4\Windows\System32\powrprof.dll' [rcNtRedir=0xc0150008]
276110a4.530: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
276210a4.530: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
276310a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
276410a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'rpcrt4.dll'.
276510a4.530: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\powrprof.dll) WinVerifyTrust
276610a4.530: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\powrprof.dll
276710a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
276810a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume4\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
276910a4.530: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmm.dll
277010a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
277110a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
277210a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
277310a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
277410a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
277510a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
277610a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
277710a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
277810a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
277910a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
278010a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
278110a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
278210a4.530: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox/VBoxDD.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
278310a4.530: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDD.dll
278410a4.530: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\dsound.dll
278510a4.530: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDDU.dll
278610a4.530: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDD2.dll
278710a4.530: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\IPHLPAPI.DLL
278810a4.530: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\powrprof.dll
278910a4.530: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\newdev.dll [avoiding WinVerifyTrust]
279010a4.530: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winnsi.dll [avoiding WinVerifyTrust]
279110a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
279210a4.530: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\System32\devrtl.dll)
279310a4.530: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\devrtl.dll
279410a4.530: supR3HardenedDllNotificationCallback: load 00007fffe5d90000 LB 0x00045000 C:\Windows\SYSTEM32\POWRPROF.dll [fFlags=0x0]
279510a4.530: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\powrprof.dll
279610a4.530: supR3HardenedDllNotificationCallback: load 00007fffd7060000 LB 0x00087000 C:\Windows\SYSTEM32\DSOUND.dll [fFlags=0x0]
279710a4.530: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\dsound.dll
279810a4.530: supR3HardenedDllNotificationCallback: load 00007fffe6d50000 LB 0x001d4000 C:\Windows\system32\SETUPAPI.dll [fFlags=0x0]
279910a4.530: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\setupapi.dll
280010a4.530: supR3HardenedDllNotificationCallback: load 00007fffdba60000 LB 0x00014000 C:\Windows\SYSTEM32\devrtl.DLL [fFlags=0x0]
280110a4.530: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\devrtl.dll [avoiding WinVerifyTrust]
280210a4.530: supR3HardenedDllNotificationCallback: load 00007fffe9140000 LB 0x00054000 C:\Windows\SYSTEM32\newdev.dll [fFlags=0x0]
280310a4.530: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\newdev.dll [avoiding WinVerifyTrust]
280410a4.530: supR3HardenedDllNotificationCallback: load 00007fffe90d0000 LB 0x00061000 C:\Program Files\Oracle\VirtualBox\VBoxDDU.dll [fFlags=0x0]
280510a4.530: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDDU.dll
280610a4.530: supR3HardenedDllNotificationCallback: load 00007fffe9080000 LB 0x00035000 C:\Program Files\Oracle\VirtualBox\VBoxDD2.dll [fFlags=0x0]
280710a4.530: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDD2.dll
280810a4.530: supR3HardenedDllNotificationCallback: load 00007fffe1320000 LB 0x0000a000 C:\Windows\SYSTEM32\WINNSI.DLL [fFlags=0x0]
280910a4.530: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winnsi.dll [avoiding WinVerifyTrust]
281010a4.530: supR3HardenedDllNotificationCallback: load 00007fffe1370000 LB 0x00029000 C:\Windows\SYSTEM32\IPHLPAPI.DLL [fFlags=0x0]
281110a4.530: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\IPHLPAPI.DLL
281210a4.530: supR3HardenedDllNotificationCallback: load 00007fffba410000 LB 0x008e1000 C:\Program Files\Oracle\VirtualBox\VBoxDD.DLL [fFlags=0x0]
281310a4.530: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDD.dll
281410a4.530: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume4\Windows\System32\devrtl.dll'.
281510a4.530: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\devrtl.dll' [rescheduled]
281610a4.530: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume4\Windows\System32\newdev.dll'.
281710a4.530: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\newdev.dll' [rescheduled]
281810a4.530: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\winnsi.dll'.
281910a4.530: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\winnsi.dll' [rescheduled]
282010a4.530: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\dsound.dll
282110a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
282210a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
282310a4.530: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\SYSTEM32\DSOUND.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
282410a4.530: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffd7060000 'C:\Windows\SYSTEM32\DSOUND.dll'
282510a4.530: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffba410000 'C:\Program Files\Oracle\VirtualBox/VBoxDD.DLL'
282610a4.530: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
282710a4.530: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
282810a4.530: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.amd64/VBoxHostWebcam.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
282910a4.530: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
283010a4.530: supR3HardenedDllNotificationCallback: load 00007fffe2390000 LB 0x00033000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL [fFlags=0x0]
283110a4.530: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
283210a4.530: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe2390000 'C:\Program Files\Oracle\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.amd64/VBoxHostWebcam.DLL'
283310a4.530: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
283410a4.530: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxC.dll
283510a4.530: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox/VBoxC.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
283610a4.530: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffbc820000 'C:\Program Files\Oracle\VirtualBox/VBoxC.DLL'
283710a4.530: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
283810a4.530: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDD2.dll
283910a4.530: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox/VBoxDD2.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
284010a4.530: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe9080000 'C:\Program Files\Oracle\VirtualBox/VBoxDD2.DLL'
284110a4.530: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
284210a4.530: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
284310a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
284410a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
284510a4.530: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.dll) WinVerifyTrust
284610a4.530: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.dll
284710a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
284810a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
284910a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
285010a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
285110a4.530: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.amd64/VBoxEhciR3.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
285210a4.530: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.dll
285310a4.530: supR3HardenedDllNotificationCallback: load 00007fffe9060000 LB 0x0001d000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.DLL [fFlags=0x0]
285410a4.530: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.dll
285510a4.530: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe9060000 'C:\Program Files\Oracle\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.amd64/VBoxEhciR3.DLL'
285610a4.530: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
285710a4.530: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
285810a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
285910a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
286010a4.530: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.dll) WinVerifyTrust
286110a4.530: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.dll
286210a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
286310a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
286410a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
286510a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
286610a4.530: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.amd64/VBoxUsbCardReaderR3.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
286710a4.530: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.dll
286810a4.530: supR3HardenedDllNotificationCallback: load 00007fffe29f0000 LB 0x00018000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.DLL [fFlags=0x0]
286910a4.530: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.dll
287010a4.530: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe29f0000 'C:\Program Files\Oracle\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.amd64/VBoxUsbCardReaderR3.DLL'
287110a4.530: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
287210a4.530: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
287310a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
287410a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
287510a4.530: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.dll) WinVerifyTrust
287610a4.530: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.dll
287710a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
287810a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
287910a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
288010a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
288110a4.530: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.amd64/VBoxUsbWebcamR3.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
288210a4.530: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.dll
288310a4.530: supR3HardenedDllNotificationCallback: load 00007fffe2760000 LB 0x00019000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.DLL [fFlags=0x0]
288410a4.530: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.dll
288510a4.530: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe2760000 'C:\Program Files\Oracle\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.amd64/VBoxUsbWebcamR3.DLL'
288610a4.530: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
288710a4.530: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
288810a4.1718: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
288910a4.1718: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
289010a4.1718: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
289110a4.1718: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
289210a4.1718: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll) WinVerifyTrust
289310a4.1718: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll
289410a4.1718: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
289510a4.1718: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
289610a4.1718: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
289710a4.1718: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
289810a4.1718: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxVMM.dll
289910a4.1718: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
290010a4.1718: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
290110a4.1718: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
290210a4.1718: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll
290310a4.1718: supR3HardenedDllNotificationCallback: load 00007fffe8dc0000 LB 0x0000d000 C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL [fFlags=0x0]
290410a4.1718: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll
290510a4.1718: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe8dc0000 'C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL'
290610a4.530: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
290710a4.530: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
290810a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
290910a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
291010a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
291110a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'gdi32.dll'.
291210a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'advapi32.dll'.
291310a4.530: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.dll) WinVerifyTrust
291410a4.530: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.dll
291510a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
291610a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
291710a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
291810a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
291910a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
292010a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
292110a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
292210a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
292310a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
292410a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
292510a4.530: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.amd64/VDPluginCrypt.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
292610a4.530: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.dll
292710a4.530: supR3HardenedDllNotificationCallback: load 00007fffddfa0000 LB 0x000c4000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.DLL [fFlags=0x0]
292810a4.530: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.dll
292910a4.530: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffddfa0000 'C:\Program Files\Oracle\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.amd64/VDPluginCrypt.DLL'
293010a4.530: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\IPHLPAPI.DLL
293110a4.530: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32/Iphlpapi.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
293210a4.530: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe1370000 'C:\Windows\system32/Iphlpapi.dll'
293310a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'rpcrt4.dll'.
293410a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ws2_32.dll'.
293510a4.530: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\System32\dhcpcsvc6.dll)
293610a4.530: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\dhcpcsvc6.dll
293710a4.530: supR3HardenedDllNotificationCallback: load 00007fffe0f50000 LB 0x00014000 C:\Windows\SYSTEM32\dhcpcsvc6.DLL [fFlags=0x0]
293810a4.530: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\dhcpcsvc6.dll [avoiding WinVerifyTrust]
293910a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rpcrt4.dll'.
294010a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ws2_32.dll'.
294110a4.530: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'nsi.dll'.
294210a4.530: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\System32\dhcpcsvc.dll)
294310a4.530: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\dhcpcsvc.dll
294410a4.530: supR3HardenedDllNotificationCallback: load 00007fffe1020000 LB 0x00019000 C:\Windows\SYSTEM32\dhcpcsvc.DLL [fFlags=0x0]
294510a4.530: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\dhcpcsvc.dll [avoiding WinVerifyTrust]
294610a4.530: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000f68 pwszName=\Device\HarddiskVolume4\Windows\System32\dhcpcsvc.dll
294710a4.530: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000dbf310
294810a4.530: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000dbf310
294910a4.530: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=5325E9A5D4C6ECE16AA73B6D9686369868F589BE
295010a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
295110a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume4\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
295210a4.530: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\nsi.dll [lacks WinVerifyTrust]
295310a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
295410a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
295510a4.530: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ws2_32.dll
295610a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
295710a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
295810a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
295910a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
296010a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
296110a4.530: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
296210a4.530: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
296310a4.530: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
296410a4.530: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_155_for_KB2919355~31bf3856ad364e35~amd64~~6.3.1.14.cat'; file='\Device\HarddiskVolume4\Windows\System32\dhcpcsvc.dll'
296510a4.530: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
296610a4.530: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\dhcpcsvc.dll'
296710a4.530: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000f5c pwszName=\Device\HarddiskVolume4\Windows\System32\dhcpcsvc6.dll
296810a4.530: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000dbf310
296910a4.530: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000dbf310
297010a4.530: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=427F9E22A3130EE4C7C75D62DD2A4FFDD7FDEA10
297110a4.530: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
297210a4.530: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
297310a4.530: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_155_for_KB2919355~31bf3856ad364e35~amd64~~6.3.1.14.cat'; file='\Device\HarddiskVolume4\Windows\System32\dhcpcsvc6.dll'
297410a4.530: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
297510a4.530: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\dhcpcsvc6.dll'
297610a4.530: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffd4de0000 'C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL'
297710a4.530: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
297810a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe70d0000 'C:\Windows\system32\user32.dll'
297910a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmm.dll
298010a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\SYSTEM32\WINMM.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
298110a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe3880000 'C:\Windows\SYSTEM32\WINMM.dll'
298210a4.530: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\kernel32.dll
298310a4.530: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32/kernel32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
298410a4.530: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6f30000 'C:\Windows\system32/kernel32.dll'
298510a4.1ac8: '\Device\HarddiskVolume4\Windows\System32\tzres.dll' has no imports
298610a4.1ac8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\System32\tzres.dll)
298710a4.1ac8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\tzres.dll
298810a4.1ac8: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\tzres.dll [avoiding WinVerifyTrust]
298910a4.1ac8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000001134 pwszName=\Device\HarddiskVolume4\Windows\System32\tzres.dll
299010a4.1ac8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000dbf310
299110a4.1ac8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000dbf310
299210a4.1ac8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6200000 'C:\Windows\System32\WINTRUST.DLL'
299310a4.1ac8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\CRYPT32.dll'
299410a4.1ac8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2C2912B1AF73A6796732D1488D75007F742A3299
299510a4.1ac8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
299610a4.1ac8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
299710a4.1ac8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3574_for_KB2919355~31bf3856ad364e35~amd64~~6.3.1.14.cat'; file='\Device\HarddiskVolume4\Windows\System32\tzres.dll'
299810a4.1ac8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
299910a4.1ac8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\tzres.dll'
300010a4.1ac8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000007a8 pwszName=\Device\HarddiskVolume4\Windows\System32\mswsock.dll
300110a4.1ac8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000dbf310
300210a4.1ac8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000dbf310
300310a4.1ac8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=C64ACDC3BD0BFFE24C87951473EBAE5CBEDAA02F
300410a4.1ac8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
300510a4.1ac8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
300610a4.1ac8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-CoreSystem-Minio-Package~31bf3856ad364e35~amd64~~6.3.9600.16384.cat'; file='\Device\HarddiskVolume4\Windows\System32\mswsock.dll'
300710a4.1ac8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
300810a4.1ac8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rpcrt4.dll'.
300910a4.1ac8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ws2_32.dll'.
301010a4.1ac8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\mswsock.dll) WinVerifyTrust
301110a4.1ac8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\mswsock.dll
301210a4.1ac8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
301310a4.1ac8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
301410a4.1ac8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
301510a4.1ac8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
301610a4.1ac8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\mswsock.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
301710a4.1ac8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\mswsock.dll
301810a4.1ac8: supR3HardenedDllNotificationCallback: load 00007fffe5610000 LB 0x00058000 C:\Windows\system32\mswsock.dll [fFlags=0x0]
301910a4.1ac8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\mswsock.dll
302010a4.1ac8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe5610000 'C:\Windows\system32\mswsock.dll'
302110a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000e5c pwszName=\Device\HarddiskVolume4\Windows\System32\mscms.dll
302210a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000dbf310
302310a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000dbf310
302410a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=603F84ABA4E8DD75D802CF57F5ABB2D0968221E0
302510a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
302610a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
302710a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package-AutoMerged-windows~31bf3856ad364e35~amd64~~6.3.9600.16384.cat'; file='\Device\HarddiskVolume4\Windows\System32\mscms.dll'
302810a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
302910a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
303010a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'userenv.dll'.
303110a4.2c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\mscms.dll) WinVerifyTrust
303210a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\mscms.dll
303310a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'userenv.dll'...
303410a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'userenv.dll' -> '\Device\HarddiskVolume4\Windows\System32\userenv.dll' [rcNtRedir=0xc0150008]
303510a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\userenv.dll
303610a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
303710a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
303810a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\mscms.dll (Input=mscms.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
303910a4.2c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\mscms.dll
304010a4.2c8: supR3HardenedDllNotificationCallback: load 00007fffbfa80000 LB 0x0008d000 C:\Windows\system32\mscms.dll [fFlags=0x0]
304110a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\mscms.dll
304210a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffbfa80000 'C:\Windows\system32\mscms.dll'
304310a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000011b0 pwszName=\Device\HarddiskVolume4\Windows\System32\icm32.dll
304410a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000dbf310
304510a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000dbf310
304610a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=87FD7D3BB298BC790CD5163953E8A559775122F0
304710a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe52f0000 'C:\Windows\system32\rsaenh.dll'
304810a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe6020000 'C:\Windows\system32\crypt32.dll'
304910a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package-AutoMerged-windows~31bf3856ad364e35~amd64~~6.3.9600.16384.cat'; file='\Device\HarddiskVolume4\Windows\System32\icm32.dll'
305010a4.2c8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
305110a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
305210a4.2c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'mscms.dll'.
305310a4.2c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\icm32.dll) WinVerifyTrust
305410a4.2c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\icm32.dll
305510a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mscms.dll'...
305610a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'mscms.dll' -> '\Device\HarddiskVolume4\Windows\System32\mscms.dll' [rcNtRedir=0xc0150008]
305710a4.2c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\mscms.dll
305810a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
305910a4.2c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
306010a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\icm32.dll (Input=icm32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
306110a4.2c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\icm32.dll
306210a4.2c8: supR3HardenedDllNotificationCallback: load 00007fffe2340000 LB 0x00041000 C:\Windows\system32\icm32.dll [fFlags=0x0]
306310a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\icm32.dll
306410a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe2340000 'C:\Windows\system32\icm32.dll'
306510a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\shell32.dll
306610a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
306710a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe73c0000 'C:\Windows\system32\shell32.dll'
306810a4.2c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\shell32.dll
306910a4.2c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
307010a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe73c0000 'C:\Windows\system32\shell32.dll'
307110a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe73c0000 'C:\Windows\system32\shell32.dll'
307210a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe73c0000 'C:\Windows\system32\shell32.dll'
307310a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe73c0000 'C:\Windows\system32\shell32.dll'
307410a4.2c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffe73c0000 'C:\Windows\system32\shell32.dll'
3075c8c.ec4: supR3HardNtChildWaitFor[2]: Quitting: ExitCode=0xc0000374 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 212922 ms, the end);
30761dcc.1798: supR3HardNtChildWaitFor[1]: Quitting: ExitCode=0xc0000374 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 213681 ms, the end);

© 2024 Oracle Support Privacy / Do Not Sell My Info Terms of Use Trademark Policy Automated Access Etiquette