VirtualBox

Ticket #14642: VBoxStartup.log

File VBoxStartup.log, 289.8 KB (added by Jörg Hofmann, 9 years ago)

vb startup log

Line 
1a70.1c88: Log file opened: 5.0.4r102546 g_hStartupLog=0000000000000120 g_uNtVerCombined=0xa0280000
2a70.1c88: \SystemRoot\System32\ntdll.dll:
3a70.1c88: CreationTime: 2015-09-25T20:05:35.147044800Z
4a70.1c88: LastWriteTime: 2015-08-08T07:29:58.168349600Z
5a70.1c88: ChangeTime: 2015-09-25T20:22:15.663609100Z
6a70.1c88: FileAttributes: 0x20
7a70.1c88: Size: 0x1bce48
8a70.1c88: NT Headers: 0xd8
9a70.1c88: Timestamp: 0x55c59f92
10a70.1c88: Machine: 0x8664 - amd64
11a70.1c88: Timestamp: 0x55c59f92
12a70.1c88: Image Version: 10.0
13a70.1c88: SizeOfImage: 0x1c1000 (1839104)
14a70.1c88: Resource Dir: 0x15a000 LB 0x65718
15a70.1c88: ProductName: Microsoft® Windows® Operating System
16a70.1c88: ProductVersion: 10.0.10240.16430
17a70.1c88: FileVersion: 10.0.10240.16430 (th1.150807-2049)
18a70.1c88: FileDescription: NT Layer DLL
19a70.1c88: \SystemRoot\System32\kernel32.dll:
20a70.1c88: CreationTime: 2015-07-10T10:59:59.699781600Z
21a70.1c88: LastWriteTime: 2015-07-10T10:59:59.699781600Z
22a70.1c88: ChangeTime: 2015-09-25T07:06:16.935797300Z
23a70.1c88: FileAttributes: 0x20
24a70.1c88: Size: 0xab830
25a70.1c88: NT Headers: 0xf0
26a70.1c88: Timestamp: 0x559f38ad
27a70.1c88: Machine: 0x8664 - amd64
28a70.1c88: Timestamp: 0x559f38ad
29a70.1c88: Image Version: 10.0
30a70.1c88: SizeOfImage: 0xad000 (708608)
31a70.1c88: Resource Dir: 0xab000 LB 0x518
32a70.1c88: ProductName: Microsoft® Windows® Operating System
33a70.1c88: ProductVersion: 10.0.10240.16384
34a70.1c88: FileVersion: 10.0.10240.16384 (th1.150709-1700)
35a70.1c88: FileDescription: Windows NT BASE API Client DLL
36a70.1c88: \SystemRoot\System32\KernelBase.dll:
37a70.1c88: CreationTime: 2015-07-10T11:00:10.325689700Z
38a70.1c88: LastWriteTime: 2015-07-10T11:00:10.325689700Z
39a70.1c88: ChangeTime: 2015-09-25T07:06:16.998301400Z
40a70.1c88: FileAttributes: 0x20
41a70.1c88: Size: 0x1dc680
42a70.1c88: NT Headers: 0x100
43a70.1c88: Timestamp: 0x559f38c3
44a70.1c88: Machine: 0x8664 - amd64
45a70.1c88: Timestamp: 0x559f38c3
46a70.1c88: Image Version: 10.0
47a70.1c88: SizeOfImage: 0x1dd000 (1953792)
48a70.1c88: Resource Dir: 0x1c7000 LB 0x530
49a70.1c88: ProductName: Microsoft® Windows® Operating System
50a70.1c88: ProductVersion: 10.0.10240.16384
51a70.1c88: FileVersion: 10.0.10240.16384 (th1.150709-1700)
52a70.1c88: FileDescription: Windows NT BASE API Client DLL
53a70.1c88: \SystemRoot\System32\apisetschema.dll:
54a70.1c88: CreationTime: 2015-07-10T11:00:04.872098600Z
55a70.1c88: LastWriteTime: 2015-07-10T11:00:04.872098600Z
56a70.1c88: ChangeTime: 2015-09-25T07:06:14.701298100Z
57a70.1c88: FileAttributes: 0x20
58a70.1c88: Size: 0x16760
59a70.1c88: NT Headers: 0xc8
60a70.1c88: Timestamp: 0x559f3e3d
61a70.1c88: Machine: 0x8664 - amd64
62a70.1c88: Timestamp: 0x559f3e3d
63a70.1c88: Image Version: 10.0
64a70.1c88: SizeOfImage: 0x17000 (94208)
65a70.1c88: Resource Dir: 0x16000 LB 0x3f0
66a70.1c88: ProductName: Microsoft® Windows® Operating System
67a70.1c88: ProductVersion: 10.0.10240.16384
68a70.1c88: FileVersion: 10.0.10240.16384 (th1.150709-1700)
69a70.1c88: FileDescription: ApiSet Schema DLL
70a70.1c88: NtOpenDirectoryObject failed on \Driver: 0xc0000022
71a70.1c88: supR3HardenedWinFindAdversaries: 0x100
72a70.1c88: \SystemRoot\System32\drivers\avgrkx64.sys:
73a70.1c88: CreationTime: 2015-03-20T10:18:18.000000000Z
74a70.1c88: LastWriteTime: 2015-03-20T10:18:18.000000000Z
75a70.1c88: ChangeTime: 2015-09-25T06:34:23.860789900Z
76a70.1c88: FileAttributes: 0x20
77a70.1c88: Size: 0x9fe0
78a70.1c88: NT Headers: 0xe8
79a70.1c88: Timestamp: 0x550bf3e7
80a70.1c88: Machine: 0x8664 - amd64
81a70.1c88: Timestamp: 0x550bf3e7
82a70.1c88: Image Version: 6.2
83a70.1c88: SizeOfImage: 0xa000 (40960)
84a70.1c88: Resource Dir: 0x9000 LB 0x510
85a70.1c88: ProductName: AVG Internet Security
86a70.1c88: ProductVersion: 15.0.0.5908
87a70.1c88: FileVersion: 15.0.0.5908
88a70.1c88: SpecialBuild: AvCompile_2015_0320_111532(5908), SVNRev 18c4578e1c294cb8006a179b834157155925d4af (release/SmallUpdate2015-04_beta), av
89a70.1c88: PrivateBuild: x64 Release_Unicode_DRIVER
90a70.1c88: FileDescription: AVG Anti-Rootkit Driver
91a70.1c88: \SystemRoot\System32\drivers\avgmfx64.sys:
92a70.1c88: CreationTime: 2015-08-04T09:32:32.000000000Z
93a70.1c88: LastWriteTime: 2015-08-04T09:32:32.000000000Z
94a70.1c88: ChangeTime: 2015-09-25T06:34:25.407743600Z
95a70.1c88: FileAttributes: 0x20
96a70.1c88: Size: 0x3d3b0
97a70.1c88: NT Headers: 0xe0
98a70.1c88: Timestamp: 0x55c086ac
99a70.1c88: Machine: 0x8664 - amd64
100a70.1c88: Timestamp: 0x55c086ac
101a70.1c88: Image Version: 6.2
102a70.1c88: SizeOfImage: 0x3e000 (253952)
103a70.1c88: Resource Dir: 0x3c000 LB 0x52c
104a70.1c88: ProductName: AVG Internet Security
105a70.1c88: ProductVersion: 15.0.0.6132
106a70.1c88: FileVersion: 15.0.0.6132
107a70.1c88: SpecialBuild: AvCompile_2015_0804_112815(6132), SVNRev cbac1c769cb9b6888db1f1065b4133bf3c9ce40f (release/SmallUpdate2015-08_beta), av
108a70.1c88: PrivateBuild: x64 Release_Unicode_DRIVER
109a70.1c88: FileDescription: AVG Resident Shield Minifilter Driver
110a70.1c88: \SystemRoot\System32\drivers\avgidsdrivera.sys:
111a70.1c88: CreationTime: 2015-08-19T09:52:30.000000000Z
112a70.1c88: LastWriteTime: 2015-08-19T09:52:30.000000000Z
113a70.1c88: ChangeTime: 2015-09-25T06:34:26.104269300Z
114a70.1c88: FileAttributes: 0x20
115a70.1c88: Size: 0x4c7b0
116a70.1c88: NT Headers: 0xe8
117a70.1c88: Timestamp: 0x55d451da
118a70.1c88: Machine: 0x8664 - amd64
119a70.1c88: Timestamp: 0x55d451da
120a70.1c88: Image Version: 6.2
121a70.1c88: SizeOfImage: 0x53000 (339968)
122a70.1c88: Resource Dir: 0x51000 LB 0x554
123a70.1c88: ProductName: AVG Internet Security
124a70.1c88: ProductVersion: 15.0.0.6137
125a70.1c88: FileVersion: 15.0.0.6137
126a70.1c88: SpecialBuild: AvCompile_2015_0819_113418(6137), SVNRev 7ade868631072664eb184732ae422a4307e58f68 (release/SmallUpdate2015-08_release), av
127a70.1c88: PrivateBuild: x64 Release_Unicode_DRIVER
128a70.1c88: FileDescription: AVG IDS Application Activity Monitor Driver.
129a70.1c88: \SystemRoot\System32\drivers\avgidsha.sys:
130a70.1c88: CreationTime: 2015-08-19T09:53:56.000000000Z
131a70.1c88: LastWriteTime: 2015-08-19T09:53:56.000000000Z
132a70.1c88: ChangeTime: 2015-09-25T06:34:26.026140600Z
133a70.1c88: FileAttributes: 0x20
134a70.1c88: Size: 0x48bb0
135a70.1c88: NT Headers: 0xd8
136a70.1c88: Timestamp: 0x55d45230
137a70.1c88: Machine: 0x8664 - amd64
138a70.1c88: Timestamp: 0x55d45230
139a70.1c88: Image Version: 6.2
140a70.1c88: SizeOfImage: 0x49000 (299008)
141a70.1c88: Resource Dir: 0x47000 LB 0x548
142a70.1c88: ProductName: AVG Internet Security
143a70.1c88: ProductVersion: 15.0.0.6137
144a70.1c88: FileVersion: 15.0.0.6137
145a70.1c88: SpecialBuild: AvCompile_2015_0819_113418(6137), SVNRev 7ade868631072664eb184732ae422a4307e58f68 (release/SmallUpdate2015-08_release), av
146a70.1c88: PrivateBuild: x64 Release_Unicode_DRIVER
147a70.1c88: FileDescription: AVG Application Activity Monitor Helper Driver
148a70.1c88: \SystemRoot\System32\drivers\avgloga.sys:
149a70.1c88: CreationTime: 2015-05-07T11:50:22.000000000Z
150a70.1c88: LastWriteTime: 2015-05-07T11:50:22.000000000Z
151a70.1c88: ChangeTime: 2015-09-25T06:34:23.767034300Z
152a70.1c88: FileAttributes: 0x20
153a70.1c88: Size: 0x5c5e0
154a70.1c88: NT Headers: 0xf0
155a70.1c88: Timestamp: 0x554b5179
156a70.1c88: Machine: 0x8664 - amd64
157a70.1c88: Timestamp: 0x554b5179
158a70.1c88: Image Version: 6.2
159a70.1c88: SizeOfImage: 0x5b000 (372736)
160a70.1c88: Resource Dir: 0x59000 LB 0x4ec
161a70.1c88: ProductName: AVG Internet Security
162a70.1c88: ProductVersion: 15.0.0.5957
163a70.1c88: FileVersion: 15.0.0.5957
164a70.1c88: SpecialBuild: AvCompile_2015_0507_134328(5957), SVNRev bcddc515e1405c8e35481b16de334020e451ec3e (release/HotFix2015-05), av
165a70.1c88: PrivateBuild: x64 Release_Unicode_DRIVER
166a70.1c88: FileDescription: AVG Logging Driver
167a70.1c88: \SystemRoot\System32\drivers\avgldx64.sys:
168a70.1c88: CreationTime: 2015-06-16T13:55:04.000000000Z
169a70.1c88: LastWriteTime: 2015-06-16T13:55:04.000000000Z
170a70.1c88: ChangeTime: 2015-09-25T06:34:23.970170200Z
171a70.1c88: FileAttributes: 0x20
172a70.1c88: Size: 0x3f3e0
173a70.1c88: NT Headers: 0xe0
174a70.1c88: Timestamp: 0x55802aaf
175a70.1c88: Machine: 0x8664 - amd64
176a70.1c88: Timestamp: 0x55802aaf
177a70.1c88: Image Version: 6.2
178a70.1c88: SizeOfImage: 0x42000 (270336)
179a70.1c88: Resource Dir: 0x40000 LB 0x50c
180a70.1c88: ProductName: AVG Internet Security
181a70.1c88: ProductVersion: 15.0.0.6055
182a70.1c88: FileVersion: 15.0.0.6055
183a70.1c88: SpecialBuild: AvCompile_2015_0616_154836(6055), SVNRev 309d50c06d2885375935ac1c0a79cdb255cb7045 (release/SmallUpdate2015-06_beta), av
184a70.1c88: PrivateBuild: x64 Release_Unicode_DRIVER
185a70.1c88: FileDescription: AVG AVI Loader Driver
186a70.1c88: \SystemRoot\System32\drivers\avgdiska.sys:
187a70.1c88: CreationTime: 2015-03-11T10:16:06.000000000Z
188a70.1c88: LastWriteTime: 2015-03-11T10:16:06.000000000Z
189a70.1c88: ChangeTime: 2015-09-25T06:34:26.307403800Z
190a70.1c88: FileAttributes: 0x20
191a70.1c88: Size: 0x27be0
192a70.1c88: NT Headers: 0xe0
193a70.1c88: Timestamp: 0x550015e3
194a70.1c88: Machine: 0x8664 - amd64
195a70.1c88: Timestamp: 0x550015e3
196a70.1c88: Image Version: 6.2
197a70.1c88: SizeOfImage: 0x29000 (167936)
198a70.1c88: Resource Dir: 0x27000 LB 0x4e0
199a70.1c88: ProductName: AVG Internet Security
200a70.1c88: ProductVersion: 15.0.0.5902
201a70.1c88: FileVersion: 15.0.0.5902
202a70.1c88: SpecialBuild: AvCompile_2015_0311_110513(5902), SVNRev d57888a6d0541615b2b2c643813a0b67abc3acba (av/devel), av
203a70.1c88: PrivateBuild: x64 Release_Unicode_DRIVER
204a70.1c88: FileDescription: AVG File Vault Driver
205a70.1c88: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox'
206a70.1c88: Calling main()
207a70.1c88: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
208a70.1c88: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox'
209a70.1c88: SUPR3HardenedMain: Respawn #1
210a70.1c88: System32: \Device\HarddiskVolume5\Windows\System32
211a70.1c88: WinSxS: \Device\HarddiskVolume5\Windows\WinSxS
212a70.1c88: KnownDllPath: C:\WINDOWS\system32
213a70.1c88: '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
214a70.1c88: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBox.exe)
215a70.1c88: supR3HardNtEnableThreadCreation:
216a70.1c88: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffc43ecfb70 pvNtTerminateThread=00007ffc43ef3a20
217a70.1c88: supR3HardenedWinDoReSpawn(1): New child 26dc.3020 [kernel32].
218a70.1c88: supR3HardNtChildGatherData: PebBaseAddress=00007ff654adb000 cbPeb=0x388
219a70.1c88: supR3HardNtPuChFindNtdll: uNtDllParentAddr=00007ffc43e60000 uNtDllChildAddr=00007ffc43e60000
220a70.1c88: supR3HardenedWinSetupChildInit: uLdrInitThunk=00007ffc43ecfb70
221a70.1c88: supR3HardenedWinSetupChildInit: Start child.
222a70.1c88: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
223a70.1c88: supR3HardNtChildPurify: Startup delay kludge #1/0: 516 ms, 33 sleeps
224a70.1c88: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
225a70.1c88: *0000000000000000-ffffffffff34ffff 0x0001/0x0000 0x0000000
226a70.1c88: *0000000000cb0000-0000000000c8ffff 0x0004/0x0004 0x0020000
227a70.1c88: *0000000000cd0000-0000000000cbbfff 0x0002/0x0002 0x0040000
228a70.1c88: 0000000000ce4000-0000000000cd7fff 0x0001/0x0000 0x0000000
229a70.1c88: *0000000000cf0000-0000000000bf3fff 0x0000/0x0004 0x0020000
230a70.1c88: 0000000000dec000-0000000000de8fff 0x0104/0x0004 0x0020000
231a70.1c88: 0000000000def000-0000000000dedfff 0x0004/0x0004 0x0020000
232a70.1c88: *0000000000df0000-0000000000debfff 0x0002/0x0002 0x0040000
233a70.1c88: 0000000000df4000-0000000000de7fff 0x0001/0x0000 0x0000000
234a70.1c88: *0000000000e00000-0000000000dfdfff 0x0004/0x0004 0x0020000
235a70.1c88: 0000000000e02000-ffffffff81c23fff 0x0001/0x0000 0x0000000
236a70.1c88: *000000007ffe0000-000000007ffdefff 0x0002/0x0002 0x0020000
237a70.1c88: 000000007ffe1000-000000007ffd1fff 0x0000/0x0002 0x0020000
238a70.1c88: 000000007fff0000-ffff800aab52ffff 0x0001/0x0000 0x0000000
239a70.1c88: *00007ff654ab0000-00007ff654a8cfff 0x0002/0x0002 0x0040000
240a70.1c88: 00007ff654ad3000-00007ff654acafff 0x0001/0x0000 0x0000000
241a70.1c88: *00007ff654adb000-00007ff654ad9fff 0x0004/0x0004 0x0020000
242a70.1c88: 00007ff654adc000-00007ff654ad9fff 0x0001/0x0000 0x0000000
243a70.1c88: *00007ff654ade000-00007ff654adbfff 0x0004/0x0004 0x0020000
244a70.1c88: 00007ff654ae0000-00007ff653bcffff 0x0001/0x0000 0x0000000
245a70.1c88: *00007ff6559f0000-00007ff6559f0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBox.exe
246a70.1c88: 00007ff6559f1000-00007ff655a77fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBox.exe
247a70.1c88: 00007ff655a78000-00007ff655a78fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBox.exe
248a70.1c88: 00007ff655a79000-00007ff655ac3fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBox.exe
249a70.1c88: 00007ff655ac4000-00007ff655ac4fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBox.exe
250a70.1c88: 00007ff655ac5000-00007ff655ac5fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBox.exe
251a70.1c88: 00007ff655ac6000-00007ff655acafff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBox.exe
252a70.1c88: 00007ff655acb000-00007ff655acbfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBox.exe
253a70.1c88: 00007ff655acc000-00007ff655accfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBox.exe
254a70.1c88: 00007ff655acd000-00007ff655ad0fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBox.exe
255a70.1c88: 00007ff655ad1000-00007ff655b1bfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBox.exe
256a70.1c88: 00007ff655b1c000-00007ff0677d7fff 0x0001/0x0000 0x0000000
257a70.1c88: *00007ffc43e60000-00007ffc43e60fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\ntdll.dll
258a70.1c88: 00007ffc43e61000-00007ffc43f5cfff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\ntdll.dll
259a70.1c88: 00007ffc43f5d000-00007ffc43f9efff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\ntdll.dll
260a70.1c88: 00007ffc43f9f000-00007ffc43fa7fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\ntdll.dll
261a70.1c88: 00007ffc43fa8000-00007ffc43fb5fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\ntdll.dll
262a70.1c88: 00007ffc43fb6000-00007ffc43fb6fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\ntdll.dll
263a70.1c88: 00007ffc43fb7000-00007ffc43fb9fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\ntdll.dll
264a70.1c88: 00007ffc43fba000-00007ffc44020fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\ntdll.dll
265a70.1c88: 00007ffc44021000-00007ff888061fff 0x0001/0x0000 0x0000000
266a70.1c88: *00007ffffffe0000-00007ffffffcffff 0x0001/0x0002 0x0020000
267a70.1c88: VirtualBox.exe: timestamp 0x55eeaed7 (rc=VINF_SUCCESS)
268a70.1c88: '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
269a70.1c88: '\Device\HarddiskVolume5\Windows\System32\ntdll.dll' has no imports
270a70.1c88: supR3HardNtChildPurify: Done after 625 ms and 0 fixes (loop #0).
27126dc.3020: Log file opened: 5.0.4r102546 g_hStartupLog=0000000000000004 g_uNtVerCombined=0xa0280000
272a70.1c88: supR3HardNtEnableThreadCreation:
27326dc.3020: supR3HardenedVmProcessInit: uNtDllAddr=00007ffc43e60000
27426dc.3020: ntdll.dll: timestamp 0x55c59f92 (rc=VINF_SUCCESS)
27526dc.3020: New simple heap: #1 0000000000f10000 LB 0x400000 (for 1839104 allocation)
27626dc.3020: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox'
27726dc.3020: System32: \Device\HarddiskVolume5\Windows\System32
27826dc.3020: WinSxS: \Device\HarddiskVolume5\Windows\WinSxS
27926dc.3020: KnownDllPath: C:\WINDOWS\system32
28026dc.3020: supR3HardenedVmProcessInit: Opening vboxdrv stub...
28126dc.3020: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
28226dc.3020: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
28326dc.3020: Registered Dll notification callback with NTDLL.
28426dc.3020: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\kernel32.dll)
28526dc.3020: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\kernel32.dll
28626dc.3020: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\KERNEL32.DLL (Input=KERNEL32.DLL, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000801:<flags> [calling]
28726dc.3020: supR3HardenedDllNotificationCallback: load 00007ffc3ffe0000 LB 0x001dd000 C:\WINDOWS\system32\KERNELBASE.dll [fFlags=0x0]
28826dc.3020: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\KernelBase.dll)
28926dc.3020: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\KernelBase.dll
29026dc.3020: supR3HardenedDllNotificationCallback: load 00007ffc426a0000 LB 0x000ad000 C:\WINDOWS\system32\KERNEL32.DLL [fFlags=0x0]
29126dc.3020: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
29226dc.3020: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc426a0000 'C:\WINDOWS\system32\KERNEL32.DLL'
29326dc.3020: supR3HardenedDllNotificationCallback: load 00007ff6559f0000 LB 0x0012c000 C:\Program Files\Oracle\VirtualBox\VirtualBox.exe [fFlags=0x0]
29426dc.3020: '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
29526dc.3020: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBox.exe)
29626dc.3020: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBox.exe
29726dc.3020: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffc43ecfb70 pvNtTerminateThread=00007ffc43ef3a20
298a70.1c88: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 282 ms.
29926dc.3020: \SystemRoot\System32\ntdll.dll:
30026dc.3020: CreationTime: 2015-09-25T20:05:35.147044800Z
30126dc.3020: LastWriteTime: 2015-08-08T07:29:58.168349600Z
30226dc.3020: ChangeTime: 2015-09-25T20:22:15.663609100Z
30326dc.3020: FileAttributes: 0x20
30426dc.3020: Size: 0x1bce48
30526dc.3020: NT Headers: 0xd8
30626dc.3020: Timestamp: 0x55c59f92
30726dc.3020: Machine: 0x8664 - amd64
30826dc.3020: Timestamp: 0x55c59f92
30926dc.3020: Image Version: 10.0
31026dc.3020: SizeOfImage: 0x1c1000 (1839104)
31126dc.3020: Resource Dir: 0x15a000 LB 0x65718
31226dc.3020: ProductName: Microsoft® Windows® Operating System
31326dc.3020: ProductVersion: 10.0.10240.16430
31426dc.3020: FileVersion: 10.0.10240.16430 (th1.150807-2049)
31526dc.3020: FileDescription: NT Layer DLL
31626dc.3020: \SystemRoot\System32\kernel32.dll:
31726dc.3020: CreationTime: 2015-07-10T10:59:59.699781600Z
31826dc.3020: LastWriteTime: 2015-07-10T10:59:59.699781600Z
31926dc.3020: ChangeTime: 2015-09-25T07:06:16.935797300Z
32026dc.3020: FileAttributes: 0x20
32126dc.3020: Size: 0xab830
32226dc.3020: NT Headers: 0xf0
32326dc.3020: Timestamp: 0x559f38ad
32426dc.3020: Machine: 0x8664 - amd64
32526dc.3020: Timestamp: 0x559f38ad
32626dc.3020: Image Version: 10.0
32726dc.3020: SizeOfImage: 0xad000 (708608)
32826dc.3020: Resource Dir: 0xab000 LB 0x518
32926dc.3020: ProductName: Microsoft® Windows® Operating System
33026dc.3020: ProductVersion: 10.0.10240.16384
33126dc.3020: FileVersion: 10.0.10240.16384 (th1.150709-1700)
33226dc.3020: FileDescription: Windows NT BASE API Client DLL
33326dc.3020: \SystemRoot\System32\KernelBase.dll:
33426dc.3020: CreationTime: 2015-07-10T11:00:10.325689700Z
33526dc.3020: LastWriteTime: 2015-07-10T11:00:10.325689700Z
33626dc.3020: ChangeTime: 2015-09-25T07:06:16.998301400Z
33726dc.3020: FileAttributes: 0x20
33826dc.3020: Size: 0x1dc680
33926dc.3020: NT Headers: 0x100
34026dc.3020: Timestamp: 0x559f38c3
34126dc.3020: Machine: 0x8664 - amd64
34226dc.3020: Timestamp: 0x559f38c3
34326dc.3020: Image Version: 10.0
34426dc.3020: SizeOfImage: 0x1dd000 (1953792)
34526dc.3020: Resource Dir: 0x1c7000 LB 0x530
34626dc.3020: ProductName: Microsoft® Windows® Operating System
34726dc.3020: ProductVersion: 10.0.10240.16384
34826dc.3020: FileVersion: 10.0.10240.16384 (th1.150709-1700)
34926dc.3020: FileDescription: Windows NT BASE API Client DLL
35026dc.3020: \SystemRoot\System32\apisetschema.dll:
35126dc.3020: CreationTime: 2015-07-10T11:00:04.872098600Z
35226dc.3020: LastWriteTime: 2015-07-10T11:00:04.872098600Z
35326dc.3020: ChangeTime: 2015-09-25T07:06:14.701298100Z
35426dc.3020: FileAttributes: 0x20
35526dc.3020: Size: 0x16760
35626dc.3020: NT Headers: 0xc8
35726dc.3020: Timestamp: 0x559f3e3d
35826dc.3020: Machine: 0x8664 - amd64
35926dc.3020: Timestamp: 0x559f3e3d
36026dc.3020: Image Version: 10.0
36126dc.3020: SizeOfImage: 0x17000 (94208)
36226dc.3020: Resource Dir: 0x16000 LB 0x3f0
36326dc.3020: ProductName: Microsoft® Windows® Operating System
36426dc.3020: ProductVersion: 10.0.10240.16384
36526dc.3020: FileVersion: 10.0.10240.16384 (th1.150709-1700)
36626dc.3020: FileDescription: ApiSet Schema DLL
36726dc.3020: NtOpenDirectoryObject failed on \Driver: 0xc0000022
36826dc.3020: supR3HardenedWinFindAdversaries: 0x100
36926dc.3020: \SystemRoot\System32\drivers\avgrkx64.sys:
37026dc.3020: CreationTime: 2015-03-20T10:18:18.000000000Z
37126dc.3020: LastWriteTime: 2015-03-20T10:18:18.000000000Z
37226dc.3020: ChangeTime: 2015-09-25T06:34:23.860789900Z
37326dc.3020: FileAttributes: 0x20
37426dc.3020: Size: 0x9fe0
37526dc.3020: NT Headers: 0xe8
37626dc.3020: Timestamp: 0x550bf3e7
37726dc.3020: Machine: 0x8664 - amd64
37826dc.3020: Timestamp: 0x550bf3e7
37926dc.3020: Image Version: 6.2
38026dc.3020: SizeOfImage: 0xa000 (40960)
38126dc.3020: Resource Dir: 0x9000 LB 0x510
38226dc.3020: ProductName: AVG Internet Security
38326dc.3020: ProductVersion: 15.0.0.5908
38426dc.3020: FileVersion: 15.0.0.5908
38526dc.3020: SpecialBuild: AvCompile_2015_0320_111532(5908), SVNRev 18c4578e1c294cb8006a179b834157155925d4af (release/SmallUpdate2015-04_beta), av
38626dc.3020: PrivateBuild: x64 Release_Unicode_DRIVER
38726dc.3020: FileDescription: AVG Anti-Rootkit Driver
38826dc.3020: \SystemRoot\System32\drivers\avgmfx64.sys:
38926dc.3020: CreationTime: 2015-08-04T09:32:32.000000000Z
39026dc.3020: LastWriteTime: 2015-08-04T09:32:32.000000000Z
39126dc.3020: ChangeTime: 2015-09-25T06:34:25.407743600Z
39226dc.3020: FileAttributes: 0x20
39326dc.3020: Size: 0x3d3b0
39426dc.3020: NT Headers: 0xe0
39526dc.3020: Timestamp: 0x55c086ac
39626dc.3020: Machine: 0x8664 - amd64
39726dc.3020: Timestamp: 0x55c086ac
39826dc.3020: Image Version: 6.2
39926dc.3020: SizeOfImage: 0x3e000 (253952)
40026dc.3020: Resource Dir: 0x3c000 LB 0x52c
40126dc.3020: ProductName: AVG Internet Security
40226dc.3020: ProductVersion: 15.0.0.6132
40326dc.3020: FileVersion: 15.0.0.6132
40426dc.3020: SpecialBuild: AvCompile_2015_0804_112815(6132), SVNRev cbac1c769cb9b6888db1f1065b4133bf3c9ce40f (release/SmallUpdate2015-08_beta), av
40526dc.3020: PrivateBuild: x64 Release_Unicode_DRIVER
40626dc.3020: FileDescription: AVG Resident Shield Minifilter Driver
40726dc.3020: \SystemRoot\System32\drivers\avgidsdrivera.sys:
40826dc.3020: CreationTime: 2015-08-19T09:52:30.000000000Z
40926dc.3020: LastWriteTime: 2015-08-19T09:52:30.000000000Z
41026dc.3020: ChangeTime: 2015-09-25T06:34:26.104269300Z
41126dc.3020: FileAttributes: 0x20
41226dc.3020: Size: 0x4c7b0
41326dc.3020: NT Headers: 0xe8
41426dc.3020: Timestamp: 0x55d451da
41526dc.3020: Machine: 0x8664 - amd64
41626dc.3020: Timestamp: 0x55d451da
41726dc.3020: Image Version: 6.2
41826dc.3020: SizeOfImage: 0x53000 (339968)
41926dc.3020: Resource Dir: 0x51000 LB 0x554
42026dc.3020: ProductName: AVG Internet Security
42126dc.3020: ProductVersion: 15.0.0.6137
42226dc.3020: FileVersion: 15.0.0.6137
42326dc.3020: SpecialBuild: AvCompile_2015_0819_113418(6137), SVNRev 7ade868631072664eb184732ae422a4307e58f68 (release/SmallUpdate2015-08_release), av
42426dc.3020: PrivateBuild: x64 Release_Unicode_DRIVER
42526dc.3020: FileDescription: AVG IDS Application Activity Monitor Driver.
42626dc.3020: \SystemRoot\System32\drivers\avgidsha.sys:
42726dc.3020: CreationTime: 2015-08-19T09:53:56.000000000Z
42826dc.3020: LastWriteTime: 2015-08-19T09:53:56.000000000Z
42926dc.3020: ChangeTime: 2015-09-25T06:34:26.026140600Z
43026dc.3020: FileAttributes: 0x20
43126dc.3020: Size: 0x48bb0
43226dc.3020: NT Headers: 0xd8
43326dc.3020: Timestamp: 0x55d45230
43426dc.3020: Machine: 0x8664 - amd64
43526dc.3020: Timestamp: 0x55d45230
43626dc.3020: Image Version: 6.2
43726dc.3020: SizeOfImage: 0x49000 (299008)
43826dc.3020: Resource Dir: 0x47000 LB 0x548
43926dc.3020: ProductName: AVG Internet Security
44026dc.3020: ProductVersion: 15.0.0.6137
44126dc.3020: FileVersion: 15.0.0.6137
44226dc.3020: SpecialBuild: AvCompile_2015_0819_113418(6137), SVNRev 7ade868631072664eb184732ae422a4307e58f68 (release/SmallUpdate2015-08_release), av
44326dc.3020: PrivateBuild: x64 Release_Unicode_DRIVER
44426dc.3020: FileDescription: AVG Application Activity Monitor Helper Driver
44526dc.3020: \SystemRoot\System32\drivers\avgloga.sys:
44626dc.3020: CreationTime: 2015-05-07T11:50:22.000000000Z
44726dc.3020: LastWriteTime: 2015-05-07T11:50:22.000000000Z
44826dc.3020: ChangeTime: 2015-09-25T06:34:23.767034300Z
44926dc.3020: FileAttributes: 0x20
45026dc.3020: Size: 0x5c5e0
45126dc.3020: NT Headers: 0xf0
45226dc.3020: Timestamp: 0x554b5179
45326dc.3020: Machine: 0x8664 - amd64
45426dc.3020: Timestamp: 0x554b5179
45526dc.3020: Image Version: 6.2
45626dc.3020: SizeOfImage: 0x5b000 (372736)
45726dc.3020: Resource Dir: 0x59000 LB 0x4ec
45826dc.3020: ProductName: AVG Internet Security
45926dc.3020: ProductVersion: 15.0.0.5957
46026dc.3020: FileVersion: 15.0.0.5957
46126dc.3020: SpecialBuild: AvCompile_2015_0507_134328(5957), SVNRev bcddc515e1405c8e35481b16de334020e451ec3e (release/HotFix2015-05), av
46226dc.3020: PrivateBuild: x64 Release_Unicode_DRIVER
46326dc.3020: FileDescription: AVG Logging Driver
46426dc.3020: \SystemRoot\System32\drivers\avgldx64.sys:
46526dc.3020: CreationTime: 2015-06-16T13:55:04.000000000Z
46626dc.3020: LastWriteTime: 2015-06-16T13:55:04.000000000Z
46726dc.3020: ChangeTime: 2015-09-25T06:34:23.970170200Z
46826dc.3020: FileAttributes: 0x20
46926dc.3020: Size: 0x3f3e0
47026dc.3020: NT Headers: 0xe0
47126dc.3020: Timestamp: 0x55802aaf
47226dc.3020: Machine: 0x8664 - amd64
47326dc.3020: Timestamp: 0x55802aaf
47426dc.3020: Image Version: 6.2
47526dc.3020: SizeOfImage: 0x42000 (270336)
47626dc.3020: Resource Dir: 0x40000 LB 0x50c
47726dc.3020: ProductName: AVG Internet Security
47826dc.3020: ProductVersion: 15.0.0.6055
47926dc.3020: FileVersion: 15.0.0.6055
48026dc.3020: SpecialBuild: AvCompile_2015_0616_154836(6055), SVNRev 309d50c06d2885375935ac1c0a79cdb255cb7045 (release/SmallUpdate2015-06_beta), av
48126dc.3020: PrivateBuild: x64 Release_Unicode_DRIVER
48226dc.3020: FileDescription: AVG AVI Loader Driver
48326dc.3020: \SystemRoot\System32\drivers\avgdiska.sys:
48426dc.3020: CreationTime: 2015-03-11T10:16:06.000000000Z
48526dc.3020: LastWriteTime: 2015-03-11T10:16:06.000000000Z
48626dc.3020: ChangeTime: 2015-09-25T06:34:26.307403800Z
48726dc.3020: FileAttributes: 0x20
48826dc.3020: Size: 0x27be0
48926dc.3020: NT Headers: 0xe0
49026dc.3020: Timestamp: 0x550015e3
49126dc.3020: Machine: 0x8664 - amd64
49226dc.3020: Timestamp: 0x550015e3
49326dc.3020: Image Version: 6.2
49426dc.3020: SizeOfImage: 0x29000 (167936)
49526dc.3020: Resource Dir: 0x27000 LB 0x4e0
49626dc.3020: ProductName: AVG Internet Security
49726dc.3020: ProductVersion: 15.0.0.5902
49826dc.3020: FileVersion: 15.0.0.5902
49926dc.3020: SpecialBuild: AvCompile_2015_0311_110513(5902), SVNRev d57888a6d0541615b2b2c643813a0b67abc3acba (av/devel), av
50026dc.3020: PrivateBuild: x64 Release_Unicode_DRIVER
50126dc.3020: FileDescription: AVG File Vault Driver
50226dc.3020: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox'
50326dc.3020: Calling main()
50426dc.3020: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
50526dc.3020: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox'
50626dc.3020: '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
50726dc.3020: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBox.exe)
50826dc.3020: SUPR3HardenedMain: Respawn #2
50926dc.3020: supR3HardNtEnableThreadCreation:
51026dc.3020: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume5\Windows\System32\apphelp.dll)
51126dc.3020: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\apphelp.dll
51226dc.3020: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\apphelp.dll (rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
51326dc.3020: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume5\Windows\System32\apphelp.dll [lacks WinVerifyTrust]
51426dc.3020: supR3HardenedDllNotificationCallback: load 00007ffc3dc30000 LB 0x00078000 C:\WINDOWS\system32\apphelp.dll [fFlags=0x0]
51526dc.3020: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume5\Windows\System32\apphelp.dll [lacks WinVerifyTrust]
51626dc.3020: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3dc30000 'C:\WINDOWS\system32\apphelp.dll'
51726dc.3020: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffc43ecfb70 pvNtTerminateThread=00007ffc43ef3a20
51826dc.3020: supR3HardenedWinDoReSpawn(2): New child 2498.2eb4 [kernel32].
51926dc.3020: supR3HardenedWinReSpawn: NtSetInformationThread/ThreadHideFromDebugger failed: 0xc0000022 (harmless)
52026dc.3020: supR3HardNtChildGatherData: PebBaseAddress=00007ff654acf000 cbPeb=0x388
52126dc.3020: supR3HardNtPuChFindNtdll: uNtDllParentAddr=00007ffc43e60000 uNtDllChildAddr=00007ffc43e60000
52226dc.3020: supR3HardenedWinSetupChildInit: uLdrInitThunk=00007ffc43ecfb70
52326dc.3020: supR3HardenedWinSetupChildInit: Start child.
52426dc.3020: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
52526dc.3020: supR3HardNtChildPurify: Startup delay kludge #1/0: 516 ms, 33 sleeps
52626dc.3020: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
52726dc.3020: *0000000000000000-ffffffffff47ffff 0x0001/0x0000 0x0000000
52826dc.3020: *0000000000b80000-0000000000b5ffff 0x0004/0x0004 0x0020000
52926dc.3020: *0000000000ba0000-0000000000b8bfff 0x0002/0x0002 0x0040000
53026dc.3020: 0000000000bb4000-0000000000ba7fff 0x0001/0x0000 0x0000000
53126dc.3020: *0000000000bc0000-0000000000ac3fff 0x0000/0x0004 0x0020000
53226dc.3020: 0000000000cbc000-0000000000cb8fff 0x0104/0x0004 0x0020000
53326dc.3020: 0000000000cbf000-0000000000cbdfff 0x0004/0x0004 0x0020000
53426dc.3020: *0000000000cc0000-0000000000cbbfff 0x0002/0x0002 0x0040000
53526dc.3020: 0000000000cc4000-0000000000cb7fff 0x0001/0x0000 0x0000000
53626dc.3020: *0000000000cd0000-0000000000ccdfff 0x0004/0x0004 0x0020000
53726dc.3020: 0000000000cd2000-ffffffff819c3fff 0x0001/0x0000 0x0000000
53826dc.3020: *000000007ffe0000-000000007ffdefff 0x0002/0x0002 0x0020000
53926dc.3020: 000000007ffe1000-000000007ffd1fff 0x0000/0x0002 0x0020000
54026dc.3020: 000000007fff0000-ffff800aab53ffff 0x0001/0x0000 0x0000000
54126dc.3020: *00007ff654aa0000-00007ff654a7cfff 0x0002/0x0002 0x0040000
54226dc.3020: 00007ff654ac3000-00007ff654ab8fff 0x0001/0x0000 0x0000000
54326dc.3020: *00007ff654acd000-00007ff654acafff 0x0004/0x0004 0x0020000
54426dc.3020: *00007ff654acf000-00007ff654acdfff 0x0004/0x0004 0x0020000
54526dc.3020: 00007ff654ad0000-00007ff653baffff 0x0001/0x0000 0x0000000
54626dc.3020: *00007ff6559f0000-00007ff6559f0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBox.exe
54726dc.3020: 00007ff6559f1000-00007ff655a77fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBox.exe
54826dc.3020: 00007ff655a78000-00007ff655a78fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBox.exe
54926dc.3020: 00007ff655a79000-00007ff655ac3fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBox.exe
55026dc.3020: 00007ff655ac4000-00007ff655ac4fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBox.exe
55126dc.3020: 00007ff655ac5000-00007ff655ac5fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBox.exe
55226dc.3020: 00007ff655ac6000-00007ff655acafff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBox.exe
55326dc.3020: 00007ff655acb000-00007ff655acbfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBox.exe
55426dc.3020: 00007ff655acc000-00007ff655accfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBox.exe
55526dc.3020: 00007ff655acd000-00007ff655ad0fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBox.exe
55626dc.3020: 00007ff655ad1000-00007ff655b1bfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBox.exe
55726dc.3020: 00007ff655b1c000-00007ff0677d7fff 0x0001/0x0000 0x0000000
55826dc.3020: *00007ffc43e60000-00007ffc43e60fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\ntdll.dll
55926dc.3020: 00007ffc43e61000-00007ffc43f5cfff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\ntdll.dll
56026dc.3020: 00007ffc43f5d000-00007ffc43f9efff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\ntdll.dll
56126dc.3020: 00007ffc43f9f000-00007ffc43fa7fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\ntdll.dll
56226dc.3020: 00007ffc43fa8000-00007ffc43fb5fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\ntdll.dll
56326dc.3020: 00007ffc43fb6000-00007ffc43fb6fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\ntdll.dll
56426dc.3020: 00007ffc43fb7000-00007ffc43fb9fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\ntdll.dll
56526dc.3020: 00007ffc43fba000-00007ffc44020fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\ntdll.dll
56626dc.3020: 00007ffc44021000-00007ff888061fff 0x0001/0x0000 0x0000000
56726dc.3020: *00007ffffffe0000-00007ffffffcffff 0x0001/0x0002 0x0020000
56826dc.3020: VirtualBox.exe: timestamp 0x55eeaed7 (rc=VINF_SUCCESS)
56926dc.3020: '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
57026dc.3020: '\Device\HarddiskVolume5\Windows\System32\ntdll.dll' has no imports
57126dc.3020: supR3HardNtChildPurify: Done after 625 ms and 0 fixes (loop #0).
5722498.2eb4: Log file opened: 5.0.4r102546 g_hStartupLog=0000000000000004 g_uNtVerCombined=0xa0280000
5732498.2eb4: supR3HardenedVmProcessInit: uNtDllAddr=00007ffc43e60000
57426dc.3020: supR3HardenedEarlyCompact: Removed heap 1 (0x00000000f10000 LB 0x400000)
57526dc.3020: supR3HardNtEnableThreadCreation:
5762498.2eb4: ntdll.dll: timestamp 0x55c59f92 (rc=VINF_SUCCESS)
5772498.2eb4: New simple heap: #1 0000000000de0000 LB 0x400000 (for 1839104 allocation)
5782498.2eb4: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox'
5792498.2eb4: System32: \Device\HarddiskVolume5\Windows\System32
5802498.2eb4: WinSxS: \Device\HarddiskVolume5\Windows\WinSxS
5812498.2eb4: KnownDllPath: C:\WINDOWS\system32
5822498.2eb4: supR3HardenedVmProcessInit: Opening vboxdrv...
5832498.2eb4: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
5842498.2eb4: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
5852498.2eb4: Registered Dll notification callback with NTDLL.
5862498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\kernel32.dll)
5872498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\kernel32.dll
5882498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\KERNEL32.DLL (Input=KERNEL32.DLL, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000801:<flags> [calling]
5892498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc3ffe0000 LB 0x001dd000 C:\WINDOWS\system32\KERNELBASE.dll [fFlags=0x0]
5902498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\KernelBase.dll)
5912498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\KernelBase.dll
5922498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc426a0000 LB 0x000ad000 C:\WINDOWS\system32\KERNEL32.DLL [fFlags=0x0]
5932498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
5942498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc426a0000 'C:\WINDOWS\system32\KERNEL32.DLL'
5952498.2eb4: supR3HardenedDllNotificationCallback: load 00007ff6559f0000 LB 0x0012c000 C:\Program Files\Oracle\VirtualBox\VirtualBox.exe [fFlags=0x0]
5962498.2eb4: '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
5972498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBox.exe)
5982498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBox.exe
5992498.2eb4: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffc43ecfb70 pvNtTerminateThread=00007ffc43ef3a20
60026dc.3020: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 313 ms.
6012498.2eb4: \SystemRoot\System32\ntdll.dll:
6022498.2eb4: CreationTime: 2015-09-25T20:05:35.147044800Z
6032498.2eb4: LastWriteTime: 2015-08-08T07:29:58.168349600Z
6042498.2eb4: ChangeTime: 2015-09-25T20:22:15.663609100Z
6052498.2eb4: FileAttributes: 0x20
6062498.2eb4: Size: 0x1bce48
6072498.2eb4: NT Headers: 0xd8
6082498.2eb4: Timestamp: 0x55c59f92
6092498.2eb4: Machine: 0x8664 - amd64
6102498.2eb4: Timestamp: 0x55c59f92
6112498.2eb4: Image Version: 10.0
6122498.2eb4: SizeOfImage: 0x1c1000 (1839104)
6132498.2eb4: Resource Dir: 0x15a000 LB 0x65718
6142498.2eb4: ProductName: Microsoft® Windows® Operating System
6152498.2eb4: ProductVersion: 10.0.10240.16430
6162498.2eb4: FileVersion: 10.0.10240.16430 (th1.150807-2049)
6172498.2eb4: FileDescription: NT Layer DLL
6182498.2eb4: \SystemRoot\System32\kernel32.dll:
6192498.2eb4: CreationTime: 2015-07-10T10:59:59.699781600Z
6202498.2eb4: LastWriteTime: 2015-07-10T10:59:59.699781600Z
6212498.2eb4: ChangeTime: 2015-09-25T07:06:16.935797300Z
6222498.2eb4: FileAttributes: 0x20
6232498.2eb4: Size: 0xab830
6242498.2eb4: NT Headers: 0xf0
6252498.2eb4: Timestamp: 0x559f38ad
6262498.2eb4: Machine: 0x8664 - amd64
6272498.2eb4: Timestamp: 0x559f38ad
6282498.2eb4: Image Version: 10.0
6292498.2eb4: SizeOfImage: 0xad000 (708608)
6302498.2eb4: Resource Dir: 0xab000 LB 0x518
6312498.2eb4: ProductName: Microsoft® Windows® Operating System
6322498.2eb4: ProductVersion: 10.0.10240.16384
6332498.2eb4: FileVersion: 10.0.10240.16384 (th1.150709-1700)
6342498.2eb4: FileDescription: Windows NT BASE API Client DLL
6352498.2eb4: \SystemRoot\System32\KernelBase.dll:
6362498.2eb4: CreationTime: 2015-07-10T11:00:10.325689700Z
6372498.2eb4: LastWriteTime: 2015-07-10T11:00:10.325689700Z
6382498.2eb4: ChangeTime: 2015-09-25T07:06:16.998301400Z
6392498.2eb4: FileAttributes: 0x20
6402498.2eb4: Size: 0x1dc680
6412498.2eb4: NT Headers: 0x100
6422498.2eb4: Timestamp: 0x559f38c3
6432498.2eb4: Machine: 0x8664 - amd64
6442498.2eb4: Timestamp: 0x559f38c3
6452498.2eb4: Image Version: 10.0
6462498.2eb4: SizeOfImage: 0x1dd000 (1953792)
6472498.2eb4: Resource Dir: 0x1c7000 LB 0x530
6482498.2eb4: ProductName: Microsoft® Windows® Operating System
6492498.2eb4: ProductVersion: 10.0.10240.16384
6502498.2eb4: FileVersion: 10.0.10240.16384 (th1.150709-1700)
6512498.2eb4: FileDescription: Windows NT BASE API Client DLL
6522498.2eb4: \SystemRoot\System32\apisetschema.dll:
6532498.2eb4: CreationTime: 2015-07-10T11:00:04.872098600Z
6542498.2eb4: LastWriteTime: 2015-07-10T11:00:04.872098600Z
6552498.2eb4: ChangeTime: 2015-09-25T07:06:14.701298100Z
6562498.2eb4: FileAttributes: 0x20
6572498.2eb4: Size: 0x16760
6582498.2eb4: NT Headers: 0xc8
6592498.2eb4: Timestamp: 0x559f3e3d
6602498.2eb4: Machine: 0x8664 - amd64
6612498.2eb4: Timestamp: 0x559f3e3d
6622498.2eb4: Image Version: 10.0
6632498.2eb4: SizeOfImage: 0x17000 (94208)
6642498.2eb4: Resource Dir: 0x16000 LB 0x3f0
6652498.2eb4: ProductName: Microsoft® Windows® Operating System
6662498.2eb4: ProductVersion: 10.0.10240.16384
6672498.2eb4: FileVersion: 10.0.10240.16384 (th1.150709-1700)
6682498.2eb4: FileDescription: ApiSet Schema DLL
6692498.2eb4: NtOpenDirectoryObject failed on \Driver: 0xc0000022
6702498.2eb4: supR3HardenedWinFindAdversaries: 0x100
6712498.2eb4: \SystemRoot\System32\drivers\avgrkx64.sys:
6722498.2eb4: CreationTime: 2015-03-20T10:18:18.000000000Z
6732498.2eb4: LastWriteTime: 2015-03-20T10:18:18.000000000Z
6742498.2eb4: ChangeTime: 2015-09-25T06:34:23.860789900Z
6752498.2eb4: FileAttributes: 0x20
6762498.2eb4: Size: 0x9fe0
6772498.2eb4: NT Headers: 0xe8
6782498.2eb4: Timestamp: 0x550bf3e7
6792498.2eb4: Machine: 0x8664 - amd64
6802498.2eb4: Timestamp: 0x550bf3e7
6812498.2eb4: Image Version: 6.2
6822498.2eb4: SizeOfImage: 0xa000 (40960)
6832498.2eb4: Resource Dir: 0x9000 LB 0x510
6842498.2eb4: ProductName: AVG Internet Security
6852498.2eb4: ProductVersion: 15.0.0.5908
6862498.2eb4: FileVersion: 15.0.0.5908
6872498.2eb4: SpecialBuild: AvCompile_2015_0320_111532(5908), SVNRev 18c4578e1c294cb8006a179b834157155925d4af (release/SmallUpdate2015-04_beta), av
6882498.2eb4: PrivateBuild: x64 Release_Unicode_DRIVER
6892498.2eb4: FileDescription: AVG Anti-Rootkit Driver
6902498.2eb4: \SystemRoot\System32\drivers\avgmfx64.sys:
6912498.2eb4: CreationTime: 2015-08-04T09:32:32.000000000Z
6922498.2eb4: LastWriteTime: 2015-08-04T09:32:32.000000000Z
6932498.2eb4: ChangeTime: 2015-09-25T06:34:25.407743600Z
6942498.2eb4: FileAttributes: 0x20
6952498.2eb4: Size: 0x3d3b0
6962498.2eb4: NT Headers: 0xe0
6972498.2eb4: Timestamp: 0x55c086ac
6982498.2eb4: Machine: 0x8664 - amd64
6992498.2eb4: Timestamp: 0x55c086ac
7002498.2eb4: Image Version: 6.2
7012498.2eb4: SizeOfImage: 0x3e000 (253952)
7022498.2eb4: Resource Dir: 0x3c000 LB 0x52c
7032498.2eb4: ProductName: AVG Internet Security
7042498.2eb4: ProductVersion: 15.0.0.6132
7052498.2eb4: FileVersion: 15.0.0.6132
7062498.2eb4: SpecialBuild: AvCompile_2015_0804_112815(6132), SVNRev cbac1c769cb9b6888db1f1065b4133bf3c9ce40f (release/SmallUpdate2015-08_beta), av
7072498.2eb4: PrivateBuild: x64 Release_Unicode_DRIVER
7082498.2eb4: FileDescription: AVG Resident Shield Minifilter Driver
7092498.2eb4: \SystemRoot\System32\drivers\avgidsdrivera.sys:
7102498.2eb4: CreationTime: 2015-08-19T09:52:30.000000000Z
7112498.2eb4: LastWriteTime: 2015-08-19T09:52:30.000000000Z
7122498.2eb4: ChangeTime: 2015-09-25T06:34:26.104269300Z
7132498.2eb4: FileAttributes: 0x20
7142498.2eb4: Size: 0x4c7b0
7152498.2eb4: NT Headers: 0xe8
7162498.2eb4: Timestamp: 0x55d451da
7172498.2eb4: Machine: 0x8664 - amd64
7182498.2eb4: Timestamp: 0x55d451da
7192498.2eb4: Image Version: 6.2
7202498.2eb4: SizeOfImage: 0x53000 (339968)
7212498.2eb4: Resource Dir: 0x51000 LB 0x554
7222498.2eb4: ProductName: AVG Internet Security
7232498.2eb4: ProductVersion: 15.0.0.6137
7242498.2eb4: FileVersion: 15.0.0.6137
7252498.2eb4: SpecialBuild: AvCompile_2015_0819_113418(6137), SVNRev 7ade868631072664eb184732ae422a4307e58f68 (release/SmallUpdate2015-08_release), av
7262498.2eb4: PrivateBuild: x64 Release_Unicode_DRIVER
7272498.2eb4: FileDescription: AVG IDS Application Activity Monitor Driver.
7282498.2eb4: \SystemRoot\System32\drivers\avgidsha.sys:
7292498.2eb4: CreationTime: 2015-08-19T09:53:56.000000000Z
7302498.2eb4: LastWriteTime: 2015-08-19T09:53:56.000000000Z
7312498.2eb4: ChangeTime: 2015-09-25T06:34:26.026140600Z
7322498.2eb4: FileAttributes: 0x20
7332498.2eb4: Size: 0x48bb0
7342498.2eb4: NT Headers: 0xd8
7352498.2eb4: Timestamp: 0x55d45230
7362498.2eb4: Machine: 0x8664 - amd64
7372498.2eb4: Timestamp: 0x55d45230
7382498.2eb4: Image Version: 6.2
7392498.2eb4: SizeOfImage: 0x49000 (299008)
7402498.2eb4: Resource Dir: 0x47000 LB 0x548
7412498.2eb4: ProductName: AVG Internet Security
7422498.2eb4: ProductVersion: 15.0.0.6137
7432498.2eb4: FileVersion: 15.0.0.6137
7442498.2eb4: SpecialBuild: AvCompile_2015_0819_113418(6137), SVNRev 7ade868631072664eb184732ae422a4307e58f68 (release/SmallUpdate2015-08_release), av
7452498.2eb4: PrivateBuild: x64 Release_Unicode_DRIVER
7462498.2eb4: FileDescription: AVG Application Activity Monitor Helper Driver
7472498.2eb4: \SystemRoot\System32\drivers\avgloga.sys:
7482498.2eb4: CreationTime: 2015-05-07T11:50:22.000000000Z
7492498.2eb4: LastWriteTime: 2015-05-07T11:50:22.000000000Z
7502498.2eb4: ChangeTime: 2015-09-25T06:34:23.767034300Z
7512498.2eb4: FileAttributes: 0x20
7522498.2eb4: Size: 0x5c5e0
7532498.2eb4: NT Headers: 0xf0
7542498.2eb4: Timestamp: 0x554b5179
7552498.2eb4: Machine: 0x8664 - amd64
7562498.2eb4: Timestamp: 0x554b5179
7572498.2eb4: Image Version: 6.2
7582498.2eb4: SizeOfImage: 0x5b000 (372736)
7592498.2eb4: Resource Dir: 0x59000 LB 0x4ec
7602498.2eb4: ProductName: AVG Internet Security
7612498.2eb4: ProductVersion: 15.0.0.5957
7622498.2eb4: FileVersion: 15.0.0.5957
7632498.2eb4: SpecialBuild: AvCompile_2015_0507_134328(5957), SVNRev bcddc515e1405c8e35481b16de334020e451ec3e (release/HotFix2015-05), av
7642498.2eb4: PrivateBuild: x64 Release_Unicode_DRIVER
7652498.2eb4: FileDescription: AVG Logging Driver
7662498.2eb4: \SystemRoot\System32\drivers\avgldx64.sys:
7672498.2eb4: CreationTime: 2015-06-16T13:55:04.000000000Z
7682498.2eb4: LastWriteTime: 2015-06-16T13:55:04.000000000Z
7692498.2eb4: ChangeTime: 2015-09-25T06:34:23.970170200Z
7702498.2eb4: FileAttributes: 0x20
7712498.2eb4: Size: 0x3f3e0
7722498.2eb4: NT Headers: 0xe0
7732498.2eb4: Timestamp: 0x55802aaf
7742498.2eb4: Machine: 0x8664 - amd64
7752498.2eb4: Timestamp: 0x55802aaf
7762498.2eb4: Image Version: 6.2
7772498.2eb4: SizeOfImage: 0x42000 (270336)
7782498.2eb4: Resource Dir: 0x40000 LB 0x50c
7792498.2eb4: ProductName: AVG Internet Security
7802498.2eb4: ProductVersion: 15.0.0.6055
7812498.2eb4: FileVersion: 15.0.0.6055
7822498.2eb4: SpecialBuild: AvCompile_2015_0616_154836(6055), SVNRev 309d50c06d2885375935ac1c0a79cdb255cb7045 (release/SmallUpdate2015-06_beta), av
7832498.2eb4: PrivateBuild: x64 Release_Unicode_DRIVER
7842498.2eb4: FileDescription: AVG AVI Loader Driver
7852498.2eb4: \SystemRoot\System32\drivers\avgdiska.sys:
7862498.2eb4: CreationTime: 2015-03-11T10:16:06.000000000Z
7872498.2eb4: LastWriteTime: 2015-03-11T10:16:06.000000000Z
7882498.2eb4: ChangeTime: 2015-09-25T06:34:26.307403800Z
7892498.2eb4: FileAttributes: 0x20
7902498.2eb4: Size: 0x27be0
7912498.2eb4: NT Headers: 0xe0
7922498.2eb4: Timestamp: 0x550015e3
7932498.2eb4: Machine: 0x8664 - amd64
7942498.2eb4: Timestamp: 0x550015e3
7952498.2eb4: Image Version: 6.2
7962498.2eb4: SizeOfImage: 0x29000 (167936)
7972498.2eb4: Resource Dir: 0x27000 LB 0x4e0
7982498.2eb4: ProductName: AVG Internet Security
7992498.2eb4: ProductVersion: 15.0.0.5902
8002498.2eb4: FileVersion: 15.0.0.5902
8012498.2eb4: SpecialBuild: AvCompile_2015_0311_110513(5902), SVNRev d57888a6d0541615b2b2c643813a0b67abc3acba (av/devel), av
8022498.2eb4: PrivateBuild: x64 Release_Unicode_DRIVER
8032498.2eb4: FileDescription: AVG File Vault Driver
8042498.2eb4: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox'
8052498.2eb4: Calling main()
8062498.2eb4: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
8072498.2eb4: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox'
8082498.2eb4: '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
8092498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBox.exe)
8102498.2eb4: SUPR3HardenedMain: Final process, opening VBoxDrv...
8112498.2eb4: supR3HardenedEarlyCompact: Removed heap 1 (0x00000000de0000 LB 0x400000)
8122498.2eb4: supR3HardNtEnableThreadCreation:
8132498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxSupLib.dll)
8142498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxSupLib.dll
8152498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
8162498.2eb4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
8172498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc341c0000 LB 0x00005000 C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL [fFlags=0x0]
8182498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
8192498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
8202498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
8212498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc341c0000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
8222498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
8232498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
8242498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc341c0000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
8252498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc341c0000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
8262498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
8272498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msasn1.dll'.
8282498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'crypt32.dll'.
8292498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'rpcrt4.dll'.
8302498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\wintrust.dll)
8312498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\wintrust.dll
8322498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
8332498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume5\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
8342498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\rpcrt4.dll)
8352498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\rpcrt4.dll
8362498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
8372498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume5\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
8382498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
8392498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 'msasn1.dll'.
8402498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\crypt32.dll)
8412498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\crypt32.dll
8422498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
8432498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume5\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
8442498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\msasn1.dll)
8452498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\msasn1.dll
8462498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
8472498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
8482498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\msvcrt.dll)
8492498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\msvcrt.dll
8502498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
8512498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume5\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
8522498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
8532498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
8542498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
8552498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
8562498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
8572498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc41fc0000 LB 0x0009d000 C:\WINDOWS\system32\msvcrt.dll [fFlags=0x0]
8582498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
8592498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc3f600000 LB 0x00011000 C:\WINDOWS\system32\MSASN1.dll [fFlags=0x0]
8602498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
8612498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc3fe10000 LB 0x001c1000 C:\WINDOWS\system32\CRYPT32.dll [fFlags=0x0]
8622498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
8632498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc41e90000 LB 0x00126000 C:\WINDOWS\system32\RPCRT4.dll [fFlags=0x0]
8642498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
8652498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc401c0000 LB 0x00054000 C:\WINDOWS\system32\Wintrust.dll [fFlags=0x0]
8662498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
8672498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc401c0000 'C:\WINDOWS\system32\Wintrust.dll'
8682498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\bcrypt.dll)
8692498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\bcrypt.dll
8702498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\bcrypt.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
8712498.2eb4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
8722498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc3f4b0000 LB 0x00028000 C:\WINDOWS\system32\bcrypt.dll [fFlags=0x0]
8732498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
8742498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3f4b0000 'C:\WINDOWS\system32\bcrypt.dll'
8752498.2eb4: bcrypt.dll loaded at 00007ffc3f4b0000, BCryptOpenAlgorithmProvider at 00007ffc3f4b4a00, preloading providers:
8762498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\bcryptprimitives.dll)
8772498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\bcryptprimitives.dll
8782498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\bcryptprimitives.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
8792498.2eb4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
8802498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc3f3a0000 LB 0x0006b000 C:\WINDOWS\system32\bcryptprimitives.dll [fFlags=0x0]
8812498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
8822498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3f3a0000 'C:\WINDOWS\system32\bcryptprimitives.dll'
8832498.2eb4: BCryptOpenAlgorithmProvider(,'MD2',0,0) -> 0x0 (hAlgo=0000000001279a40)
8842498.2eb4: BCryptOpenAlgorithmProvider(,'MD4',0,0) -> 0x0 (hAlgo=000000000127a100)
8852498.2eb4: BCryptOpenAlgorithmProvider(,'MD5',0,0) -> 0x0 (hAlgo=000000000127a3d0)
8862498.2eb4: BCryptOpenAlgorithmProvider(,'SHA1',0,0) -> 0x0 (hAlgo=000000000127a730)
8872498.2eb4: BCryptOpenAlgorithmProvider(,'SHA256',0,0) -> 0x0 (hAlgo=000000000127b250)
8882498.2eb4: BCryptOpenAlgorithmProvider(,'SHA512',0,0) -> 0x0 (hAlgo=000000000127b560)
8892498.2eb4: BCryptOpenAlgorithmProvider(,'RSA',0,0) -> 0x0 (hAlgo=000000000127b870)
8902498.2eb4: BCryptOpenAlgorithmProvider(,'DSA',0,0) -> 0x0 (hAlgo=000000000127bb40)
8912498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
8922498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
8932498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc401c0000 'C:\Windows\System32\WINTRUST.DLL'
8942498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
8952498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
8962498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc401c0000 'C:\Windows\System32\WINTRUST.DLL'
8972498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
8982498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
8992498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc401c0000 'C:\Windows\System32\WINTRUST.DLL'
9002498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
9012498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9022498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc401c0000 'C:\Windows\System32\WINTRUST.DLL'
9032498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
9042498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9052498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc401c0000 'C:\Windows\System32\WINTRUST.DLL'
9062498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
9072498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9082498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc401c0000 'C:\Windows\System32\WINTRUST.DLL'
9092498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
9102498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9112498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc401c0000 'C:\Windows\System32\WINTRUST.DLL'
9122498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'bcrypt.dll'.
9132498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\cryptsp.dll)
9142498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\cryptsp.dll
9152498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc3ee20000 LB 0x00017000 C:\WINDOWS\SYSTEM32\CRYPTSP.dll [fFlags=0x0]
9162498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
9172498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'bcrypt.dll'.
9182498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\rsaenh.dll)
9192498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\rsaenh.dll
9202498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
9212498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume5\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
9222498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
9232498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
9242498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume5\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
9252498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
9262498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9272498.2eb4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
9282498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc3ea00000 LB 0x00033000 C:\WINDOWS\system32\rsaenh.dll [fFlags=0x0]
9292498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
9302498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
9312498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'bcryptprimitives.dll'.
9322498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\cryptbase.dll)
9332498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\cryptbase.dll
9342498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc3ef90000 LB 0x0000b000 C:\WINDOWS\SYSTEM32\CRYPTBASE.dll [fFlags=0x0]
9352498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\cryptbase.dll [lacks WinVerifyTrust]
9362498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
9372498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcryptprimitives.dll'...
9382498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcryptprimitives.dll' -> '\Device\HarddiskVolume5\Windows\System32\bcryptprimitives.dll' [rcNtRedir=0xc0150008]
9392498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
9402498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9412498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc426a0000 'C:\WINDOWS\system32\kernel32.dll'
9422498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
9432498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc401c0000 'C:\Windows\System32\WINTRUST.DLL'
9442498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
9452498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\CRYPT32.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
9462498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\CRYPT32.dll'
9472498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc403d0000 LB 0x0001c000 C:\WINDOWS\system32\imagehlp.dll [fFlags=0x0]
9482498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
9492498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\imagehlp.dll)
9502498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\imagehlp.dll
9512498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
9522498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
9532498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
9542498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
9552498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9562498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
9572498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc42640000 LB 0x0005b000 C:\WINDOWS\system32\sechost.dll [fFlags=0x0]
9582498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'rpcrt4.dll'.
9592498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\sechost.dll)
9602498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\sechost.dll
9612498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
9622498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'rpcrt4.dll'.
9632498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\gpapi.dll)
9642498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\gpapi.dll
9652498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc3e4a0000 LB 0x00023000 C:\WINDOWS\SYSTEM32\gpapi.dll [fFlags=0x0]
9662498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\gpapi.dll [lacks WinVerifyTrust]
9672498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc3f580000 LB 0x00013000 C:\WINDOWS\system32\profapi.dll [fFlags=0x0]
9682498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\profapi.dll)
9692498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\profapi.dll
9702498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
9712498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'crypt32.dll'.
9722498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'wldap32.dll'.
9732498.2eb4: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume5\Windows\System32\cryptnet.dll)
9742498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\cryptnet.dll
9752498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wldap32.dll'...
9762498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'wldap32.dll' -> '\Device\HarddiskVolume5\Windows\System32\wldap32.dll' [rcNtRedir=0xc0150008]
9772498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
9782498.2eb4: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume5\Windows\System32\Wldap32.dll)
9792498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\Wldap32.dll
9802498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
9812498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume5\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
9822498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
9832498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
9842498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
9852498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
9862498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
9872498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume5\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
9882498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
9892498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
9902498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
9912498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
9922498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
9932498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume5\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
9942498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
9952498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
9962498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
9972498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
9982498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\cryptnet.dll (Input=cryptnet.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9992498.2eb4: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume5\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
10002498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc42a80000 LB 0x0005b000 C:\WINDOWS\system32\WLDAP32.dll [fFlags=0x0]
10012498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume5\Windows\System32\Wldap32.dll [lacks WinVerifyTrust]
10022498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc267b0000 LB 0x0002f000 C:\WINDOWS\system32\cryptnet.dll [fFlags=0x0]
10032498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume5\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
10042498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume5\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
10052498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
10062498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc267b0000 'C:\WINDOWS\system32\cryptnet.dll'
10072498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume5\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
10082498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
10092498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc267b0000 'C:\WINDOWS\system32\cryptnet.dll'
10102498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume5\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
10112498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
10122498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc267b0000 'C:\WINDOWS\system32\cryptnet.dll'
10132498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume5\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
10142498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
10152498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc267b0000 'C:\WINDOWS\system32\cryptnet.dll'
10162498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume5\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
10172498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
10182498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc267b0000 'C:\WINDOWS\system32\cryptnet.dll'
10192498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume5\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
10202498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
10212498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc267b0000 'C:\WINDOWS\system32\cryptnet.dll'
10222498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume5\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
10232498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc267b0000 'C:\WINDOWS\system32\cryptnet.dll'
10242498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume5\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
10252498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc267b0000 'C:\WINDOWS\system32\cryptnet.dll'
10262498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume5\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
10272498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc267b0000 'C:\WINDOWS\system32\cryptnet.dll'
10282498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume5\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
10292498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc267b0000 'C:\WINDOWS\system32\cryptnet.dll'
10302498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume5\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
10312498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc267b0000 'C:\WINDOWS\system32\cryptnet.dll'
10322498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc267b0000 'C:\WINDOWS\system32\cryptnet.dll'
10332498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume5\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
10342498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc267b0000 'C:\Windows\System32\cryptnet.dll'
10352498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc40520000 LB 0x000a6000 C:\WINDOWS\system32\advapi32.dll [fFlags=0x0]
10362498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
10372498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'sechost.dll'.
10382498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #20 'rpcrt4.dll'.
10392498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\advapi32.dll)
10402498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\advapi32.dll
10412498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
10422498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
10432498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume5\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
10442498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
10452498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'sechost.dll'...
10462498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'sechost.dll' -> '\Device\HarddiskVolume5\Windows\System32\sechost.dll' [rcNtRedir=0xc0150008]
10472498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\sechost.dll [lacks WinVerifyTrust]
10482498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
10492498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
10502498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
10512498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
10522498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
10532498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
10542498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
10552498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
10562498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000000 pwszName=\SystemRoot\System32\ntdll.dll
10572498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: New context 00000000012bca70
10582498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000012bca70
10592498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=311B4CDD9B998ED36E8EA94DCB004D809301CC36
10602498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
10612498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rpcrt4.dll (Input=rpcrt4.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
10622498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc41e90000 'C:\WINDOWS\system32\rpcrt4.dll'
10632498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
10642498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc401c0000 'C:\Windows\System32\WINTRUST.DLL'
10652498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
10662498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc401c0000 'C:\Windows\System32\WINTRUST.DLL'
10672498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
10682498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc401c0000 'C:\Windows\System32\WINTRUST.DLL'
10692498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
10702498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc401c0000 'C:\Windows\System32\WINTRUST.DLL'
10712498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
10722498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc401c0000 'C:\Windows\System32\WINTRUST.DLL'
10732498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
10742498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc401c0000 'C:\Windows\System32\WINTRUST.DLL'
10752498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
10762498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
10772498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc401c0000 'C:\Windows\System32\WINTRUST.DLL'
10782498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
10792498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
10802498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
10812498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
10822498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
10832498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
10842498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_555_for_KB3081455~31bf3856ad364e35~amd64~~10.0.1.3.cat'; file='\SystemRoot\System32\ntdll.dll'
10852498.2eb4: g_pfnWinVerifyTrust=00007ffc401c8890
10862498.2eb4: supR3HardenedScreenImage/preload: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\crypt32.dll [redoing WinVerifyTrust]
10872498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
10882498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
10892498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
10902498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
10912498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
10922498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
10932498.2eb4: supR3HardenedScreenImage/preload: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\crypt32.dll'
10942498.2eb4: supR3HardenedScreenImage/preload: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\wintrust.dll [redoing WinVerifyTrust]
10952498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
10962498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
10972498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
10982498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\crypt32.dll
10992498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
11002498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
11012498.2eb4: supR3HardenedScreenImage/preload: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\wintrust.dll'
11022498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
11032498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
11042498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
11052498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
11062498.2eb4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\advapi32.dll'
11072498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000380 pwszName=\Device\HarddiskVolume5\Windows\System32\Wldap32.dll
11082498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000012bca70
11092498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000012bca70
11102498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=3E30C00BB3189B639214835B4F4C320DEC5BFA77
11112498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
11122498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
11132498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
11142498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-OneCore-CoreSystem-ds-Package~31bf3856ad364e35~amd64~~10.0.10240.16384.cat'; file='\Device\HarddiskVolume5\Windows\System32\Wldap32.dll'
11152498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
11162498.2eb4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\Wldap32.dll'
11172498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000037c pwszName=\Device\HarddiskVolume5\Windows\System32\cryptnet.dll
11182498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000012bca70
11192498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000012bca70
11202498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=5997BB270A09A76A71A9EE8A7ADB154F3D75EEF3
11212498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
11222498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
11232498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
11242498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-OneCore-CoreSystem-ds-Package~31bf3856ad364e35~amd64~~10.0.10240.16384.cat'; file='\Device\HarddiskVolume5\Windows\System32\cryptnet.dll'
11252498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
11262498.2eb4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\cryptnet.dll'
11272498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
11282498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
11292498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
11302498.2eb4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\profapi.dll'
11312498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
11322498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
11332498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
11342498.2eb4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\gpapi.dll'
11352498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
11362498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
11372498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
11382498.2eb4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\sechost.dll'
11392498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
11402498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
11412498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
11422498.2eb4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\imagehlp.dll'
11432498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
11442498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
11452498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\crypt32.dll
11462498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
11472498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
11482498.2eb4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\cryptbase.dll'
11492498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
11502498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
11512498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
11522498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
11532498.2eb4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\rsaenh.dll'
11542498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
11552498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
11562498.2eb4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\cryptsp.dll'
11572498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
11582498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
11592498.2eb4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\bcryptprimitives.dll'
11602498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
11612498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
11622498.2eb4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\bcrypt.dll'
11632498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
11642498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
11652498.2eb4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll'
11662498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
11672498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
11682498.2eb4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\msasn1.dll'
11692498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
11702498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
11712498.2eb4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\rpcrt4.dll'
11722498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
11732498.2eb4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxSupLib.dll'
11742498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
11752498.2eb4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBox.exe'
11762498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
11772498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
11782498.2eb4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\KernelBase.dll'
11792498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
11802498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
11812498.2eb4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\kernel32.dll'
11822498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
11832498.2eb4: supR3HardenedWinIsDesiredRootCA: Adding 0x5ad46780fa5df300 DC=com, DC=microsoft, CN=Microsoft Root Certificate Authority
11842498.2eb4: supR3HardenedWinIsDesiredRootCA: Adding 0xea5386456178582b C=ZA, ST=Western Cape, L=Durbanville, O=Thawte, OU=Thawte Certification, CN=Thawte Timestamping CA
11852498.2eb4: supR3HardenedWinIsDesiredRootCA: Adding 0x3be670c1bd02a900 OU=Copyright (c) 1997 Microsoft Corp., OU=Microsoft Corporation, CN=Microsoft Root Authority
11862498.2eb4: supR3HardenedWinIsDesiredRootCA: Adding 0xe991ee72b03db500 C=US, O=Symantec Corporation, CN=Symantec Enterprise Mobile Root for Microsoft
11872498.2eb4: supR3HardenedWinIsDesiredRootCA: Adding 0x4d3835aa4180b200 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2011
11882498.2eb4: supR3HardenedWinIsDesiredRootCA: Adding 0x987869d3679da00 CN=ClockworkMod
11892498.2eb4: supR3HardenedWinIsDesiredRootCA: Adding 0x646e3fe3ba08df00 C=US, O=MSFT, CN=Microsoft Authenticode(tm) Root Authority
11902498.2eb4: supR3HardenedWinIsDesiredRootCA: Adding 0x5fc0d803a95dc700 C=CZ, ST=Moravia, L=Brno, O=AVG Technologies cz, OU=Engineering, CN=AVG Technologies
11912498.2eb4: supR3HardenedWinIsDesiredRootCA: Adding 0xece4e4289e08b900 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010
11922498.2eb4: supR3HardenedWinIsDesiredRootCA: Adding 0x43a9cc371ff5385a O=Microsoft Trust Network, OU=Microsoft Corporation, OU=Microsoft Time Stamping Service Root, OU=Copyright (c) 1997 Microsoft Corp.
11932498.2eb4: supR3HardenedWinIsDesiredRootCA: Adding 0x2e2d2c7c68f0202e O=VeriSign Trust Network, OU=VeriSign, Inc., OU=VeriSign Time Stamping Service Root, OU=NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.
11942498.2eb4: supR3HardenedWinIsDesiredRootCA: Adding 0x9b24d19bd616cb00 CN=localhost, O=Skype Click to Call, OU=Skype Click to Call
11952498.2eb4: supR3HardenedWinIsDesiredRootCA: Adding 0xd8dbfb2c27bfb200 C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2008 thawte, Inc. - For authorized use only, CN=thawte Primary Root CA - G3
11962498.2eb4: supR3HardenedWinIsDesiredRootCA: Adding 0x61a3a33f81aace00 C=US, ST=UT, L=Salt Lake City, O=The USERTRUST Network, OU=http://www.usertrust.com, CN=UTN-USERFirst-Object
11972498.2eb4: supR3HardenedWinIsDesiredRootCA: Adding 0xf4fd306318ccda00 C=US, O=GeoTrust Inc., CN=GeoTrust Global CA
11982498.2eb4: supR3HardenedWinIsDesiredRootCA: Adding 0x780679907625cc00 OU=GlobalSign Root CA - R3, O=GlobalSign, CN=GlobalSign
11992498.2eb4: supR3HardenedWinIsDesiredRootCA: Adding 0x3d98ab22bb04a300 C=IE, O=Baltimore, OU=CyberTrust, CN=Baltimore CyberTrust Root
12002498.2eb4: supR3HardenedWinIsDesiredRootCA: Adding 0xa0ee62086758b15d C=US, O=Equifax, OU=Equifax Secure Certificate Authority
12012498.2eb4: supR3HardenedWinIsDesiredRootCA: Adding 0xd944bca189a00 C=BM, O=QuoVadis Limited, CN=QuoVadis Root CA 2
12022498.2eb4: supR3HardenedWinIsDesiredRootCA: Adding 0x8ff6fc03c1edbd00 C=US, ST=Arizona, L=Scottsdale, O=Starfield Technologies, Inc., CN=Starfield Root Certificate Authority - G2
12032498.2eb4: supR3HardenedWinIsDesiredRootCA: Adding 0xc6fa4243b695b600 C=US, O=Entrust, Inc., OU=www.entrust.net/CPS is incorporated by reference, OU=(c) 2006 Entrust, Inc., CN=Entrust Root Certification Authority
12042498.2eb4: supR3HardenedWinIsDesiredRootCA: Adding 0xa3ce8d99e60eda00 C=BE, O=GlobalSign nv-sa, OU=Root CA, CN=GlobalSign Root CA
12052498.2eb4: supR3HardenedWinIsDesiredRootCA: Adding 0xa671e9fec832b700 C=US, O=Starfield Technologies, Inc., OU=Starfield Class 2 Certification Authority
12062498.2eb4: supR3HardenedWinIsDesiredRootCA: Adding 0xa8de7211e13be200 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root CA
12072498.2eb4: supR3HardenedWinIsDesiredRootCA: Adding 0x3178d37f87f1c400 C=CH, O=SwissSign AG, CN=SwissSign Silver CA - G2
12082498.2eb4: supR3HardenedWinIsDesiredRootCA: Adding 0xff3891b54348328 C=US, O=Entrust.net, OU=www.entrust.net/CPS incorp. by ref. (limits liab.), OU=(c) 1999 Entrust.net Limited, CN=Entrust.net Secure Server Certification Authority
12092498.2eb4: supR3HardenedWinIsDesiredRootCA: Adding 0x7ae89c50f0b6a00f C=US, O=GTE Corporation, OU=GTE CyberTrust Solutions, Inc., CN=GTE CyberTrust Global Root
12102498.2eb4: supR3HardenedWinIsDesiredRootCA: Adding 0xd45980fbf0a0ac00 C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2006 thawte, Inc. - For authorized use only, CN=thawte Primary Root CA
12112498.2eb4: supR3HardenedWinIsDesiredRootCA: Adding 0xf5cd95e581a4ab00 C=US, O=SecureTrust Corporation, CN=SecureTrust CA
12122498.2eb4: supR3HardenedWinIsDesiredRootCA: Adding 0x298be035a30bab00 C=DE, O=Deutsche Telekom AG, OU=T-TeleSec Trust Center, CN=Deutsche Telekom Root CA 2
12132498.2eb4: supR3HardenedWinIsDesiredRootCA: Adding 0xabd0695c5d11d15e C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority - G2, OU=(c) 1998 VeriSign, Inc. - For authorized use only, OU=VeriSign Trust Network
12142498.2eb4: supR3HardenedWinIsDesiredRootCA: Adding 0x6f2ebe0e24cfa600 OU=GlobalSign Root CA - R2, O=GlobalSign, CN=GlobalSign
12152498.2eb4: supR3HardenedWinIsDesiredRootCA: Adding 0x14018a1bf29e595c C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority
12162498.2eb4: supR3HardenedWinIsDesiredRootCA: Adding 0x35f812d09650dc00 C=FR, O=Certplus, CN=Class 2 Primary CA
12172498.2eb4: supR3HardenedWinIsDesiredRootCA: Adding 0x9e5bc2d78b6a3636 C=ZA, ST=Western Cape, L=Cape Town, O=Thawte Consulting cc, OU=Certification Services Division, CN=Thawte Premium Server CA, Email=premium-server@thawte.com
12182498.2eb4: supR3HardenedWinIsDesiredRootCA: Adding 0x7c4fd32ec1b1ce00 C=PL, O=Unizeto Sp. z o.o., CN=Certum CA
12192498.2eb4: supR3HardenedWinIsDesiredRootCA: Adding 0xd4fbe673e5ccc600 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA
12202498.2eb4: supR3HardenedWinIsDesiredRootCA: Adding 0x16e64d2a56ccf200 C=US, ST=Arizona, L=Scottsdale, O=Starfield Technologies, Inc., OU=http://certificates.starfieldtech.com/repository/, CN=Starfield Services Root Certificate Authority
12212498.2eb4: supR3HardenedWinIsDesiredRootCA: Adding 0x6e2ba21058eedf00 C=US, ST=UT, L=Salt Lake City, O=The USERTRUST Network, OU=http://www.usertrust.com, CN=UTN - DATACorp SGC
12222498.2eb4: supR3HardenedWinIsDesiredRootCA: Adding 0x6f2262f09375bd00 C=DE, O=T-Systems Enterprise Services GmbH, OU=T-Systems Trust Center, CN=T-TeleSec GlobalRoot Class 3
12232498.2eb4: supR3HardenedWinIsDesiredRootCA: Adding 0xb28612a94b4dad00 O=Entrust.net, OU=www.entrust.net/CPS_2048 incorp. by ref. (limits liab.), OU=(c) 1999 Entrust.net Limited, CN=Entrust.net Certification Authority (2048)
12242498.2eb4: supR3HardenedWinIsDesiredRootCA: Adding 0x357a29080824af00 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2006 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G5
12252498.2eb4: supR3HardenedWinIsDesiredRootCA: Adding 0x59faf1086271bf00 C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com, Inc., CN=Go Daddy Root Certificate Authority - G2
12262498.2eb4: supR3HardenedWinIsDesiredRootCA: Adding 0x466cbc09db88c100 C=IL, O=StartCom Ltd., OU=Secure Digital Certificate Signing, CN=StartCom Certification Authority
12272498.2eb4: supR3HardenedWinIsDesiredRootCA: Adding 0x3401b15e3761c700 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2008 VeriSign, Inc. - For authorized use only, CN=VeriSign Universal Root Certification Authority
12282498.2eb4: supR3HardenedWinIsDesiredRootCA: Adding 0x7cd4ff7b15b8be00 C=US, O=GeoTrust Inc., CN=GeoTrust Primary Certification Authority
12292498.2eb4: supR3HardenedWinIsDesiredRootCA: Adding 0x491857ead79dde00 C=US, O=The Go Daddy Group, Inc., OU=Go Daddy Class 2 Certification Authority
12302498.2eb4: supR3HardenedWinIsDesiredRootCA: Adding 0xdd80d271558fb700 O=RSA Security Inc, OU=RSA Security 2048 V3
12312498.2eb4: supR3HardenedWinIsDesiredRootCA: Adding 0xab549401526569d3 L=Internet, O=VeriSign, Inc., OU=VeriSign Commercial Software Publishers CA
12322498.2eb4: supR3HardenedWinIsDesiredRootCA: Adding 0xe66b56ffc86e50a4 C=ZA, ST=Western Cape, L=Cape Town, O=Thawte Consulting cc, OU=Certification Services Division, CN=Thawte Server CA, Email=server-certs@thawte.com
12332498.2eb4: supR3HardenedWinIsDesiredRootCA: Adding 0x1f78fc529cbacb00 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 1999 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G3
12342498.2eb4: supR3HardenedWinIsDesiredRootCA: Adding 0x8043e4ce150ead00 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID Root CA
12352498.2eb4: supR3HardenedWinIsDesiredRootCA: Adding 0x331d58625ee2dc00 C=US, O=GeoTrust Inc., OU=(c) 2008 GeoTrust Inc. - For authorized use only, CN=GeoTrust Primary Certification Authority - G3
12362498.2eb4: supR3HardenedWinIsDesiredRootCA: Adding 0xf2e6331af7b700 C=SE, O=AddTrust AB, OU=AddTrust External TTP Network, CN=AddTrust External CA Root
12372498.2eb4: supR3HardenedWinRetrieveTrustedRootCAs: cAdded=54
12382498.2eb4: SUPR3HardenedMain: Load Runtime...
12392498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
12402498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
12412498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
12422498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ws2_32.dll'.
12432498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'rpcrt4.dll'.
12442498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxRT.dll) WinVerifyTrust
12452498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxRT.dll
12462498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
12472498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume5\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
12482498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\rpcrt4.dll
12492498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
12502498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume5\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
12512498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
12522498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
12532498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'nsi.dll'.
12542498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'rpcrt4.dll'.
12552498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\ws2_32.dll) WinVerifyTrust
12562498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\ws2_32.dll
12572498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
12582498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
12592498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
12602498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume5\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
12612498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\rpcrt4.dll
12622498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
12632498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume5\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
12642498.2eb4: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\nsi.dll'.
12652498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\nsi.dll)
12662498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\nsi.dll
12672498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
12682498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
12692498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\msvcp100.dll) WinVerifyTrust
12702498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\msvcp100.dll
12712498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
12722498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
12732498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
12742498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
12752498.2eb4: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\msvcr100.dll'.
12762498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\msvcr100.dll)
12772498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\msvcr100.dll
12782498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
12792498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\msvcr100.dll) WinVerifyTrust
12802498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000a01:<flags> [calling]
12812498.2eb4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxRT.dll
12822498.2eb4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\msvcr100.dll [avoiding WinVerifyTrust]
12832498.2eb4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\msvcp100.dll
12842498.2eb4: supR3HardenedDllNotificationCallback: load 0000000058b90000 LB 0x000d2000 C:\Program Files\Oracle\VirtualBox\MSVCR100.dll [fFlags=0x0]
12852498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\msvcr100.dll [avoiding WinVerifyTrust]
12862498.2eb4: supR3HardenedDllNotificationCallback: load 0000000058af0000 LB 0x00098000 C:\Program Files\Oracle\VirtualBox\MSVCP100.dll [fFlags=0x0]
12872498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\msvcp100.dll
12882498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc40610000 LB 0x00008000 C:\WINDOWS\system32\NSI.dll [fFlags=0x0]
12892498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\nsi.dll [avoiding WinVerifyTrust]
12902498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc403f0000 LB 0x00069000 C:\WINDOWS\system32\WS2_32.dll [fFlags=0x0]
12912498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\ws2_32.dll
12922498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc11e00000 LB 0x0054b000 C:\Program Files\Oracle\VirtualBox\VBoxRT.dll [fFlags=0x0]
12932498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxRT.dll
12942498.2eb4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\msvcr100.dll'.
12952498.2eb4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
12962498.2eb4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\nsi.dll'.
12972498.2eb4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\nsi.dll' [rescheduled]
12982498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxRT.dll
12992498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
13002498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11e00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13012498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxRT.dll
13022498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
13032498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11e00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13042498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxRT.dll
13052498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
13062498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11e00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13072498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxRT.dll
13082498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
13092498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11e00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13102498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxRT.dll
13112498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
13122498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11e00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13132498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxRT.dll
13142498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
13152498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11e00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13162498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11e00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13172498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11e00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13182498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11e00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13192498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11e00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13202498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11e00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13212498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11e00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13222498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11e00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13232498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxRT.dll
13242498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
13252498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11e00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13262498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11e00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13272498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11e00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13282498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11e00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13292498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11e00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13302498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11e00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13312498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11e00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13322498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11e00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13332498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11e00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13342498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11e00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13352498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11e00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13362498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11e00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13372498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11e00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13382498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11e00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13392498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11e00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13402498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11e00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13412498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxRT.dll
13422498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
13432498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11e00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13442498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11e00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13452498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11e00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13462498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11e00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13472498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc401c0000 'C:\WINDOWS\system32\Wintrust.dll'
13482498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
13492498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
13502498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\rsaenh.dll
13512498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
13522498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
13532498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
13542498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
13552498.2eb4: SUPR3HardenedMain: Load TrustedMain...
13562498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
13572498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'opengl32.dll'.
13582498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
13592498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcp100.dll'.
13602498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcr100.dll'.
13612498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qtcorevbox4.dll'.
13622498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'qtguivbox4.dll'.
13632498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'qtnetworkvbox4.dll'.
13642498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'qtopenglvbox4.dll'.
13652498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'user32.dll'.
13662498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'gdi32.dll'.
13672498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'advapi32.dll'.
13682498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'shell32.dll'.
13692498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'ole32.dll'.
13702498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'oleaut32.dll'.
13712498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #15 'comdlg32.dll'.
13722498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'winmm.dll'.
13732498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBox.dll) WinVerifyTrust
13742498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBox.dll
13752498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
13762498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume5\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
13772498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
13782498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
13792498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'winmmbase.dll'.
13802498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcrt.dll'.
13812498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #31 'user32.dll'.
13822498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\winmm.dll) WinVerifyTrust
13832498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\winmm.dll
13842498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comdlg32.dll'...
13852498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'comdlg32.dll' -> '\Device\HarddiskVolume5\Windows\System32\comdlg32.dll' [rcNtRedir=0xc0150008]
13862498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000003c8 pwszName=\Device\HarddiskVolume5\Windows\System32\comdlg32.dll
13872498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000012bca70
13882498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000012bca70
13892498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=857477BEC0F0F69A9C4898B3680E207E94733C3F
13902498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
13912498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume5\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
13922498.2eb4: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\user32.dll'.
13932498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #31 'gdi32.dll'.
13942498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\user32.dll)
13952498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\user32.dll
13962498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
13972498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
13982498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\msvcrt.dll
13992498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmmbase.dll'...
14002498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmmbase.dll' -> '\Device\HarddiskVolume5\Windows\System32\winmmbase.dll' [rcNtRedir=0xc0150008]
14012498.2eb4: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\winmmbase.dll'.
14022498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
14032498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'devobj.dll'.
14042498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\winmmbase.dll)
14052498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\winmmbase.dll
14062498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'devobj.dll'...
14072498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'devobj.dll' -> '\Device\HarddiskVolume5\Windows\System32\devobj.dll' [rcNtRedir=0xc0150008]
14082498.2eb4: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\devobj.dll'.
14092498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
14102498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'cfgmgr32.dll'.
14112498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\devobj.dll)
14122498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\devobj.dll
14132498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
14142498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
14152498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
14162498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume5\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
14172498.2eb4: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\gdi32.dll'.
14182498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #22 'user32.dll'.
14192498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\gdi32.dll)
14202498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\gdi32.dll
14212498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
14222498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume5\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
14232498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\user32.dll [lacks WinVerifyTrust]
14242498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
14252498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume5\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
14262498.2eb4: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\cfgmgr32.dll'.
14272498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\cfgmgr32.dll)
14282498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\cfgmgr32.dll
14292498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
14302498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
14312498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
14322498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\crypt32.dll
14332498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
14342498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
14352498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_207_for_KB3074683~31bf3856ad364e35~amd64~~10.0.1.0.cat'; file='\Device\HarddiskVolume5\Windows\System32\comdlg32.dll'
14362498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
14372498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
14382498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #28 'user32.dll'.
14392498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #29 'shlwapi.dll'.
14402498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #30 'gdi32.dll'.
14412498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #31 'comctl32.dll'.
14422498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #32 'shell32.dll'.
14432498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\comdlg32.dll) WinVerifyTrust
14442498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\comdlg32.dll
14452498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
14462498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume5\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
14472498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
14482498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume5\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
14492498.2eb4: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\shell32.dll'.
14502498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
14512498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #64 'user32.dll'.
14522498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #66 'gdi32.dll'.
14532498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\shell32.dll)
14542498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\shell32.dll
14552498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comctl32.dll'...
14562498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'comctl32.dll' -> '\Device\HarddiskVolume5\Windows\System32\comctl32.dll' [rcNtRedir=0x0]
14572498.2eb4: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\comctl32.dll'.
14582498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'advapi32.dll'.
14592498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
14602498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
14612498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\comctl32.dll)
14622498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\comctl32.dll
14632498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
14642498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume5\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
14652498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
14662498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
14672498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume5\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
14682498.2eb4: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\shlwapi.dll'.
14692498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
14702498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #41 'gdi32.dll'.
14712498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #42 'user32.dll'.
14722498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\shlwapi.dll)
14732498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\shlwapi.dll
14742498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
14752498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume5\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
14762498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\user32.dll [lacks WinVerifyTrust]
14772498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
14782498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
14792498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
14802498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume5\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
14812498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\user32.dll [lacks WinVerifyTrust]
14822498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
14832498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume5\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
14842498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
14852498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
14862498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
14872498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
14882498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume5\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
14892498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\user32.dll [lacks WinVerifyTrust]
14902498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
14912498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume5\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
14922498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
14932498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
14942498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume5\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
14952498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\advapi32.dll
14962498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
14972498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume5\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
14982498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
14992498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
15002498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume5\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
15012498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\user32.dll [lacks WinVerifyTrust]
15022498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
15032498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
15042498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
15052498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
15062498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
15072498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'combase.dll'.
15082498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'rpcrt4.dll'.
15092498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\oleaut32.dll) WinVerifyTrust
15102498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\oleaut32.dll
15112498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
15122498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume5\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
15132498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
15142498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume5\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
15152498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\rpcrt4.dll
15162498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
15172498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume5\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
15182498.2eb4: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\combase.dll'.
15192498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
15202498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'rpcrt4.dll'.
15212498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\combase.dll)
15222498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\combase.dll
15232498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
15242498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
15252498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
15262498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume5\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
15272498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
15282498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
15292498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
15302498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
15312498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
15322498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'rpcrt4.dll'.
15332498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #43 'gdi32.dll'.
15342498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #44 'user32.dll'.
15352498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #45 'combase.dll'.
15362498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\ole32.dll) WinVerifyTrust
15372498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\ole32.dll
15382498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
15392498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume5\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
15402498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\shell32.dll [redoing WinVerifyTrust]
15412498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
15422498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume5\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
15432498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\combase.dll [lacks WinVerifyTrust]
15442498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
15452498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume5\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
15462498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\user32.dll [lacks WinVerifyTrust]
15472498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
15482498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume5\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
15492498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
15502498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
15512498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume5\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
15522498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
15532498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
15542498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\msvcrt.dll
15552498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
15562498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
15572498.2eb4: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\shell32.dll'
15582498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
15592498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume5\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
15602498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\advapi32.dll
15612498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
15622498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume5\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
15632498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\gdi32.dll [redoing WinVerifyTrust]
15642498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
15652498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
15662498.2eb4: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\gdi32.dll'
15672498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
15682498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume5\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
15692498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\user32.dll [redoing WinVerifyTrust]
15702498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
15712498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
15722498.2eb4: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\user32.dll'
15732498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtopenglvbox4.dll'...
15742498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtopenglvbox4.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\qtopenglvbox4.dll' [rcNtRedir=0xc0150008]
15752498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
15762498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'opengl32.dll'.
15772498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
15782498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
15792498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qtguivbox4.dll'.
15802498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qtcorevbox4.dll'.
15812498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcr100.dll'.
15822498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll) WinVerifyTrust
15832498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll
15842498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtnetworkvbox4.dll'...
15852498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtnetworkvbox4.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\qtnetworkvbox4.dll' [rcNtRedir=0xc0150008]
15862498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
15872498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
15882498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
15892498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtcorevbox4.dll'...
15902498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtcorevbox4.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\qtcorevbox4.dll' [rcNtRedir=0xc0150008]
15912498.2eb4: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll'.
15922498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
15932498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'ole32.dll'.
15942498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
15952498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ws2_32.dll'.
15962498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcp100.dll'.
15972498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcr100.dll'.
15982498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll)
15992498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll
16002498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtguivbox4.dll'...
16012498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtguivbox4.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\qtguivbox4.dll' [rcNtRedir=0xc0150008]
16022498.2eb4: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll'.
16032498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
16042498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'comdlg32.dll'.
16052498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'oleaut32.dll'.
16062498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'imm32.dll'.
16072498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'winmm.dll'.
16082498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'winspool.drv'.
16092498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ole32.dll'.
16102498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'user32.dll'.
16112498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'advapi32.dll'.
16122498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'shell32.dll'.
16132498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'qtcorevbox4.dll'.
16142498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'msvcp100.dll'.
16152498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'msvcr100.dll'.
16162498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll)
16172498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll
16182498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
16192498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume5\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
16202498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\user32.dll
16212498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
16222498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume5\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
16232498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\gdi32.dll
16242498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
16252498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume5\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
16262498.2eb4: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume5\Windows\System32\opengl32.dll'.
16272498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
16282498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
16292498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'gdi32.dll'.
16302498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'glu32.dll'.
16312498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ddraw.dll'.
16322498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'user32.dll'.
16332498.2eb4: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume5\Windows\System32\opengl32.dll)
16342498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\opengl32.dll
16352498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
16362498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume5\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
16372498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ddraw.dll'...
16382498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ddraw.dll' -> '\Device\HarddiskVolume5\Windows\System32\ddraw.dll' [rcNtRedir=0xc0150008]
16392498.2eb4: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume5\Windows\System32\ddraw.dll'.
16402498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
16412498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #19 'user32.dll'.
16422498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #20 'gdi32.dll'.
16432498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #21 'dciman32.dll'.
16442498.2eb4: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume5\Windows\System32\ddraw.dll)
16452498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\ddraw.dll
16462498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'glu32.dll'...
16472498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'glu32.dll' -> '\Device\HarddiskVolume5\Windows\System32\glu32.dll' [rcNtRedir=0xc0150008]
16482498.2eb4: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume5\Windows\System32\glu32.dll'.
16492498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
16502498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'opengl32.dll'.
16512498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
16522498.2eb4: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume5\Windows\System32\glu32.dll)
16532498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\glu32.dll
16542498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
16552498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume5\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
16562498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\gdi32.dll
16572498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
16582498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume5\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
16592498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\advapi32.dll
16602498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
16612498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
16622498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
16632498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
16642498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
16652498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
16662498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
16672498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\msvcp100.dll
16682498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtcorevbox4.dll'...
16692498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtcorevbox4.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\qtcorevbox4.dll' [rcNtRedir=0xc0150008]
16702498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll [lacks WinVerifyTrust]
16712498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
16722498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume5\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
16732498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\shell32.dll
16742498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
16752498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume5\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
16762498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\advapi32.dll
16772498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
16782498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume5\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
16792498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
16802498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume5\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
16812498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\ole32.dll
16822498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winspool.drv'...
16832498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'winspool.drv' -> '\Device\HarddiskVolume5\Windows\System32\winspool.drv' [rcNtRedir=0xc0150008]
16842498.2eb4: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume5\Windows\System32\winspool.drv'.
16852498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
16862498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #24 'bcrypt.dll'.
16872498.2eb4: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume5\Windows\System32\winspool.drv)
16882498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\winspool.drv
16892498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
16902498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume5\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
16912498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\winmm.dll
16922498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
16932498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume5\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
16942498.2eb4: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\imm32.dll'.
16952498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'user32.dll'.
16962498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'msctf.dll'.
16972498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\imm32.dll)
16982498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\imm32.dll
16992498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
17002498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume5\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
17012498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\oleaut32.dll
17022498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comdlg32.dll'...
17032498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'comdlg32.dll' -> '\Device\HarddiskVolume5\Windows\System32\comdlg32.dll' [rcNtRedir=0xc0150008]
17042498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\comdlg32.dll
17052498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
17062498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume5\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
17072498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
17082498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
17092498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
17102498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
17112498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
17122498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\msvcp100.dll
17132498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
17142498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume5\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
17152498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\ws2_32.dll
17162498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
17172498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume5\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
17182498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\advapi32.dll
17192498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
17202498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume5\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
17212498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\ole32.dll
17222498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
17232498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume5\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
17242498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msctf.dll'...
17252498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msctf.dll' -> '\Device\HarddiskVolume5\Windows\System32\msctf.dll' [rcNtRedir=0xc0150008]
17262498.2eb4: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\msctf.dll'.
17272498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
17282498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'user32.dll'.
17292498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'gdi32.dll'.
17302498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 'imm32.dll'.
17312498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\msctf.dll)
17322498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\msctf.dll
17332498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
17342498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume5\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
17352498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
17362498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume5\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
17372498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\bcrypt.dll
17382498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
17392498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
17402498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
17412498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume5\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
17422498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
17432498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume5\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
17442498.2eb4: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume5\Windows\System32\opengl32.dll [lacks WinVerifyTrust]
17452498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
17462498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
17472498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dciman32.dll'...
17482498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'dciman32.dll' -> '\Device\HarddiskVolume5\Windows\System32\dciman32.dll' [rcNtRedir=0xc0150008]
17492498.2eb4: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume5\Windows\System32\dciman32.dll'.
17502498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
17512498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'gdi32.dll'.
17522498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
17532498.2eb4: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume5\Windows\System32\dciman32.dll)
17542498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\dciman32.dll
17552498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
17562498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume5\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
17572498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
17582498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume5\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
17592498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
17602498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
17612498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
17622498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume5\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
17632498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
17642498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume5\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
17652498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
17662498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
17672498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
17682498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume5\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
17692498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\imm32.dll [lacks WinVerifyTrust]
17702498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
17712498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume5\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
17722498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
17732498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume5\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
17742498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\user32.dll
17752498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
17762498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
17772498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
17782498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ws2_32.dll'.
17792498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'qtcorevbox4.dll'.
17802498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcr100.dll'.
17812498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\QtNetworkVBox4.dll) WinVerifyTrust
17822498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\QtNetworkVBox4.dll
17832498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtguivbox4.dll'...
17842498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtguivbox4.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\qtguivbox4.dll' [rcNtRedir=0xc0150008]
17852498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll [redoing WinVerifyTrust]
17862498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
17872498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
17882498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
17892498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtcorevbox4.dll'...
17902498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtcorevbox4.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\qtcorevbox4.dll' [rcNtRedir=0xc0150008]
17912498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll [lacks WinVerifyTrust]
17922498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
17932498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume5\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
17942498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\ws2_32.dll
17952498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
17962498.2eb4: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll'
17972498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtcorevbox4.dll'...
17982498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtcorevbox4.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\qtcorevbox4.dll' [rcNtRedir=0xc0150008]
17992498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll [redoing WinVerifyTrust]
18002498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
18012498.2eb4: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll'
18022498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
18032498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
18042498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\msvcr100.dll [redoing WinVerifyTrust]
18052498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
18062498.2eb4: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\msvcr100.dll'
18072498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
18082498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
18092498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\msvcp100.dll
18102498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
18112498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
18122498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
18132498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume5\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
18142498.2eb4: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume5\Windows\System32\opengl32.dll [redoing WinVerifyTrust]
18152498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000450 pwszName=\Device\HarddiskVolume5\Windows\System32\opengl32.dll
18162498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000012bca70
18172498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000012bca70
18182498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=5F0CC8DA0E67C8C01864C0783FA867C4BDCE0AAA
18192498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
18202498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
18212498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package-AutoMerged-windows~31bf3856ad364e35~amd64~~10.0.10240.16384.cat'; file='\Device\HarddiskVolume5\Windows\System32\opengl32.dll'
18222498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
18232498.2eb4: supR3HardenedScreenImage/Imports: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\opengl32.dll'
18242498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VirtualBox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000a01:<flags> [calling]
18252498.2eb4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBox.dll
18262498.2eb4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\opengl32.dll
18272498.2eb4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll
18282498.2eb4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll
18292498.2eb4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\QtNetworkVBox4.dll
18302498.2eb4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll
18312498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'advapi32.dll'.
18322498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
18332498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
18342498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.10240.16384_none_0212ec7eba871e86\comctl32.dll)
18352498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.10240.16384_none_0212ec7eba871e86\comctl32.dll
18362498.2eb4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\winmm.dll
18372498.2eb4: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume5\Windows\System32\glu32.dll [avoiding WinVerifyTrust]
18382498.2eb4: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume5\Windows\System32\ddraw.dll [avoiding WinVerifyTrust]
18392498.2eb4: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume5\Windows\System32\winspool.drv [avoiding WinVerifyTrust]
18402498.2eb4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\winmmbase.dll [avoiding WinVerifyTrust]
18412498.2eb4: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume5\Windows\System32\dciman32.dll [avoiding WinVerifyTrust]
18422498.2eb4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\devobj.dll [avoiding WinVerifyTrust]
18432498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc42340000 LB 0x0014e000 C:\WINDOWS\system32\USER32.dll [fFlags=0x0]
18442498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc421b0000 LB 0x00186000 C:\WINDOWS\system32\GDI32.dll [fFlags=0x0]
18452498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc28450000 LB 0x00008000 C:\WINDOWS\SYSTEM32\DCIMAN32.dll [fFlags=0x0]
18462498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume5\Windows\System32\dciman32.dll [avoiding WinVerifyTrust]
18472498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc28130000 LB 0x000f6000 C:\WINDOWS\SYSTEM32\DDRAW.dll [fFlags=0x0]
18482498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume5\Windows\System32\ddraw.dll [avoiding WinVerifyTrust]
18492498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc28460000 LB 0x0002e000 C:\WINDOWS\SYSTEM32\GLU32.dll [fFlags=0x0]
18502498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume5\Windows\System32\glu32.dll [avoiding WinVerifyTrust]
18512498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc28230000 LB 0x00128000 C:\WINDOWS\SYSTEM32\OPENGL32.dll [fFlags=0x0]
18522498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\opengl32.dll
18532498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc42750000 LB 0x0027c000 C:\WINDOWS\system32\combase.dll [fFlags=0x0]
18542498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\combase.dll [avoiding WinVerifyTrust]
18552498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc42060000 LB 0x00141000 C:\WINDOWS\system32\ole32.dll [fFlags=0x0]
18562498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\ole32.dll
18572498.2eb4: supR3HardenedDllNotificationCallback: load 0000000058810000 LB 0x002de000 C:\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll [fFlags=0x0]
18582498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll
18592498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc3fd00000 LB 0x000b3000 C:\WINDOWS\system32\shcore.dll [fFlags=0x0]
18602498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
18612498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #37 'combase.dll'.
18622498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\SHCore.dll)
18632498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\SHCore.dll
18642498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc42490000 LB 0x00051000 C:\WINDOWS\system32\shlwapi.dll [fFlags=0x0]
18652498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\shlwapi.dll [avoiding WinVerifyTrust]
18662498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc2f1a0000 LB 0x000aa000 C:\WINDOWS\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.10240.16384_none_0212ec7eba871e86\COMCTL32.dll [fFlags=0x0]
18672498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.10240.16384_none_0212ec7eba871e86\comctl32.dll [avoiding WinVerifyTrust]
18682498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc3f5f0000 LB 0x0000f000 C:\WINDOWS\system32\kernel.appcore.dll [fFlags=0x0]
18692498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcrt.dll'.
18702498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
18712498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\kernel.appcore.dll)
18722498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\kernel.appcore.dll
18732498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc3f5a0000 LB 0x0004a000 C:\WINDOWS\system32\powrprof.dll [fFlags=0x0]
18742498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
18752498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'rpcrt4.dll'.
18762498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\powrprof.dll)
18772498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\powrprof.dll
18782498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc3f620000 LB 0x00629000 C:\WINDOWS\system32\windows.storage.dll [fFlags=0x0]
18792498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
18802498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #29 'rpcrt4.dll'.
18812498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #58 'combase.dll'.
18822498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #64 'profapi.dll'.
18832498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\windows.storage.dll)
18842498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\windows.storage.dll
18852498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc40620000 LB 0x01522000 C:\WINDOWS\system32\SHELL32.dll [fFlags=0x0]
18862498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\shell32.dll
18872498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc42560000 LB 0x000d7000 C:\WINDOWS\system32\COMDLG32.dll [fFlags=0x0]
18882498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\comdlg32.dll
18892498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc40460000 LB 0x000be000 C:\WINDOWS\system32\OLEAUT32.dll [fFlags=0x0]
18902498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\oleaut32.dll
18912498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc41d30000 LB 0x0015c000 C:\WINDOWS\system32\MSCTF.dll [fFlags=0x0]
18922498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\msctf.dll [avoiding WinVerifyTrust]
18932498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc405d0000 LB 0x00036000 C:\WINDOWS\system32\IMM32.dll [fFlags=0x0]
18942498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\imm32.dll [avoiding WinVerifyTrust]
18952498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc3fdc0000 LB 0x00044000 C:\WINDOWS\system32\cfgmgr32.dll [fFlags=0x0]
18962498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\cfgmgr32.dll [avoiding WinVerifyTrust]
18972498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc3def0000 LB 0x00027000 C:\WINDOWS\SYSTEM32\DEVOBJ.dll [fFlags=0x0]
18982498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\devobj.dll [avoiding WinVerifyTrust]
18992498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc3dba0000 LB 0x0002c000 C:\WINDOWS\SYSTEM32\WINMMBASE.dll [fFlags=0x0]
19002498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\winmmbase.dll [avoiding WinVerifyTrust]
19012498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc3dbd0000 LB 0x00023000 C:\WINDOWS\SYSTEM32\WINMM.dll [fFlags=0x0]
19022498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\winmm.dll
19032498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc2ef60000 LB 0x00084000 C:\WINDOWS\SYSTEM32\WINSPOOL.DRV [fFlags=0x0]
19042498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume5\Windows\System32\winspool.drv [avoiding WinVerifyTrust]
19052498.2eb4: supR3HardenedDllNotificationCallback: load 0000000057ea0000 LB 0x0096c000 C:\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll [fFlags=0x0]
19062498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll
19072498.2eb4: supR3HardenedDllNotificationCallback: load 00000000593d0000 LB 0x00105000 C:\Program Files\Oracle\VirtualBox\QtNetworkVBox4.dll [fFlags=0x0]
19082498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\QtNetworkVBox4.dll
19092498.2eb4: supR3HardenedDllNotificationCallback: load 0000000058e40000 LB 0x000dc000 C:\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll [fFlags=0x0]
19102498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll
19112498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc0fe20000 LB 0x00ab9000 C:\Program Files\Oracle\VirtualBox\VirtualBox.dll [fFlags=0x0]
19122498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBox.dll
19132498.2eb4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\windows.storage.dll'.
19142498.2eb4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\windows.storage.dll' [rescheduled]
19152498.2eb4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\powrprof.dll'.
19162498.2eb4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\powrprof.dll' [rescheduled]
19172498.2eb4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\kernel.appcore.dll'.
19182498.2eb4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\kernel.appcore.dll' [rescheduled]
19192498.2eb4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\SHCore.dll'.
19202498.2eb4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\SHCore.dll' [rescheduled]
19212498.2eb4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.10240.16384_none_0212ec7eba871e86\comctl32.dll'.
19222498.2eb4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.10240.16384_none_0212ec7eba871e86\comctl32.dll' [rescheduled]
19232498.2eb4: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume5\Windows\System32\dciman32.dll'.
19242498.2eb4: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\dciman32.dll' [rescheduled]
19252498.2eb4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\msctf.dll'.
19262498.2eb4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\msctf.dll' [rescheduled]
19272498.2eb4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\imm32.dll'.
19282498.2eb4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\imm32.dll' [rescheduled]
19292498.2eb4: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume5\Windows\System32\winspool.drv'.
19302498.2eb4: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\winspool.drv' [rescheduled]
19312498.2eb4: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume5\Windows\System32\glu32.dll'.
19322498.2eb4: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\glu32.dll' [rescheduled]
19332498.2eb4: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume5\Windows\System32\ddraw.dll'.
19342498.2eb4: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\ddraw.dll' [rescheduled]
19352498.2eb4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\combase.dll'.
19362498.2eb4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\combase.dll' [rescheduled]
19372498.2eb4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\shlwapi.dll'.
19382498.2eb4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\shlwapi.dll' [rescheduled]
19392498.2eb4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\comctl32.dll'.
19402498.2eb4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\comctl32.dll' [rescheduled]
19412498.2eb4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\cfgmgr32.dll'.
19422498.2eb4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\cfgmgr32.dll' [rescheduled]
19432498.2eb4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\devobj.dll'.
19442498.2eb4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\devobj.dll' [rescheduled]
19452498.2eb4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\winmmbase.dll'.
19462498.2eb4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\winmmbase.dll' [rescheduled]
19472498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\imm32.dll [redoing WinVerifyTrust]
19482498.2eb4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\imm32.dll'.
19492498.2eb4: supR3HardenedScreenImage/LdrLoadDll: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume5\Windows\System32\imm32.dll
19502498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'profapi.dll'...
19512498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'profapi.dll' -> '\Device\HarddiskVolume5\Windows\System32\profapi.dll' [rcNtRedir=0xc0150008]
19522498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\profapi.dll
19532498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
19542498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume5\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
19552498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\combase.dll [redoing WinVerifyTrust]
19562498.2eb4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\combase.dll'.
19572498.2eb4: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume5\Windows\System32\combase.dll
19582498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
19592498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume5\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
19602498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
19612498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
19622498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
19632498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume5\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
19642498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
19652498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
19662498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
19672498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume5\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
19682498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
19692498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
19702498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
19712498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume5\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
19722498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\combase.dll [redoing WinVerifyTrust]
19732498.2eb4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\combase.dll'.
19742498.2eb4: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume5\Windows\System32\combase.dll
19752498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
19762498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
19772498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
19782498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume5\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
19792498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
19802498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume5\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
19812498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
19822498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume5\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
19832498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\advapi32.dll
19842498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\imm32.dll (Input=imm32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
19852498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc405d0000 'C:\WINDOWS\system32\imm32.dll'
19862498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc0fe20000 'C:\Program Files\Oracle\VirtualBox\VirtualBox.dll'
19872498.2eb4: SUPR3HardenedMain: Calling TrustedMain (00007ffc0fe21910)...
19882498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\winmm.dll
19892498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\winmm.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
19902498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3dbd0000 'C:\WINDOWS\system32\winmm.dll'
19912498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000005fc pwszName=\Device\HarddiskVolume5\Windows\System32\uxtheme.dll
19922498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000012bca70
19932498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000012bca70
19942498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=3717D376EF95470D8C03AD02F97C4DCBCE269CF8
19952498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
19962498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
19972498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_205_for_KB3074683~31bf3856ad364e35~amd64~~10.0.1.0.cat'; file='\Device\HarddiskVolume5\Windows\System32\uxtheme.dll'
19982498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
19992498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
20002498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #31 'gdi32.dll'.
20012498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #32 'user32.dll'.
20022498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\uxtheme.dll) WinVerifyTrust
20032498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\uxtheme.dll
20042498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
20052498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume5\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
20062498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
20072498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume5\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
20082498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
20092498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
20102498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
20112498.2eb4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\uxtheme.dll
20122498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc3de50000 LB 0x00096000 C:\WINDOWS\system32\uxtheme.dll [fFlags=0x0]
20132498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\uxtheme.dll
20142498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3de50000 'C:\WINDOWS\system32\uxtheme.dll'
20152498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000654 pwszName=\Device\HarddiskVolume5\Program Files\Common Files\microsoft shared\ink\tiptsf.dll
20162498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000012bca70
20172498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000012bca70
20182498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=09FF5B072B6B78D02C4955C2161A8E11ABD90FFC
20192498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
20202498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
20212498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TabletPC-Package~31bf3856ad364e35~amd64~~10.0.10240.16384.cat'; file='\Device\HarddiskVolume5\Program Files\Common Files\microsoft shared\ink\tiptsf.dll'
20222498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
20232498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
20242498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'rpcrt4.dll'.
20252498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #20 'user32.dll'.
20262498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #21 'msctf.dll'.
20272498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Program Files\Common Files\microsoft shared\ink\tiptsf.dll) WinVerifyTrust
20282498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Program Files\Common Files\microsoft shared\ink\tiptsf.dll
20292498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msctf.dll'...
20302498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msctf.dll' -> '\Device\HarddiskVolume5\Windows\System32\msctf.dll' [rcNtRedir=0xc0150008]
20312498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\msctf.dll [redoing WinVerifyTrust]
20322498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
20332498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
20342498.2eb4: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\msctf.dll'
20352498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
20362498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume5\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
20372498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
20382498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume5\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
20392498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
20402498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
20412498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Common Files\microsoft shared\ink\tiptsf.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
20422498.2eb4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Common Files\microsoft shared\ink\tiptsf.dll
20432498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc2f970000 LB 0x000a2000 C:\Program Files\Common Files\microsoft shared\ink\tiptsf.dll [fFlags=0x0]
20442498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Common Files\microsoft shared\ink\tiptsf.dll
20452498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc2f970000 'C:\Program Files\Common Files\microsoft shared\ink\tiptsf.dll'
20462498.2eb4: \Device\HarddiskVolume5\Program Files (x86)\TeamViewer\tv_x64.dll: Owner is administrators group.
20472498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
20482498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'version.dll'.
20492498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'comctl32.dll'.
20502498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
20512498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'gdi32.dll'.
20522498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'shell32.dll'.
20532498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ole32.dll'.
20542498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Program Files (x86)\TeamViewer\tv_x64.dll) WinVerifyTrust
20552498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Program Files (x86)\TeamViewer\tv_x64.dll
20562498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
20572498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume5\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
20582498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\ole32.dll
20592498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
20602498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume5\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
20612498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\shell32.dll
20622498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
20632498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume5\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
20642498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\gdi32.dll
20652498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
20662498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume5\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
20672498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comctl32.dll'...
20682498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'comctl32.dll' -> '\Device\HarddiskVolume5\Windows\System32\comctl32.dll' [rcNtRedir=0x0]
20692498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\comctl32.dll [redoing WinVerifyTrust]
20702498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
20712498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
20722498.2eb4: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\comctl32.dll'
20732498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'version.dll'...
20742498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'version.dll' -> '\Device\HarddiskVolume5\Windows\System32\version.dll' [rcNtRedir=0xc0150008]
20752498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
20762498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
20772498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
20782498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\version.dll) WinVerifyTrust
20792498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\version.dll
20802498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
20812498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
20822498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files (x86)\TeamViewer\tv_x64.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
20832498.2eb4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files (x86)\TeamViewer\tv_x64.dll
20842498.2eb4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\version.dll
20852498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc34ac0000 LB 0x0000a000 C:\WINDOWS\SYSTEM32\VERSION.dll [fFlags=0x0]
20862498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\version.dll
20872498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc267e0000 LB 0x00048000 C:\Program Files (x86)\TeamViewer\tv_x64.dll [fFlags=0x0]
20882498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files (x86)\TeamViewer\tv_x64.dll
20892498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc267e0000 'C:\Program Files (x86)\TeamViewer\tv_x64.dll'
20902498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\advapi32.dll
20912498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\advapi32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
20922498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc40520000 'C:\WINDOWS\system32\advapi32.dll'
20932498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
20942498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'user32.dll'.
20952498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'gdi32.dll'.
20962498.2eb4: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume5\Windows\System32\dwmapi.dll)
20972498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\dwmapi.dll
20982498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc3d090000 LB 0x00022000 C:\WINDOWS\system32\dwmapi.dll [fFlags=0x0]
20992498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume5\Windows\System32\dwmapi.dll [avoiding WinVerifyTrust]
21002498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000006ac pwszName=\Device\HarddiskVolume5\Windows\System32\dwmapi.dll
21012498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000012bca70
21022498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000012bca70
21032498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=71451274041047D99462EA805D3FAD1A9E10F86D
21042498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
21052498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume5\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
21062498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
21072498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume5\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
21082498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
21092498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
21102498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
21112498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
21122498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_42_for_KB3074683~31bf3856ad364e35~amd64~~10.0.1.0.cat'; file='\Device\HarddiskVolume5\Windows\System32\dwmapi.dll'
21132498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
21142498.2eb4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\dwmapi.dll'
21152498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\shell32.dll
21162498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
21172498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc40620000 'C:\WINDOWS\system32\shell32.dll'
21182498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\kernel32.dll
21192498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\kernel32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
21202498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc426a0000 'C:\WINDOWS\system32\kernel32.dll'
21212498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\uxtheme.dll
21222498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
21232498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3de50000 'C:\WINDOWS\system32\uxtheme.dll'
21242498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\uxtheme.dll
21252498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
21262498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3de50000 'C:\WINDOWS\system32\uxtheme.dll'
21272498.2eb4: supR3HardenedMonitor_LdrLoadDll: error opening 'C:\WINDOWS\system32\wintab32.dll': 0 (NtPath=\??\C:\WINDOWS\system32\wintab32.dll; Input=C:\WINDOWS\system32\wintab32.dll; rcNtGetDll=0x0
21282498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\wintab32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
21292498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000135 'C:\WINDOWS\system32\wintab32.dll'
21302498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc42340000 'C:\WINDOWS\system32\user32.dll'
21312498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\uxtheme.dll
21322498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
21332498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3de50000 'C:\WINDOWS\system32\uxtheme.dll'
21342498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc42340000 'C:\WINDOWS\system32\user32.dll'
21352498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\advapi32.dll
21362498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\advapi32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
21372498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc40520000 'C:\WINDOWS\system32\advapi32.dll'
21382498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
21392498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
21402498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
21412498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'rpcrt4.dll'.
21422498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #21 'profapi.dll'.
21432498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\userenv.dll) WinVerifyTrust
21442498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\userenv.dll
21452498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'profapi.dll'...
21462498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'profapi.dll' -> '\Device\HarddiskVolume5\Windows\System32\profapi.dll' [rcNtRedir=0xc0150008]
21472498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\profapi.dll
21482498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
21492498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume5\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
21502498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
21512498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
21522498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\userenv.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
21532498.2eb4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\userenv.dll
21542498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc3ecd0000 LB 0x0001f000 C:\WINDOWS\system32\userenv.dll [fFlags=0x0]
21552498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\userenv.dll
21562498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ecd0000 'C:\WINDOWS\system32\userenv.dll'
21572498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\kernel32.dll
21582498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\kernel32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
21592498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc426a0000 'C:\WINDOWS\system32\kernel32.dll'
21602498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc429d0000 LB 0x000a5000 C:\WINDOWS\system32\clbcatq.dll [fFlags=0x0]
21612498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
21622498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'rpcrt4.dll'.
21632498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\clbcatq.dll)
21642498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\clbcatq.dll
21652498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
21662498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume5\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
21672498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\rpcrt4.dll
21682498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
21692498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
21702498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\msvcrt.dll
21712498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
21722498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
21732498.2eb4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\clbcatq.dll'
21742498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
21752498.173c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
21762498.173c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
21772498.173c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
21782498.173c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'psapi.dll'.
21792498.173c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vboxrt.dll'.
21802498.173c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'advapi32.dll'.
21812498.173c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'version.dll'.
21822498.173c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'ws2_32.dll'.
21832498.173c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'ole32.dll'.
21842498.173c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'oleaut32.dll'.
21852498.173c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxC.dll) WinVerifyTrust
21862498.173c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxC.dll
21872498.173c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
21882498.173c: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume5\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
21892498.173c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\oleaut32.dll
21902498.173c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
21912498.173c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume5\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
21922498.173c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\ole32.dll
21932498.173c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
21942498.173c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume5\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
21952498.173c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\ws2_32.dll
21962498.173c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'version.dll'...
21972498.173c: supR3HardenedWinVerifyCacheProcessImportTodos: 'version.dll' -> '\Device\HarddiskVolume5\Windows\System32\version.dll' [rcNtRedir=0xc0150008]
21982498.173c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\version.dll
21992498.173c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
22002498.173c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume5\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
22012498.173c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
22022498.173c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
22032498.173c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'psapi.dll'...
22042498.173c: supR3HardenedWinVerifyCacheProcessImportTodos: 'psapi.dll' -> '\Device\HarddiskVolume5\Windows\System32\psapi.dll' [rcNtRedir=0xc0150008]
22052498.173c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
22062498.173c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
22072498.173c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\psapi.dll) WinVerifyTrust
22082498.173c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\psapi.dll
22092498.173c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
22102498.173c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
22112498.173c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\msvcp100.dll
22122498.173c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
22132498.173c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
22142498.173c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\msvcr100.dll
22152498.173c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxC.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
22162498.173c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxC.dll
22172498.173c: supR3HardenedDllNotificationCallback: load 00007ffc42ae0000 LB 0x00008000 C:\WINDOWS\system32\PSAPI.DLL [fFlags=0x0]
22182498.173c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\psapi.dll
22192498.173c: supR3HardenedDllNotificationCallback: load 00007ffc26040000 LB 0x005d7000 C:\Program Files\Oracle\VirtualBox\VBoxC.dll [fFlags=0x0]
22202498.173c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxC.dll
22212498.173c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc26040000 'C:\Program Files\Oracle\VirtualBox\VBoxC.dll'
22222498.173c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\oleaut32.dll
22232498.173c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\oleaut32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
22242498.173c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc40460000 'C:\Windows\System32\oleaut32.dll'
22252498.173c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\sxs.dll)
22262498.173c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\sxs.dll
22272498.173c: supR3HardenedDllNotificationCallback: load 00007ffc3f410000 LB 0x00098000 C:\WINDOWS\SYSTEM32\sxs.dll [fFlags=0x0]
22282498.173c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\sxs.dll [avoiding WinVerifyTrust]
22292498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
22302498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
22312498.2eb4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\sxs.dll'
22322498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\oleaut32.dll
22332498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\OLEAUT32.dll (Input=OLEAUT32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
22342498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc40460000 'C:\WINDOWS\system32\OLEAUT32.dll'
22352498.2eb4: supR3HardenedMonitor_LdrLoadDll: error opening 'C:\WINDOWS\system32\wintab32.dll': 0 (NtPath=\??\C:\WINDOWS\system32\wintab32.dll; Input=C:\WINDOWS\system32\wintab32.dll; rcNtGetDll=0x0
22362498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\wintab32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
22372498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000135 'C:\WINDOWS\system32\wintab32.dll'
22382498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc421b0000 'C:\WINDOWS\system32\gdi32.dll'
22392498.1074: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
22402498.1074: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
22412498.1074: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
22422498.1074: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
22432498.1074: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
22442498.1074: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMain.dll) WinVerifyTrust
22452498.1074: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMain.dll
22462498.1074: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
22472498.1074: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
22482498.1074: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
22492498.1074: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
22502498.1074: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.amd64/VBoxPuelMain.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
22512498.1074: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMain.dll
22522498.1074: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000139 'C:\Program Files\Oracle\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.amd64/VBoxPuelMain.DLL'
22532498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc42340000 'C:\WINDOWS\system32\user32.dll'
22542498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\shell32.dll
22552498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
22562498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc40620000 'C:\WINDOWS\system32\shell32.dll'
22572498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000bc8 pwszName=\Device\HarddiskVolume5\Windows\System32\DataExchange.dll
22582498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000012bca70
22592498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000012bca70
22602498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=030BB80F5AC7982FF01AB351589D64E6D4167B3E
22612498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
22622498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
22632498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-OneCore-AppRuntime-shell-Package~31bf3856ad364e35~amd64~~10.0.10240.16384.cat'; file='\Device\HarddiskVolume5\Windows\System32\DataExchange.dll'
22642498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
22652498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
22662498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'shcore.dll'.
22672498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'combase.dll'.
22682498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'd2d1.dll'.
22692498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'd3d11.dll'.
22702498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 'dcomp.dll'.
22712498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\DataExchange.dll) WinVerifyTrust
22722498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\DataExchange.dll
22732498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dcomp.dll'...
22742498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'dcomp.dll' -> '\Device\HarddiskVolume5\Windows\System32\dcomp.dll' [rcNtRedir=0xc0150008]
22752498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\rsaenh.dll
22762498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
22772498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
22782498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
22792498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
22802498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\dcomp.dll) WinVerifyTrust
22812498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\dcomp.dll
22822498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'd3d11.dll'...
22832498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'd3d11.dll' -> '\Device\HarddiskVolume5\Windows\System32\d3d11.dll' [rcNtRedir=0xc0150008]
22842498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
22852498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
22862498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
22872498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
22882498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
22892498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'dxgi.dll'.
22902498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\d3d11.dll) WinVerifyTrust
22912498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\d3d11.dll
22922498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'd2d1.dll'...
22932498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'd2d1.dll' -> '\Device\HarddiskVolume5\Windows\System32\d2d1.dll' [rcNtRedir=0xc0150008]
22942498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000ba0 pwszName=\Device\HarddiskVolume5\Windows\System32\d2d1.dll
22952498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000012bca70
22962498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000012bca70
22972498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=CA1A7323788F698339FF353F1BA100EF7C556D74
22982498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dxgi.dll'...
22992498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'dxgi.dll' -> '\Device\HarddiskVolume5\Windows\System32\dxgi.dll' [rcNtRedir=0xc0150008]
23002498.2eb4: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\dxgi.dll'.
23012498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
23022498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'user32.dll'.
23032498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\dxgi.dll)
23042498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\dxgi.dll
23052498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
23062498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
23072498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
23082498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume5\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
23092498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
23102498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
23112498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
23122498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
23132498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-OneCore-Graphics-DirectX-Package~31bf3856ad364e35~amd64~~10.0.10240.16384.cat'; file='\Device\HarddiskVolume5\Windows\System32\d2d1.dll'
23142498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
23152498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
23162498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\d2d1.dll) WinVerifyTrust
23172498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\d2d1.dll
23182498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
23192498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume5\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
23202498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\combase.dll [redoing WinVerifyTrust]
23212498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
23222498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
23232498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
23242498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
23252498.2eb4: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\combase.dll'
23262498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shcore.dll'...
23272498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'shcore.dll' -> '\Device\HarddiskVolume5\Windows\System32\shcore.dll' [rcNtRedir=0xc0150008]
23282498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\SHCore.dll [redoing WinVerifyTrust]
23292498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
23302498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
23312498.2eb4: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\SHCore.dll'
23322498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
23332498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
23342498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\dataexchange.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
23352498.2eb4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\DataExchange.dll
23362498.2eb4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\d2d1.dll
23372498.2eb4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\d3d11.dll
23382498.2eb4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\dcomp.dll
23392498.2eb4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\dxgi.dll [avoiding WinVerifyTrust]
23402498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc36b90000 LB 0x00545000 C:\WINDOWS\system32\d2d1.dll [fFlags=0x0]
23412498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\d2d1.dll
23422498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc3caa0000 LB 0x0009c000 C:\WINDOWS\system32\dxgi.dll [fFlags=0x0]
23432498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\dxgi.dll [avoiding WinVerifyTrust]
23442498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc3cb40000 LB 0x002a3000 C:\WINDOWS\system32\d3d11.dll [fFlags=0x0]
23452498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\d3d11.dll
23462498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc3d7e0000 LB 0x000d1000 C:\WINDOWS\system32\dcomp.dll [fFlags=0x0]
23472498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\dcomp.dll
23482498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc2b290000 LB 0x00046000 C:\WINDOWS\system32\dataexchange.dll [fFlags=0x0]
23492498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\DataExchange.dll
23502498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc2b290000 'C:\WINDOWS\system32\dataexchange.dll'
23512498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
23522498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
23532498.2eb4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\dxgi.dll'
23542498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
23552498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 'userenv.dll'.
23562498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #29 'bcrypt.dll'.
23572498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #30 'rpcrt4.dll'.
23582498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #39 'combase.dll'.
23592498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\twinapi.appcore.dll)
23602498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\twinapi.appcore.dll
23612498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc3df40000 LB 0x000ee000 C:\WINDOWS\system32\twinapi.appcore.dll [fFlags=0x0]
23622498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\twinapi.appcore.dll [avoiding WinVerifyTrust]
23632498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
23642498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume5\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
23652498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\combase.dll
23662498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
23672498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume5\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
23682498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
23692498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume5\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
23702498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\bcrypt.dll
23712498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'userenv.dll'...
23722498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'userenv.dll' -> '\Device\HarddiskVolume5\Windows\System32\userenv.dll' [rcNtRedir=0xc0150008]
23732498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\userenv.dll
23742498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
23752498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
23762498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
23772498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
23782498.2eb4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\twinapi.appcore.dll'
23792498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\kernel32.dll
23802498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\kernel32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
23812498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc426a0000 'C:\WINDOWS\system32\kernel32.dll'
23822498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\dwmapi.dll
23832498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\dwmapi.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
23842498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3d090000 'C:\WINDOWS\system32\dwmapi.dll'
23852498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\uxtheme.dll
23862498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
23872498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3de50000 'C:\WINDOWS\system32\uxtheme.dll'
23882498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc42340000 'C:\WINDOWS\system32\user32.dll'
23892498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\ole32.dll
23902498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\ole32.dll (Input=ole32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
23912498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc42060000 'C:\WINDOWS\system32\ole32.dll'
23922498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\oleaut32.dll
23932498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\OLEAUT32.dll (Input=OLEAUT32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
23942498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc40460000 'C:\WINDOWS\system32\OLEAUT32.dll'
23952498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000c94 pwszName=\Device\HarddiskVolume5\Windows\System32\wbem\wbemprox.dll
23962498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000012bca70
23972498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000012bca70
23982498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=AA7BAB6C49E4A06208A6E0EE146D0A4385100231
23992498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
24002498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
24012498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-OneCore-WinMgmt-admin-Package~31bf3856ad364e35~amd64~~10.0.10240.16384.cat'; file='\Device\HarddiskVolume5\Windows\System32\wbem\wbemprox.dll'
24022498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
24032498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
24042498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ws2_32.dll'.
24052498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'wbemcomn.dll'.
24062498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\wbem\wbemprox.dll) WinVerifyTrust
24072498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\wbem\wbemprox.dll
24082498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wbemcomn.dll'...
24092498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'wbemcomn.dll' -> '\Device\HarddiskVolume5\Windows\System32\wbemcomn.dll' [rcNtRedir=0xc0150008]
24102498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000ca4 pwszName=\Device\HarddiskVolume5\Windows\System32\wbemcomn.dll
24112498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000012bca70
24122498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000012bca70
24132498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=8589CB867869E61D2D0DD902D9F24828D41B3FB4
24142498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
24152498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
24162498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-OneCore-WinMgmt-admin-Package~31bf3856ad364e35~amd64~~10.0.10240.16384.cat'; file='\Device\HarddiskVolume5\Windows\System32\wbemcomn.dll'
24172498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
24182498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
24192498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'bcrypt.dll'.
24202498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'ws2_32.dll'.
24212498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\wbemcomn.dll) WinVerifyTrust
24222498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\wbemcomn.dll
24232498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
24242498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume5\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
24252498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\ws2_32.dll
24262498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
24272498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
24282498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
24292498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume5\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
24302498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\ws2_32.dll
24312498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
24322498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume5\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
24332498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\bcrypt.dll
24342498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
24352498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
24362498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\wbem\wbemprox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
24372498.2eb4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\wbem\wbemprox.dll
24382498.2eb4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\wbemcomn.dll
24392498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc371f0000 LB 0x0007f000 C:\WINDOWS\SYSTEM32\wbemcomn.dll [fFlags=0x0]
24402498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\wbemcomn.dll
24412498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc341f0000 LB 0x00011000 C:\WINDOWS\system32\wbem\wbemprox.dll [fFlags=0x0]
24422498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\wbem\wbemprox.dll
24432498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Core-LocalRegistry-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
24442498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ffe0000 'API-MS-Win-Core-LocalRegistry-L1-1-0.dll'
24452498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc341f0000 'C:\WINDOWS\system32\wbem\wbemprox.dll'
24462498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000c38 pwszName=\Device\HarddiskVolume5\Windows\System32\wbem\wbemsvc.dll
24472498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000012bca70
24482498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000012bca70
24492498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F55A40FEDA5AB0854F7A2A7AE88B827B3F76303B
24502498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
24512498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
24522498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-OneCore-WinMgmt-admin-Package~31bf3856ad364e35~amd64~~10.0.10240.16384.cat'; file='\Device\HarddiskVolume5\Windows\System32\wbem\wbemsvc.dll'
24532498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
24542498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
24552498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'rpcrt4.dll'.
24562498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\wbem\wbemsvc.dll) WinVerifyTrust
24572498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\wbem\wbemsvc.dll
24582498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
24592498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume5\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
24602498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
24612498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
24622498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\wbem\wbemsvc.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
24632498.2eb4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\wbem\wbemsvc.dll
24642498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc33a10000 LB 0x00014000 C:\WINDOWS\system32\wbem\wbemsvc.dll [fFlags=0x0]
24652498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\wbem\wbemsvc.dll
24662498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc33a10000 'C:\WINDOWS\system32\wbem\wbemsvc.dll'
24672498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-l1-2-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
24682498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ffe0000 'api-ms-win-core-localization-l1-2-0.dll'
24692498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-obsolete-l1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
24702498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ffe0000 'api-ms-win-core-localization-obsolete-l1-1-0.dll'
24712498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000c44 pwszName=\Device\HarddiskVolume5\Windows\System32\wbem\fastprox.dll
24722498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000012bca70
24732498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000012bca70
24742498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=E360AD530F1A62ACF9003C6FE3BA6BBD7638D488
24752498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
24762498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
24772498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-OneCore-WinMgmt-admin-Package~31bf3856ad364e35~amd64~~10.0.10240.16384.cat'; file='\Device\HarddiskVolume5\Windows\System32\wbem\fastprox.dll'
24782498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
24792498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
24802498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'wbemcomn.dll'.
24812498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\wbem\fastprox.dll) WinVerifyTrust
24822498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\wbem\fastprox.dll
24832498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wbemcomn.dll'...
24842498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'wbemcomn.dll' -> '\Device\HarddiskVolume5\Windows\System32\wbemcomn.dll' [rcNtRedir=0xc0150008]
24852498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\wbemcomn.dll
24862498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
24872498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
24882498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\wbem\fastprox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
24892498.2eb4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\wbem\fastprox.dll
24902498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc33d30000 LB 0x000f8000 C:\WINDOWS\system32\wbem\fastprox.dll [fFlags=0x0]
24912498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\wbem\fastprox.dll
24922498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc33d30000 'C:\WINDOWS\system32\wbem\fastprox.dll'
24932498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000d24 pwszName=\Device\HarddiskVolume5\Windows\System32\UIAutomationCore.dll
24942498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000012bca70
24952498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000012bca70
24962498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=16E6BFDCA13CB7F51A7C251687D263D303321EBA
24972498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
24982498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
24992498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_181_for_KB3081444~31bf3856ad364e35~amd64~~10.0.1.0.cat'; file='\Device\HarddiskVolume5\Windows\System32\UIAutomationCore.dll'
25002498.2eb4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
25012498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
25022498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'oleaut32.dll'.
25032498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #15 'rpcrt4.dll'.
25042498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'userenv.dll'.
25052498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\UIAutomationCore.dll) WinVerifyTrust
25062498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\UIAutomationCore.dll
25072498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'userenv.dll'...
25082498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'userenv.dll' -> '\Device\HarddiskVolume5\Windows\System32\userenv.dll' [rcNtRedir=0xc0150008]
25092498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\userenv.dll
25102498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
25112498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume5\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
25122498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
25132498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume5\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
25142498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\oleaut32.dll
25152498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
25162498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
25172498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\uiautomationcore.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
25182498.2eb4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\UIAutomationCore.dll
25192498.2eb4: supR3HardenedDllNotificationCallback: load 00007ffc36540000 LB 0x0014c000 C:\Windows\System32\uiautomationcore.dll [fFlags=0x0]
25202498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\UIAutomationCore.dll
25212498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36540000 'C:\Windows\System32\uiautomationcore.dll'
25222498.173c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\UIAutomationCore.dll
25232498.173c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\UIAutomationCore.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
25242498.173c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36540000 'C:\Windows\System32\UIAutomationCore.dll'
25252498.199c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
25262498.199c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
25272498.199c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrem.dll'.
25282498.199c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
25292498.199c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxVMM.dll) WinVerifyTrust
25302498.199c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxVMM.dll
25312498.199c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
25322498.199c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
25332498.199c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrem.dll'...
25342498.199c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrem.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\vboxrem.dll' [rcNtRedir=0xc0150008]
25352498.199c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
25362498.199c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'vboxrt.dll'.
25372498.199c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
25382498.199c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcrt.dll'.
25392498.199c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxREM.dll) WinVerifyTrust
25402498.199c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxREM.dll
25412498.199c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
25422498.199c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
25432498.199c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
25442498.199c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
25452498.199c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
25462498.199c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
25472498.199c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxVMM.dll
25482498.199c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
25492498.199c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
25502498.199c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
25512498.199c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxVMM.dll
25522498.199c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxREM.dll
25532498.199c: supR3HardenedDllNotificationCallback: load 0000000058d30000 LB 0x0010a000 C:\Program Files\Oracle\VirtualBox\VBoxREM.dll [fFlags=0x0]
25542498.199c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxREM.dll
25552498.199c: supR3HardenedDllNotificationCallback: load 00007ffc11510000 LB 0x00293000 C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL [fFlags=0x0]
25562498.199c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxVMM.dll
25572498.199c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11510000 'C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL'
25582498.288c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
25592498.288c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ndis.sys'.
25602498.288c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'ntoskrnl.exe'.
25612498.288c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\drivers\VBoxNetAdp6.sys)
25622498.288c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\drivers\VBoxNetAdp6.sys
25632498.288c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\drivers\VBoxNetAdp6.sys [avoiding WinVerifyTrust]
25642498.288c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
25652498.288c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'ndis.sys'.
25662498.288c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'netio.sys'.
25672498.288c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\drivers\VBoxNetLwf.sys)
25682498.288c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\drivers\VBoxNetLwf.sys
25692498.288c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\drivers\VBoxNetLwf.sys [avoiding WinVerifyTrust]
25702498.288c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
25712498.288c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\drivers\VBoxUSBMon.sys)
25722498.288c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\drivers\VBoxUSBMon.sys
25732498.288c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\drivers\VBoxUSBMon.sys [avoiding WinVerifyTrust]
25742498.288c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
25752498.288c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\drivers\VBoxDrv.sys)
25762498.288c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\drivers\VBoxDrv.sys
25772498.288c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\drivers\VBoxDrv.sys [avoiding WinVerifyTrust]
25782498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
25792498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume5\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
25802498.2eb4: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\ntoskrnl.exe'.
25812498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'hal.dll'.
25822498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'pshed.dll'.
25832498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'bootvid.dll'.
25842498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'kdcom.dll'.
25852498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'ci.dll'.
25862498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'msrpc.sys'.
25872498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\ntoskrnl.exe)
25882498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\ntoskrnl.exe
25892498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
25902498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume5\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
25912498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\ntoskrnl.exe [lacks WinVerifyTrust]
25922498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'netio.sys'...
25932498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'netio.sys' -> '\Device\HarddiskVolume5\Windows\System32\drivers\netio.sys' [rcNtRedir=0xc0150008]
25942498.2eb4: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\drivers\netio.sys'.
25952498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
25962498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'ndis.sys'.
25972498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msrpc.sys'.
25982498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\drivers\netio.sys)
25992498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\drivers\netio.sys
26002498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ndis.sys'...
26012498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ndis.sys' -> '\Device\HarddiskVolume5\Windows\System32\drivers\ndis.sys' [rcNtRedir=0xc0150008]
26022498.2eb4: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\drivers\ndis.sys'.
26032498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
26042498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'hal.dll'.
26052498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'netio.sys'.
26062498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'wpprecorder.sys'.
26072498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\drivers\ndis.sys)
26082498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\drivers\ndis.sys
26092498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
26102498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume5\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
26112498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\ntoskrnl.exe [lacks WinVerifyTrust]
26122498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
26132498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume5\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
26142498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\ntoskrnl.exe [lacks WinVerifyTrust]
26152498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ndis.sys'...
26162498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ndis.sys' -> '\Device\HarddiskVolume5\Windows\System32\drivers\ndis.sys' [rcNtRedir=0xc0150008]
26172498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\drivers\ndis.sys [lacks WinVerifyTrust]
26182498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wpprecorder.sys'...
26192498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'wpprecorder.sys' -> '\Device\HarddiskVolume5\Windows\System32\drivers\wpprecorder.sys' [rcNtRedir=0xc0150008]
26202498.2eb4: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\drivers\WppRecorder.sys'.
26212498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
26222498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\drivers\WppRecorder.sys)
26232498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\drivers\WppRecorder.sys
26242498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'netio.sys'...
26252498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'netio.sys' -> '\Device\HarddiskVolume5\Windows\System32\drivers\netio.sys' [rcNtRedir=0xc0150008]
26262498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\drivers\netio.sys [lacks WinVerifyTrust]
26272498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'hal.dll'...
26282498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'hal.dll' -> '\Device\HarddiskVolume5\Windows\System32\hal.dll' [rcNtRedir=0xc0150008]
26292498.2eb4: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\hal.dll'.
26302498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
26312498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'kdcom.dll'.
26322498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'pshed.dll'.
26332498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\hal.dll)
26342498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\hal.dll
26352498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
26362498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume5\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
26372498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\ntoskrnl.exe [lacks WinVerifyTrust]
26382498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msrpc.sys'...
26392498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msrpc.sys' -> '\Device\HarddiskVolume5\Windows\System32\drivers\msrpc.sys' [rcNtRedir=0xc0150008]
26402498.2eb4: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\drivers\msrpc.sys'.
26412498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
26422498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\drivers\msrpc.sys)
26432498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\drivers\msrpc.sys
26442498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ndis.sys'...
26452498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ndis.sys' -> '\Device\HarddiskVolume5\Windows\System32\drivers\ndis.sys' [rcNtRedir=0xc0150008]
26462498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\drivers\ndis.sys [lacks WinVerifyTrust]
26472498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
26482498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume5\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
26492498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\ntoskrnl.exe [lacks WinVerifyTrust]
26502498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msrpc.sys'...
26512498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Failed to locate 'msrpc.sys'
26522498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ci.dll'...
26532498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ci.dll' -> '\Device\HarddiskVolume5\Windows\System32\ci.dll' [rcNtRedir=0xc0150008]
26542498.2eb4: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\ci.dll'.
26552498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
26562498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'hal.dll'.
26572498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\ci.dll)
26582498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\ci.dll
26592498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'kdcom.dll'...
26602498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'kdcom.dll' -> '\Device\HarddiskVolume5\Windows\System32\kdcom.dll' [rcNtRedir=0xc0150008]
26612498.2eb4: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\kdcom.dll'.
26622498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
26632498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'hal.dll'.
26642498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\kdcom.dll)
26652498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\kdcom.dll
26662498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bootvid.dll'...
26672498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'bootvid.dll' -> '\Device\HarddiskVolume5\Windows\System32\bootvid.dll' [rcNtRedir=0xc0150008]
26682498.2eb4: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\BOOTVID.DLL'.
26692498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
26702498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\BOOTVID.DLL)
26712498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\BOOTVID.DLL
26722498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'pshed.dll'...
26732498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'pshed.dll' -> '\Device\HarddiskVolume5\Windows\System32\pshed.dll' [rcNtRedir=0xc0150008]
26742498.2eb4: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\PSHED.DLL'.
26752498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
26762498.2eb4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'hal.dll'.
26772498.2eb4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\PSHED.DLL)
26782498.2eb4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\PSHED.DLL
26792498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'hal.dll'...
26802498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'hal.dll' -> '\Device\HarddiskVolume5\Windows\System32\hal.dll' [rcNtRedir=0xc0150008]
26812498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\hal.dll [lacks WinVerifyTrust]
26822498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'hal.dll'...
26832498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'hal.dll' -> '\Device\HarddiskVolume5\Windows\System32\hal.dll' [rcNtRedir=0xc0150008]
26842498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\hal.dll [lacks WinVerifyTrust]
26852498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
26862498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume5\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
26872498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\ntoskrnl.exe [lacks WinVerifyTrust]
26882498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
26892498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume5\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
26902498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\ntoskrnl.exe [lacks WinVerifyTrust]
26912498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'hal.dll'...
26922498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'hal.dll' -> '\Device\HarddiskVolume5\Windows\System32\hal.dll' [rcNtRedir=0xc0150008]
26932498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\hal.dll [lacks WinVerifyTrust]
26942498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
26952498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume5\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
26962498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\ntoskrnl.exe [lacks WinVerifyTrust]
26972498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'hal.dll'...
26982498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'hal.dll' -> '\Device\HarddiskVolume5\Windows\System32\hal.dll' [rcNtRedir=0xc0150008]
26992498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\hal.dll [lacks WinVerifyTrust]
27002498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
27012498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume5\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
27022498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\ntoskrnl.exe [lacks WinVerifyTrust]
27032498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
27042498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume5\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
27052498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\ntoskrnl.exe [lacks WinVerifyTrust]
27062498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'pshed.dll'...
27072498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'pshed.dll' -> '\Device\HarddiskVolume5\Windows\System32\pshed.dll' [rcNtRedir=0xc0150008]
27082498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\PSHED.DLL [lacks WinVerifyTrust]
27092498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'kdcom.dll'...
27102498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'kdcom.dll' -> '\Device\HarddiskVolume5\Windows\System32\kdcom.dll' [rcNtRedir=0xc0150008]
27112498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\kdcom.dll [lacks WinVerifyTrust]
27122498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
27132498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume5\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
27142498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\ntoskrnl.exe [lacks WinVerifyTrust]
27152498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
27162498.2eb4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume5\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
27172498.2eb4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\ntoskrnl.exe [lacks WinVerifyTrust]
27182498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
27192498.2eb4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\drivers\VBoxDrv.sys'
27202498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
27212498.2eb4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\drivers\VBoxUSBMon.sys'
27222498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
27232498.2eb4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\drivers\VBoxNetLwf.sys'
27242498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
27252498.2eb4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\drivers\VBoxNetAdp6.sys'
27262498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
27272498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
27282498.2eb4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\PSHED.DLL'
27292498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
27302498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
27312498.2eb4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\BOOTVID.DLL'
27322498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
27332498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\crypt32.dll
27342498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
27352498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
27362498.2eb4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\kdcom.dll'
27372498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
27382498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
27392498.2eb4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\ci.dll'
27402498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
27412498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
27422498.2eb4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\drivers\msrpc.sys'
27432498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
27442498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
27452498.2eb4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\hal.dll'
27462498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
27472498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
27482498.2eb4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\drivers\WppRecorder.sys'
27492498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
27502498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
27512498.2eb4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\drivers\ndis.sys'
27522498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
27532498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
27542498.2eb4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\drivers\netio.sys'
27552498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ea00000 'C:\WINDOWS\system32\rsaenh.dll'
27562498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3fe10000 'C:\WINDOWS\system32\crypt32.dll'
27572498.2eb4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\ntoskrnl.exe'
27582498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\dwmapi.dll
27592498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\SYSTEM32\dwmapi.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
27602498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3d090000 'C:\WINDOWS\SYSTEM32\dwmapi.dll'
27612498.2eb4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\kernel32.dll
27622498.2eb4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\kernel32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
27632498.2eb4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc426a0000 'C:\WINDOWS\system32\kernel32.dll'
27642498.2eb4: supR3HardenedDllNotificationCallback: Unload 00007ffc33a10000 LB 0x00014000 C:\WINDOWS\system32\wbem\wbemsvc.dll [flags=0x0]
27652498.2eb4: supR3HardenedDllNotificationCallback: Unload 00007ffc2b290000 LB 0x00046000 C:\WINDOWS\system32\dataexchange.dll [flags=0x0]
27662498.2eb4: supR3HardenedDllNotificationCallback: Unload 00007ffc36b90000 LB 0x00545000 C:\WINDOWS\system32\d2d1.dll [flags=0x0]
27672498.2eb4: supR3HardenedDllNotificationCallback: Unload 00007ffc3cb40000 LB 0x002a3000 C:\WINDOWS\system32\d3d11.dll [flags=0x0]
27682498.2eb4: supR3HardenedDllNotificationCallback: Unload 00007ffc3caa0000 LB 0x0009c000 C:\WINDOWS\system32\dxgi.dll [flags=0x0]
27692498.2eb4: supR3HardenedDllNotificationCallback: Unload 00007ffc3d7e0000 LB 0x000d1000 C:\WINDOWS\system32\dcomp.dll [flags=0x0]
27702498.2eb4: supR3HardenedDllNotificationCallback: Unload 00007ffc3df40000 LB 0x000ee000 C:\WINDOWS\system32\twinapi.appcore.dll [flags=0x0]
27712498.2eb4: supR3HardenedDllNotificationCallback: Unload 00007ffc33d30000 LB 0x000f8000 C:\WINDOWS\system32\wbem\fastprox.dll [flags=0x0]
27722498.2eb4: supR3HardenedDllNotificationCallback: Unload 00007ffc341f0000 LB 0x00011000 C:\WINDOWS\system32\wbem\wbemprox.dll [flags=0x0]
27732498.2eb4: supR3HardenedDllNotificationCallback: Unload 00007ffc371f0000 LB 0x0007f000 C:\WINDOWS\SYSTEM32\wbemcomn.dll [flags=0x0]
27742498.2eb4: supR3HardenedDllNotificationCallback: Unload 00007ffc26040000 LB 0x005d7000 C:\Program Files\Oracle\VirtualBox\VBoxC.dll [flags=0x0]
27752498.2eb4: supR3HardenedDllNotificationCallback: Unload 00007ffc42ae0000 LB 0x00008000 C:\WINDOWS\system32\PSAPI.DLL [flags=0x0]
27762498.2eb4: Terminating the normal way: rcExit=1
277726dc.3020: supR3HardNtChildWaitFor[2]: Quitting: ExitCode=0x1 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 13673 ms, the end);
2778a70.1c88: supR3HardNtChildWaitFor[1]: Quitting: ExitCode=0x1 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 14720 ms, the end);

© 2024 Oracle Support Privacy / Do Not Sell My Info Terms of Use Trademark Policy Automated Access Etiquette