VirtualBox

Ticket #16291: VBoxHardening_freezeB.log

File VBoxHardening_freezeB.log, 381.3 KB (added by neumannd, 8 years ago)

Hardening Log file (relating to VBox_freezeB.log)

Line 
116c.e9c: Log file opened: 5.1.10r112026 g_hStartupLog=0000000000000014 g_uNtVerCombined=0x611db110
216c.e9c: \SystemRoot\System32\ntdll.dll:
316c.e9c: CreationTime: 2010-11-21T03:23:51.351694200Z
416c.e9c: LastWriteTime: 2010-11-21T03:23:51.367294200Z
516c.e9c: ChangeTime: 2016-09-30T16:27:23.544905100Z
616c.e9c: FileAttributes: 0x20
716c.e9c: Size: 0x1a6d60
816c.e9c: NT Headers: 0xe0
916c.e9c: Timestamp: 0x4ce7c8f9
1016c.e9c: Machine: 0x8664 - amd64
1116c.e9c: Timestamp: 0x4ce7c8f9
1216c.e9c: Image Version: 6.1
1316c.e9c: SizeOfImage: 0x1a9000 (1740800)
1416c.e9c: Resource Dir: 0x151000 LB 0x560d8
1516c.e9c: ProductName: Microsoft® Windows® Operating System
1616c.e9c: ProductVersion: 6.1.7601.17514
1716c.e9c: FileVersion: 6.1.7601.17514 (win7sp1_rtm.101119-1850)
1816c.e9c: FileDescription: NT Layer DLL
1916c.e9c: \SystemRoot\System32\kernel32.dll:
2016c.e9c: CreationTime: 2010-11-21T03:24:07.965723400Z
2116c.e9c: LastWriteTime: 2010-11-21T03:24:07.981323400Z
2216c.e9c: ChangeTime: 2016-09-30T16:27:03.155669300Z
2316c.e9c: FileAttributes: 0x20
2416c.e9c: Size: 0x11b800
2516c.e9c: NT Headers: 0xe8
2616c.e9c: Timestamp: 0x4ce7c78b
2716c.e9c: Machine: 0x8664 - amd64
2816c.e9c: Timestamp: 0x4ce7c78b
2916c.e9c: Image Version: 6.1
3016c.e9c: SizeOfImage: 0x11f000 (1175552)
3116c.e9c: Resource Dir: 0x116000 LB 0x528
3216c.e9c: ProductName: Microsoft® Windows® Operating System
3316c.e9c: ProductVersion: 6.1.7601.17514
3416c.e9c: FileVersion: 6.1.7601.17514 (win7sp1_rtm.101119-1850)
3516c.e9c: FileDescription: Windows NT BASE API Client DLL
3616c.e9c: \SystemRoot\System32\KernelBase.dll:
3716c.e9c: CreationTime: 2010-11-21T03:24:26.217755400Z
3816c.e9c: LastWriteTime: 2010-11-21T03:24:26.248955500Z
3916c.e9c: ChangeTime: 2016-09-30T16:27:03.077669200Z
4016c.e9c: FileAttributes: 0x20
4116c.e9c: Size: 0x66800
4216c.e9c: NT Headers: 0xf0
4316c.e9c: Timestamp: 0x4ce7c78c
4416c.e9c: Machine: 0x8664 - amd64
4516c.e9c: Timestamp: 0x4ce7c78c
4616c.e9c: Image Version: 6.1
4716c.e9c: SizeOfImage: 0x6b000 (438272)
4816c.e9c: Resource Dir: 0x69000 LB 0x530
4916c.e9c: ProductName: Microsoft® Windows® Operating System
5016c.e9c: ProductVersion: 6.1.7601.17514
5116c.e9c: FileVersion: 6.1.7601.17514 (win7sp1_rtm.101119-1850)
5216c.e9c: FileDescription: Windows NT BASE API Client DLL
5316c.e9c: \SystemRoot\System32\apisetschema.dll:
5416c.e9c: CreationTime: 2009-07-13T23:18:54.866423200Z
5516c.e9c: LastWriteTime: 2009-07-14T01:24:53.779000000Z
5616c.e9c: ChangeTime: 2016-09-30T16:26:47.134441200Z
5716c.e9c: FileAttributes: 0x20
5816c.e9c: Size: 0x1a00
5916c.e9c: NT Headers: 0xc0
6016c.e9c: Timestamp: 0x4a5bdeab
6116c.e9c: Machine: 0x8664 - amd64
6216c.e9c: Timestamp: 0x4a5bdeab
6316c.e9c: Image Version: 6.1
6416c.e9c: SizeOfImage: 0x50000 (327680)
6516c.e9c: Resource Dir: 0x30000 LB 0x3f0
6616c.e9c: ProductName: Microsoft® Windows® Operating System
6716c.e9c: ProductVersion: 6.1.7600.16385
6816c.e9c: FileVersion: 6.1.7600.16385 (win7_rtm.090713-1255)
6916c.e9c: FileDescription: ApiSet Schema DLL
7016c.e9c: NtOpenDirectoryObject failed on \Driver: 0xc0000022
7116c.e9c: supR3HardenedWinFindAdversaries: 0x0
7216c.e9c: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
7316c.e9c: Calling main()
7416c.e9c: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
7516c.e9c: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
7616c.e9c: SUPR3HardenedMain: Respawn #1
7716c.e9c: System32: \Device\HarddiskVolume2\Windows\System32
7816c.e9c: WinSxS: \Device\HarddiskVolume2\Windows\winsxs
7916c.e9c: KnownDllPath: C:\Windows\system32
8016c.e9c: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
8116c.e9c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe)
8216c.e9c: supR3HardNtEnableThreadCreation:
8316c.e9c: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00000000779cc320 pvNtTerminateThread=00000000779f1840
8416c.e9c: supR3HardenedWinDoReSpawn(1): New child 500.194 [kernel32].
8516c.e9c: supR3HardNtChildGatherData: PebBaseAddress=000007fffffd6000 cbPeb=0x380
8616c.e9c: supR3HardNtPuChFindNtdll: uNtDllParentAddr=00000000779a0000 uNtDllChildAddr=00000000779a0000
8716c.e9c: supR3HardenedWinSetupChildInit: uLdrInitThunk=00000000779cc320
8816c.e9c: supR3HardenedWinSetupChildInit: Start child.
8916c.e9c: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
9016c.e9c: supR3HardNtChildPurify: Startup delay kludge #1/0: 265 ms, 17 sleeps
9116c.e9c: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
9216c.e9c: *0000000000000000-fffffffffffeffff 0x0001/0x0000 0x0000000
9316c.e9c: *0000000000010000-fffffffffffeffff 0x0004/0x0004 0x0020000
9416c.e9c: *0000000000030000-000000000002bfff 0x0002/0x0002 0x0040000
9516c.e9c: 0000000000034000-0000000000027fff 0x0001/0x0000 0x0000000
9616c.e9c: *0000000000040000-000000000003efff 0x0004/0x0004 0x0020000
9716c.e9c: 0000000000041000-fffffffffffd1fff 0x0001/0x0000 0x0000000
9816c.e9c: *00000000000b0000-fffffffffffb3fff 0x0000/0x0004 0x0020000
9916c.e9c: 00000000001ac000-00000000001a9fff 0x0104/0x0004 0x0020000
10016c.e9c: 00000000001ae000-00000000001abfff 0x0004/0x0004 0x0020000
10116c.e9c: 00000000001b0000-ffffffff889bffff 0x0001/0x0000 0x0000000
10216c.e9c: *00000000779a0000-00000000779a0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
10316c.e9c: 00000000779a1000-0000000077aa2fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
10416c.e9c: 0000000077aa3000-0000000077ad1fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
10516c.e9c: 0000000077ad2000-0000000077addfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
10616c.e9c: 0000000077ade000-0000000077b48fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
10716c.e9c: 0000000077b49000-00000000706b1fff 0x0001/0x0000 0x0000000
10816c.e9c: *000000007efe0000-000000007dfdffff 0x0000/0x0002 0x0020000
10916c.e9c: *000000007ffe0000-000000007ffdefff 0x0002/0x0002 0x0020000
11016c.e9c: 000000007ffe1000-000000007ffd1fff 0x0000/0x0002 0x0020000
11116c.e9c: 000000007fff0000-ffffffffc069ffff 0x0001/0x0000 0x0000000
11216c.e9c: *000000013f940000-000000013f940fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
11316c.e9c: 000000013f941000-000000013f9affff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
11416c.e9c: 000000013f9b0000-000000013f9b0fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
11516c.e9c: 000000013f9b1000-000000013f9f5fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
11616c.e9c: 000000013f9f6000-000000013f9f6fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
11716c.e9c: 000000013f9f7000-000000013f9f7fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
11816c.e9c: 000000013f9f8000-000000013f9fcfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
11916c.e9c: 000000013f9fd000-000000013f9fdfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
12016c.e9c: 000000013f9fe000-000000013f9fefff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
12116c.e9c: 000000013f9ff000-000000013fa02fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
12216c.e9c: 000000013fa03000-000000013fa4afff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
12316c.e9c: 000000013fa4b000-fffff8037f7d5fff 0x0001/0x0000 0x0000000
12416c.e9c: *000007feffcc0000-000007feffcc0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\apisetschema.dll
12516c.e9c: 000007feffcc1000-000007fdff9d1fff 0x0001/0x0000 0x0000000
12616c.e9c: *000007fffffb0000-000007fffff8cfff 0x0002/0x0002 0x0040000
12716c.e9c: 000007fffffd3000-000007fffffcffff 0x0001/0x0000 0x0000000
12816c.e9c: *000007fffffd6000-000007fffffd4fff 0x0004/0x0004 0x0020000
12916c.e9c: 000007fffffd7000-000007fffffcffff 0x0001/0x0000 0x0000000
13016c.e9c: *000007fffffde000-000007fffffdbfff 0x0004/0x0004 0x0020000
13116c.e9c: *000007fffffe0000-000007fffffcffff 0x0001/0x0002 0x0020000
13216c.e9c: apisetschema.dll: timestamp 0x4a5bdeab (rc=VINF_SUCCESS)
13316c.e9c: VirtualBox.exe: timestamp 0x58332496 (rc=VINF_SUCCESS)
13416c.e9c: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
13516c.e9c: '\Device\HarddiskVolume2\Windows\System32\apisetschema.dll' has no imports
13616c.e9c: '\Device\HarddiskVolume2\Windows\System32\ntdll.dll' has no imports
13716c.e9c: supR3HardNtChildPurify: Done after 281 ms and 0 fixes (loop #0).
13816c.e9c: supR3HardNtEnableThreadCreation:
139500.194: Log file opened: 5.1.10r112026 g_hStartupLog=0000000000000004 g_uNtVerCombined=0x611db100
140500.194: supR3HardenedVmProcessInit: uNtDllAddr=00000000779a0000 g_uNtVerCombined=0x611db100
141500.194: ntdll.dll: timestamp 0x4ce7c8f9 (rc=VINF_SUCCESS)
142500.194: New simple heap: #1 00000000002b0000 LB 0x400000 (for 1740800 allocation)
143500.194: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
144500.194: System32: \Device\HarddiskVolume2\Windows\System32
145500.194: WinSxS: \Device\HarddiskVolume2\Windows\winsxs
146500.194: KnownDllPath: C:\Windows\system32
147500.194: supR3HardenedVmProcessInit: Opening vboxdrv stub...
148500.194: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
149500.194: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
150500.194: Registered Dll notification callback with NTDLL.
151500.194: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\kernel32.dll)
152500.194: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\kernel32.dll
153500.194: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
154500.194: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
155500.194: supR3HardenedDllNotificationCallback: load 0000000077880000 LB 0x0011f000 C:\Windows\system32\kernel32.dll [fFlags=0x0]
156500.194: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
157500.194: supR3HardenedDllNotificationCallback: load 000007fefd9e0000 LB 0x0006b000 C:\Windows\system32\KERNELBASE.dll [fFlags=0x0]
158500.194: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\KernelBase.dll)
159500.194: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\KernelBase.dll
160500.194: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077880000 'C:\Windows\system32\kernel32.dll'
161500.194: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00000000779cc320 pvNtTerminateThread=00000000779f1840
16216c.e9c: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 31 ms.
163500.194: \SystemRoot\System32\ntdll.dll:
164500.194: CreationTime: 2010-11-21T03:23:51.351694200Z
165500.194: LastWriteTime: 2010-11-21T03:23:51.367294200Z
166500.194: ChangeTime: 2016-09-30T16:27:23.544905100Z
167500.194: FileAttributes: 0x20
168500.194: Size: 0x1a6d60
169500.194: NT Headers: 0xe0
170500.194: Timestamp: 0x4ce7c8f9
171500.194: Machine: 0x8664 - amd64
172500.194: Timestamp: 0x4ce7c8f9
173500.194: Image Version: 6.1
174500.194: SizeOfImage: 0x1a9000 (1740800)
175500.194: Resource Dir: 0x151000 LB 0x560d8
176500.194: ProductName: Microsoft® Windows® Operating System
177500.194: ProductVersion: 6.1.7601.17514
178500.194: FileVersion: 6.1.7601.17514 (win7sp1_rtm.101119-1850)
179500.194: FileDescription: NT Layer DLL
180500.194: \SystemRoot\System32\kernel32.dll:
181500.194: CreationTime: 2010-11-21T03:24:07.965723400Z
182500.194: LastWriteTime: 2010-11-21T03:24:07.981323400Z
183500.194: ChangeTime: 2016-09-30T16:27:03.155669300Z
184500.194: FileAttributes: 0x20
185500.194: Size: 0x11b800
186500.194: NT Headers: 0xe8
187500.194: Timestamp: 0x4ce7c78b
188500.194: Machine: 0x8664 - amd64
189500.194: Timestamp: 0x4ce7c78b
190500.194: Image Version: 6.1
191500.194: SizeOfImage: 0x11f000 (1175552)
192500.194: Resource Dir: 0x116000 LB 0x528
193500.194: ProductName: Microsoft® Windows® Operating System
194500.194: ProductVersion: 6.1.7601.17514
195500.194: FileVersion: 6.1.7601.17514 (win7sp1_rtm.101119-1850)
196500.194: FileDescription: Windows NT BASE API Client DLL
197500.194: \SystemRoot\System32\KernelBase.dll:
198500.194: CreationTime: 2010-11-21T03:24:26.217755400Z
199500.194: LastWriteTime: 2010-11-21T03:24:26.248955500Z
200500.194: ChangeTime: 2016-09-30T16:27:03.077669200Z
201500.194: FileAttributes: 0x20
202500.194: Size: 0x66800
203500.194: NT Headers: 0xf0
204500.194: Timestamp: 0x4ce7c78c
205500.194: Machine: 0x8664 - amd64
206500.194: Timestamp: 0x4ce7c78c
207500.194: Image Version: 6.1
208500.194: SizeOfImage: 0x6b000 (438272)
209500.194: Resource Dir: 0x69000 LB 0x530
210500.194: ProductName: Microsoft® Windows® Operating System
211500.194: ProductVersion: 6.1.7601.17514
212500.194: FileVersion: 6.1.7601.17514 (win7sp1_rtm.101119-1850)
213500.194: FileDescription: Windows NT BASE API Client DLL
214500.194: \SystemRoot\System32\apisetschema.dll:
215500.194: CreationTime: 2009-07-13T23:18:54.866423200Z
216500.194: LastWriteTime: 2009-07-14T01:24:53.779000000Z
217500.194: ChangeTime: 2016-09-30T16:26:47.134441200Z
218500.194: FileAttributes: 0x20
219500.194: Size: 0x1a00
220500.194: NT Headers: 0xc0
221500.194: Timestamp: 0x4a5bdeab
222500.194: Machine: 0x8664 - amd64
223500.194: Timestamp: 0x4a5bdeab
224500.194: Image Version: 6.1
225500.194: SizeOfImage: 0x50000 (327680)
226500.194: Resource Dir: 0x30000 LB 0x3f0
227500.194: ProductName: Microsoft® Windows® Operating System
228500.194: ProductVersion: 6.1.7600.16385
229500.194: FileVersion: 6.1.7600.16385 (win7_rtm.090713-1255)
230500.194: FileDescription: ApiSet Schema DLL
231500.194: NtOpenDirectoryObject failed on \Driver: 0xc0000022
232500.194: supR3HardenedWinFindAdversaries: 0x0
233500.194: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
234500.194: Calling main()
235500.194: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
236500.194: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
237500.194: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
238500.194: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe)
239500.194: SUPR3HardenedMain: Respawn #2
240500.194: supR3HardNtEnableThreadCreation:
241500.194: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\apphelp.dll)
242500.194: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\apphelp.dll
243500.194: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\apphelp.dll (rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
244500.194: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\apphelp.dll [lacks WinVerifyTrust]
245500.194: supR3HardenedDllNotificationCallback: load 000007fefd7c0000 LB 0x00057000 C:\Windows\system32\apphelp.dll [fFlags=0x0]
246500.194: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\apphelp.dll [lacks WinVerifyTrust]
247500.194: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd7c0000 'C:\Windows\system32\apphelp.dll'
248500.194: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00000000779cc320 pvNtTerminateThread=00000000779f1840
249500.194: supR3HardenedWinDoReSpawn(2): New child cd8.c20 [kernel32].
250500.194: supR3HardNtChildGatherData: PebBaseAddress=000007fffffd5000 cbPeb=0x380
251500.194: supR3HardNtPuChFindNtdll: uNtDllParentAddr=00000000779a0000 uNtDllChildAddr=00000000779a0000
252500.194: supR3HardenedWinSetupChildInit: uLdrInitThunk=00000000779cc320
253500.194: supR3HardenedWinSetupChildInit: Start child.
254500.194: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
255500.194: supR3HardNtChildPurify: Startup delay kludge #1/0: 265 ms, 17 sleeps
256500.194: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
257500.194: *0000000000000000-fffffffffffeffff 0x0001/0x0000 0x0000000
258500.194: *0000000000010000-fffffffffffeffff 0x0004/0x0004 0x0020000
259500.194: *0000000000030000-000000000002bfff 0x0002/0x0002 0x0040000
260500.194: 0000000000034000-0000000000027fff 0x0001/0x0000 0x0000000
261500.194: *0000000000040000-000000000003efff 0x0004/0x0004 0x0020000
262500.194: 0000000000041000-ffffffffffea1fff 0x0001/0x0000 0x0000000
263500.194: *00000000001e0000-00000000000e3fff 0x0000/0x0004 0x0020000
264500.194: 00000000002dc000-00000000002d9fff 0x0104/0x0004 0x0020000
265500.194: 00000000002de000-00000000002dbfff 0x0004/0x0004 0x0020000
266500.194: 00000000002e0000-ffffffff88c1ffff 0x0001/0x0000 0x0000000
267500.194: *00000000779a0000-00000000779a0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
268500.194: 00000000779a1000-0000000077aa2fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
269500.194: 0000000077aa3000-0000000077ad1fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
270500.194: 0000000077ad2000-0000000077addfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
271500.194: 0000000077ade000-0000000077b48fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
272500.194: 0000000077b49000-00000000706b1fff 0x0001/0x0000 0x0000000
273500.194: *000000007efe0000-000000007dfdffff 0x0000/0x0002 0x0020000
274500.194: *000000007ffe0000-000000007ffdefff 0x0002/0x0002 0x0020000
275500.194: 000000007ffe1000-000000007ffd1fff 0x0000/0x0002 0x0020000
276500.194: 000000007fff0000-ffffffffc069ffff 0x0001/0x0000 0x0000000
277500.194: *000000013f940000-000000013f940fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
278500.194: 000000013f941000-000000013f9affff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
279500.194: 000000013f9b0000-000000013f9b0fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
280500.194: 000000013f9b1000-000000013f9f5fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
281500.194: 000000013f9f6000-000000013f9f6fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
282500.194: 000000013f9f7000-000000013f9f7fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
283500.194: 000000013f9f8000-000000013f9fcfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
284500.194: 000000013f9fd000-000000013f9fdfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
285500.194: 000000013f9fe000-000000013f9fefff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
286500.194: 000000013f9ff000-000000013fa02fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
287500.194: 000000013fa03000-000000013fa4afff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
288500.194: 000000013fa4b000-fffff8037f7d5fff 0x0001/0x0000 0x0000000
289500.194: *000007feffcc0000-000007feffcc0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\apisetschema.dll
290500.194: 000007feffcc1000-000007fdff9d1fff 0x0001/0x0000 0x0000000
291500.194: *000007fffffb0000-000007fffff8cfff 0x0002/0x0002 0x0040000
292500.194: 000007fffffd3000-000007fffffd0fff 0x0001/0x0000 0x0000000
293500.194: *000007fffffd5000-000007fffffd3fff 0x0004/0x0004 0x0020000
294500.194: 000007fffffd6000-000007fffffcdfff 0x0001/0x0000 0x0000000
295500.194: *000007fffffde000-000007fffffdbfff 0x0004/0x0004 0x0020000
296500.194: *000007fffffe0000-000007fffffcffff 0x0001/0x0002 0x0020000
297500.194: apisetschema.dll: timestamp 0x4a5bdeab (rc=VINF_SUCCESS)
298500.194: VirtualBox.exe: timestamp 0x58332496 (rc=VINF_SUCCESS)
299500.194: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
300500.194: '\Device\HarddiskVolume2\Windows\System32\apisetschema.dll' has no imports
301500.194: '\Device\HarddiskVolume2\Windows\System32\ntdll.dll' has no imports
302500.194: supR3HardNtChildPurify: Done after 281 ms and 0 fixes (loop #0).
303500.194: supR3HardenedEarlyCompact: Removed heap 1 (0x000000002b0000 LB 0x400000)
304500.194: supR3HardNtEnableThreadCreation:
305cd8.c20: Log file opened: 5.1.10r112026 g_hStartupLog=0000000000000004 g_uNtVerCombined=0x611db100
306cd8.c20: supR3HardenedVmProcessInit: uNtDllAddr=00000000779a0000 g_uNtVerCombined=0x611db100
307cd8.c20: ntdll.dll: timestamp 0x4ce7c8f9 (rc=VINF_SUCCESS)
308cd8.c20: New simple heap: #1 00000000002e0000 LB 0x400000 (for 1740800 allocation)
309cd8.c20: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
310cd8.c20: System32: \Device\HarddiskVolume2\Windows\System32
311cd8.c20: WinSxS: \Device\HarddiskVolume2\Windows\winsxs
312cd8.c20: KnownDllPath: C:\Windows\system32
313cd8.c20: supR3HardenedVmProcessInit: Opening vboxdrv...
314cd8.c20: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
315cd8.c20: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
316cd8.c20: Registered Dll notification callback with NTDLL.
317cd8.c20: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\kernel32.dll)
318cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\kernel32.dll
319cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
320cd8.c20: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
321cd8.c20: supR3HardenedDllNotificationCallback: load 0000000077880000 LB 0x0011f000 C:\Windows\system32\kernel32.dll [fFlags=0x0]
322cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
323cd8.c20: supR3HardenedDllNotificationCallback: load 000007fefd9e0000 LB 0x0006b000 C:\Windows\system32\KERNELBASE.dll [fFlags=0x0]
324cd8.c20: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\KernelBase.dll)
325cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\KernelBase.dll
326cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077880000 'C:\Windows\system32\kernel32.dll'
327cd8.c20: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00000000779cc320 pvNtTerminateThread=00000000779f1840
328500.194: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 31 ms.
329cd8.c20: \SystemRoot\System32\ntdll.dll:
330cd8.c20: CreationTime: 2010-11-21T03:23:51.351694200Z
331cd8.c20: LastWriteTime: 2010-11-21T03:23:51.367294200Z
332cd8.c20: ChangeTime: 2016-09-30T16:27:23.544905100Z
333cd8.c20: FileAttributes: 0x20
334cd8.c20: Size: 0x1a6d60
335cd8.c20: NT Headers: 0xe0
336cd8.c20: Timestamp: 0x4ce7c8f9
337cd8.c20: Machine: 0x8664 - amd64
338cd8.c20: Timestamp: 0x4ce7c8f9
339cd8.c20: Image Version: 6.1
340cd8.c20: SizeOfImage: 0x1a9000 (1740800)
341cd8.c20: Resource Dir: 0x151000 LB 0x560d8
342cd8.c20: ProductName: Microsoft® Windows® Operating System
343cd8.c20: ProductVersion: 6.1.7601.17514
344cd8.c20: FileVersion: 6.1.7601.17514 (win7sp1_rtm.101119-1850)
345cd8.c20: FileDescription: NT Layer DLL
346cd8.c20: \SystemRoot\System32\kernel32.dll:
347cd8.c20: CreationTime: 2010-11-21T03:24:07.965723400Z
348cd8.c20: LastWriteTime: 2010-11-21T03:24:07.981323400Z
349cd8.c20: ChangeTime: 2016-09-30T16:27:03.155669300Z
350cd8.c20: FileAttributes: 0x20
351cd8.c20: Size: 0x11b800
352cd8.c20: NT Headers: 0xe8
353cd8.c20: Timestamp: 0x4ce7c78b
354cd8.c20: Machine: 0x8664 - amd64
355cd8.c20: Timestamp: 0x4ce7c78b
356cd8.c20: Image Version: 6.1
357cd8.c20: SizeOfImage: 0x11f000 (1175552)
358cd8.c20: Resource Dir: 0x116000 LB 0x528
359cd8.c20: ProductName: Microsoft® Windows® Operating System
360cd8.c20: ProductVersion: 6.1.7601.17514
361cd8.c20: FileVersion: 6.1.7601.17514 (win7sp1_rtm.101119-1850)
362cd8.c20: FileDescription: Windows NT BASE API Client DLL
363cd8.c20: \SystemRoot\System32\KernelBase.dll:
364cd8.c20: CreationTime: 2010-11-21T03:24:26.217755400Z
365cd8.c20: LastWriteTime: 2010-11-21T03:24:26.248955500Z
366cd8.c20: ChangeTime: 2016-09-30T16:27:03.077669200Z
367cd8.c20: FileAttributes: 0x20
368cd8.c20: Size: 0x66800
369cd8.c20: NT Headers: 0xf0
370cd8.c20: Timestamp: 0x4ce7c78c
371cd8.c20: Machine: 0x8664 - amd64
372cd8.c20: Timestamp: 0x4ce7c78c
373cd8.c20: Image Version: 6.1
374cd8.c20: SizeOfImage: 0x6b000 (438272)
375cd8.c20: Resource Dir: 0x69000 LB 0x530
376cd8.c20: ProductName: Microsoft® Windows® Operating System
377cd8.c20: ProductVersion: 6.1.7601.17514
378cd8.c20: FileVersion: 6.1.7601.17514 (win7sp1_rtm.101119-1850)
379cd8.c20: FileDescription: Windows NT BASE API Client DLL
380cd8.c20: \SystemRoot\System32\apisetschema.dll:
381cd8.c20: CreationTime: 2009-07-13T23:18:54.866423200Z
382cd8.c20: LastWriteTime: 2009-07-14T01:24:53.779000000Z
383cd8.c20: ChangeTime: 2016-09-30T16:26:47.134441200Z
384cd8.c20: FileAttributes: 0x20
385cd8.c20: Size: 0x1a00
386cd8.c20: NT Headers: 0xc0
387cd8.c20: Timestamp: 0x4a5bdeab
388cd8.c20: Machine: 0x8664 - amd64
389cd8.c20: Timestamp: 0x4a5bdeab
390cd8.c20: Image Version: 6.1
391cd8.c20: SizeOfImage: 0x50000 (327680)
392cd8.c20: Resource Dir: 0x30000 LB 0x3f0
393cd8.c20: ProductName: Microsoft® Windows® Operating System
394cd8.c20: ProductVersion: 6.1.7600.16385
395cd8.c20: FileVersion: 6.1.7600.16385 (win7_rtm.090713-1255)
396cd8.c20: FileDescription: ApiSet Schema DLL
397cd8.c20: NtOpenDirectoryObject failed on \Driver: 0xc0000022
398cd8.c20: supR3HardenedWinFindAdversaries: 0x0
399cd8.c20: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
400cd8.c20: Calling main()
401cd8.c20: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
402cd8.c20: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
403cd8.c20: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
404cd8.c20: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe)
405cd8.c20: SUPR3HardenedMain: Final process, opening VBoxDrv...
406cd8.c20: supR3HardenedEarlyCompact: Removed heap 1 (0x000000002e0000 LB 0x400000)
407cd8.c20: supR3HardNtEnableThreadCreation:
408cd8.c20: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll)
409cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll
410cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
411cd8.c20: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
412cd8.c20: supR3HardenedDllNotificationCallback: load 000007fefc830000 LB 0x00005000 C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL [fFlags=0x0]
413cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
414cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
415cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
416cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc830000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
417cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
418cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
419cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc830000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
420cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc830000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
421cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
422cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'crypt32.dll'.
423cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msasn1.dll'.
424cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
425cd8.c20: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\wintrust.dll)
426cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wintrust.dll
427cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
428cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
429cd8.c20: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll)
430cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
431cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
432cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume2\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
433cd8.c20: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\msasn1.dll)
434cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msasn1.dll
435cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
436cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume2\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
437cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
438cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msasn1.dll'.
439cd8.c20: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\crypt32.dll)
440cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\crypt32.dll
441cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
442cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
443cd8.c20: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\msvcrt.dll)
444cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
445cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
446cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume2\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
447cd8.c20: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
448cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
449cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
450cd8.c20: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
451cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
452cd8.c20: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
453cd8.c20: supR3HardenedDllNotificationCallback: load 000007fefd9a0000 LB 0x0003a000 C:\Windows\system32\Wintrust.dll [fFlags=0x0]
454cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
455cd8.c20: supR3HardenedDllNotificationCallback: load 000007fefdf00000 LB 0x0009f000 C:\Windows\system32\msvcrt.dll [fFlags=0x0]
456cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
457cd8.c20: supR3HardenedDllNotificationCallback: load 000007fefda50000 LB 0x00167000 C:\Windows\system32\CRYPT32.dll [fFlags=0x0]
458cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
459cd8.c20: supR3HardenedDllNotificationCallback: load 000007fefd990000 LB 0x0000f000 C:\Windows\system32\MSASN1.dll [fFlags=0x0]
460cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
461cd8.c20: supR3HardenedDllNotificationCallback: load 000007feff000000 LB 0x0012d000 C:\Windows\system32\RPCRT4.dll [fFlags=0x0]
462cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
463cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd9a0000 'C:\Windows\system32\Wintrust.dll'
464cd8.c20: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\bcrypt.dll)
465cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\bcrypt.dll
466cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcrypt.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
467cd8.c20: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
468cd8.c20: supR3HardenedDllNotificationCallback: load 000007fefd310000 LB 0x00022000 C:\Windows\system32\bcrypt.dll [fFlags=0x0]
469cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
470cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd310000 'C:\Windows\system32\bcrypt.dll'
471cd8.c20: bcrypt.dll loaded at 000007fefd310000, BCryptOpenAlgorithmProvider at 000007fefd312640, preloading providers:
472cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
473cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'bcrypt.dll'.
474cd8.c20: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll)
475cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll
476cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
477cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume2\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
478cd8.c20: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
479cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
480cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
481cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
482cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'rpcrt4.dll'.
483cd8.c20: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\advapi32.dll)
484cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\advapi32.dll
485cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
486cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
487cd8.c20: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
488cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
489cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
490cd8.c20: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
491cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcryptprimitives.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
492cd8.c20: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
493cd8.c20: supR3HardenedDllNotificationCallback: load 000007fefce00000 LB 0x0004c000 C:\Windows\system32\bcryptprimitives.dll [fFlags=0x0]
494cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
495cd8.c20: supR3HardenedDllNotificationCallback: load 000007feff9d0000 LB 0x000db000 C:\Windows\system32\ADVAPI32.dll [fFlags=0x0]
496cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
497cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msvcrt.dll'.
498cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'rpcrt4.dll'.
499cd8.c20: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\sechost.dll)
500cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\sechost.dll
501cd8.c20: supR3HardenedDllNotificationCallback: load 000007feff8a0000 LB 0x0001f000 C:\Windows\SYSTEM32\sechost.dll [fFlags=0x0]
502cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\sechost.dll [lacks WinVerifyTrust]
503cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefce00000 'C:\Windows\system32\bcryptprimitives.dll'
504cd8.c20: BCryptOpenAlgorithmProvider(,'MD2',0,0) -> 0x0 (hAlgo=000000000082a650)
505cd8.c20: BCryptOpenAlgorithmProvider(,'MD4',0,0) -> 0x0 (hAlgo=000000000082d510)
506cd8.c20: BCryptOpenAlgorithmProvider(,'MD5',0,0) -> 0x0 (hAlgo=000000000082d630)
507cd8.c20: BCryptOpenAlgorithmProvider(,'SHA1',0,0) -> 0x0 (hAlgo=000000000082d840)
508cd8.c20: BCryptOpenAlgorithmProvider(,'SHA256',0,0) -> 0x0 (hAlgo=000000000082d960)
509cd8.c20: BCryptOpenAlgorithmProvider(,'SHA512',0,0) -> 0x0 (hAlgo=000000000082da80)
510cd8.c20: BCryptOpenAlgorithmProvider(,'RSA',0,0) -> 0x0 (hAlgo=000000000082dcc0)
511cd8.c20: BCryptOpenAlgorithmProvider(,'DSA',0,0) -> 0x0 (hAlgo=000000000082dde0)
512cd8.c20: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\cryptsp.dll)
513cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cryptsp.dll
514cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
515cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
516cd8.c20: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
517cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
518cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
519cd8.c20: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
520cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTSP.dll (Input=CRYPTSP.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
521cd8.c20: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
522cd8.c20: supR3HardenedDllNotificationCallback: load 000007fefd1c0000 LB 0x00017000 C:\Windows\system32\CRYPTSP.dll [fFlags=0x0]
523cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
524cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd1c0000 'C:\Windows\system32\CRYPTSP.dll'
525cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
526cd8.c20: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\rsaenh.dll)
527cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\rsaenh.dll
528cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
529cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
530cd8.c20: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
531cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
532cd8.c20: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
533cd8.c20: supR3HardenedDllNotificationCallback: load 000007fefcec0000 LB 0x00047000 C:\Windows\system32\rsaenh.dll [fFlags=0x0]
534cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
535cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcec0000 'C:\Windows\system32\rsaenh.dll'
536cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
537cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ADVAPI32.dll (Input=ADVAPI32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
538cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff9d0000 'C:\Windows\system32\ADVAPI32.dll'
539cd8.c20: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\cryptbase.dll)
540cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cryptbase.dll
541cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTBASE.dll (Input=CRYPTBASE.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
542cd8.c20: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptbase.dll [lacks WinVerifyTrust]
543cd8.c20: supR3HardenedDllNotificationCallback: load 000007fefd820000 LB 0x0000f000 C:\Windows\system32\CRYPTBASE.dll [fFlags=0x0]
544cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptbase.dll [lacks WinVerifyTrust]
545cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd820000 'C:\Windows\system32\CRYPTBASE.dll'
546cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
547cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
548cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077880000 'C:\Windows\system32\kernel32.dll'
549cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
550cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\WINTRUST.DLL (Input=WINTRUST.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
551cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd9a0000 'C:\Windows\system32\WINTRUST.DLL'
552cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
553cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPT32.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
554cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefda50000 'C:\Windows\system32\CRYPT32.dll'
555cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
556cd8.c20: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\imagehlp.dll)
557cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\imagehlp.dll
558cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
559cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
560cd8.c20: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
561cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\imagehlp.dll (Input=imagehlp.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
562cd8.c20: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\imagehlp.dll [lacks WinVerifyTrust]
563cd8.c20: supR3HardenedDllNotificationCallback: load 000007feff9a0000 LB 0x00017000 C:\Windows\system32\imagehlp.dll [fFlags=0x0]
564cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\imagehlp.dll [lacks WinVerifyTrust]
565cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff9a0000 'C:\Windows\system32\imagehlp.dll'
566cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
567cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTSP.dll (Input=CRYPTSP.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
568cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd1c0000 'C:\Windows\system32\CRYPTSP.dll'
569cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
570cd8.c20: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\user32.dll)
571cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\user32.dll
572cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
573cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
574cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
575cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'lpk.dll'.
576cd8.c20: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\gdi32.dll)
577cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\gdi32.dll
578cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'lpk.dll'...
579cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'lpk.dll' -> '\Device\HarddiskVolume2\Windows\System32\lpk.dll' [rcNtRedir=0xc0150008]
580cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'gdi32.dll'.
581cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'user32.dll'.
582cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'usp10.dll'.
583cd8.c20: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\lpk.dll)
584cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\lpk.dll
585cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
586cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
587cd8.c20: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
588cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'usp10.dll'...
589cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'usp10.dll' -> '\Device\HarddiskVolume2\Windows\System32\usp10.dll' [rcNtRedir=0xc0150008]
590cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
591cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
592cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'gdi32.dll'.
593cd8.c20: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\usp10.dll)
594cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\usp10.dll
595cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
596cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
597cd8.c20: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
598cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
599cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
600cd8.c20: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
601cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
602cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
603cd8.c20: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
604cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
605cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
606cd8.c20: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
607cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
608cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
609cd8.c20: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
610cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\USER32.dll (Input=USER32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
611cd8.c20: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
612cd8.c20: supR3HardenedDllNotificationCallback: load 0000000077780000 LB 0x000fa000 C:\Windows\system32\USER32.dll [fFlags=0x0]
613cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
614cd8.c20: supR3HardenedDllNotificationCallback: load 000007feff130000 LB 0x00067000 C:\Windows\system32\GDI32.dll [fFlags=0x0]
615cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
616cd8.c20: supR3HardenedDllNotificationCallback: load 000007feff9c0000 LB 0x0000e000 C:\Windows\system32\LPK.dll [fFlags=0x0]
617cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\lpk.dll [lacks WinVerifyTrust]
618cd8.c20: supR3HardenedDllNotificationCallback: load 000007fefe100000 LB 0x000c9000 C:\Windows\system32\USP10.dll [fFlags=0x0]
619cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\usp10.dll [lacks WinVerifyTrust]
620cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
621cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\gdi32.dll (Input=gdi32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
622cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff130000 'C:\Windows\system32\gdi32.dll'
623cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'user32.dll'.
624cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
625cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msctf.dll'.
626cd8.c20: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\imm32.dll)
627cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\imm32.dll
628cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msctf.dll'...
629cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'msctf.dll' -> '\Device\HarddiskVolume2\Windows\System32\msctf.dll' [rcNtRedir=0xc0150008]
630cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
631cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
632cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'gdi32.dll'.
633cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'imm32.dll'.
634cd8.c20: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\msctf.dll)
635cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msctf.dll
636cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
637cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
638cd8.c20: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
639cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
640cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
641cd8.c20: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
642cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
643cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume2\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
644cd8.c20: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\imm32.dll [lacks WinVerifyTrust]
645cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
646cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
647cd8.c20: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
648cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
649cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
650cd8.c20: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
651cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
652cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
653cd8.c20: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
654cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\IMM32.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
655cd8.c20: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\imm32.dll [lacks WinVerifyTrust]
656cd8.c20: supR3HardenedDllNotificationCallback: load 000007feffc80000 LB 0x0002e000 C:\Windows\system32\IMM32.DLL [fFlags=0x0]
657cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\imm32.dll [lacks WinVerifyTrust]
658cd8.c20: supR3HardenedDllNotificationCallback: load 000007fefdff0000 LB 0x00109000 C:\Windows\system32\MSCTF.dll [fFlags=0x0]
659cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msctf.dll [lacks WinVerifyTrust]
660cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feffc80000 'C:\Windows\system32\IMM32.DLL'
661cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'psapi.dll'.
662cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
663cd8.c20: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files (x86)\Sophos\Sophos Anti-Virus\SOPHOS~2.DLL)
664cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files (x86)\Sophos\Sophos Anti-Virus\SOPHOS~2.DLL
665cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
666cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
667cd8.c20: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
668cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'psapi.dll'...
669cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'psapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\psapi.dll' [rcNtRedir=0xc0150008]
670cd8.c20: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\psapi.dll)
671cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\psapi.dll
672cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\PROGRA~2\Sophos\SOPHOS~1\SOPHOS~2.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
673cd8.c20: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files (x86)\Sophos\Sophos Anti-Virus\SOPHOS~2.DLL [lacks WinVerifyTrust]
674cd8.c20: supR3HardenedDllNotificationCallback: load 0000000075690000 LB 0x00039000 C:\PROGRA~2\Sophos\SOPHOS~1\SOPHOS~2.DLL [fFlags=0x0]
675cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files (x86)\Sophos\Sophos Anti-Virus\SOPHOS~2.DLL [lacks WinVerifyTrust]
676cd8.c20: supR3HardenedDllNotificationCallback: load 0000000077b70000 LB 0x00007000 C:\Windows\system32\PSAPI.DLL [fFlags=0x0]
677cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\psapi.dll [lacks WinVerifyTrust]
678cd8.c20: '\Device\HarddiskVolume2\Windows\System32\ntdll.dll' has no imports
679cd8.c20: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ntdll.dll)
680cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ntdll.dll
681cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ntdll.dll (Input=ntdll.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
682cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00000000779a0000 'C:\Windows\system32\ntdll.dll'
683cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000075690000 'C:\PROGRA~2\Sophos\SOPHOS~1\SOPHOS~2.DLL'
684cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077780000 'C:\Windows\system32\USER32.dll'
685cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'bcrypt.dll'.
686cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
687cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msasn1.dll'.
688cd8.c20: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\ncrypt.dll)
689cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ncrypt.dll
690cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
691cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume2\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
692cd8.c20: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
693cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
694cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
695cd8.c20: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
696cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
697cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume2\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
698cd8.c20: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
699cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ncrypt.dll (Input=ncrypt.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
700cd8.c20: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\ncrypt.dll [lacks WinVerifyTrust]
701cd8.c20: supR3HardenedDllNotificationCallback: load 000007fefd340000 LB 0x0004e000 C:\Windows\system32\ncrypt.dll [fFlags=0x0]
702cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\ncrypt.dll [lacks WinVerifyTrust]
703cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd340000 'C:\Windows\system32\ncrypt.dll'
704cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
705cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcrypt.dll (Input=bcrypt.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
706cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd310000 'C:\Windows\system32\bcrypt.dll'
707cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
708cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'rpcrt4.dll'.
709cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'profapi.dll'.
710cd8.c20: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\userenv.dll)
711cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\userenv.dll
712cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'profapi.dll'...
713cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'profapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\profapi.dll' [rcNtRedir=0xc0150008]
714cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
715cd8.c20: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\profapi.dll)
716cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\profapi.dll
717cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
718cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
719cd8.c20: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
720cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
721cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
722cd8.c20: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
723cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
724cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
725cd8.c20: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
726cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\USERENV.dll (Input=USERENV.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
727cd8.c20: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\userenv.dll [lacks WinVerifyTrust]
728cd8.c20: supR3HardenedDllNotificationCallback: load 000007fefcc20000 LB 0x0001e000 C:\Windows\system32\USERENV.dll [fFlags=0x0]
729cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\userenv.dll [lacks WinVerifyTrust]
730cd8.c20: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\profapi.dll [lacks WinVerifyTrust]
731cd8.c20: supR3HardenedDllNotificationCallback: load 000007fefd8f0000 LB 0x0000f000 C:\Windows\system32\profapi.dll [fFlags=0x0]
732cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\profapi.dll [lacks WinVerifyTrust]
733cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcc20000 'C:\Windows\system32\USERENV.dll'
734cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
735cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff8a0000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
736cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
737cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff8a0000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
738cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
739cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'rpcrt4.dll'.
740cd8.c20: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\gpapi.dll)
741cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\gpapi.dll
742cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
743cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
744cd8.c20: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
745cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
746cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
747cd8.c20: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
748cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\GPAPI.dll (Input=GPAPI.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
749cd8.c20: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gpapi.dll [lacks WinVerifyTrust]
750cd8.c20: supR3HardenedDllNotificationCallback: load 000007fefcc00000 LB 0x0001b000 C:\Windows\system32\GPAPI.dll [fFlags=0x0]
751cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gpapi.dll [lacks WinVerifyTrust]
752cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcc00000 'C:\Windows\system32\GPAPI.dll'
753cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-Management-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
754cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff8a0000 'API-MS-WIN-Service-Management-L1-1-0.dll'
755cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
756cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rpcrt4.dll (Input=rpcrt4.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
757cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff000000 'C:\Windows\system32\rpcrt4.dll'
758cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-Management-L2-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
759cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff8a0000 'API-MS-WIN-Service-Management-L2-1-0.dll'
760cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
761cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff8a0000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
762cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
763cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'crypt32.dll'.
764cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'wldap32.dll'.
765cd8.c20: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\cryptnet.dll)
766cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cryptnet.dll
767cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wldap32.dll'...
768cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'wldap32.dll' -> '\Device\HarddiskVolume2\Windows\System32\wldap32.dll' [rcNtRedir=0xc0150008]
769cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
770cd8.c20: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\Wldap32.dll)
771cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\Wldap32.dll
772cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
773cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume2\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
774cd8.c20: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
775cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
776cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
777cd8.c20: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
778cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
779cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
780cd8.c20: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
781cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (Input=cryptnet.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
782cd8.c20: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
783cd8.c20: supR3HardenedDllNotificationCallback: load 000007feeefd0000 LB 0x00026000 C:\Windows\system32\cryptnet.dll [fFlags=0x0]
784cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
785cd8.c20: supR3HardenedDllNotificationCallback: load 000007fefdea0000 LB 0x00052000 C:\Windows\system32\WLDAP32.dll [fFlags=0x0]
786cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\Wldap32.dll [lacks WinVerifyTrust]
787cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
788cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
789cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeefd0000 'C:\Windows\system32\cryptnet.dll'
790cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
791cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
792cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeefd0000 'C:\Windows\system32\cryptnet.dll'
793cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
794cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
795cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeefd0000 'C:\Windows\system32\cryptnet.dll'
796cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
797cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
798cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeefd0000 'C:\Windows\system32\cryptnet.dll'
799cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
800cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
801cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeefd0000 'C:\Windows\system32\cryptnet.dll'
802cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
803cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
804cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeefd0000 'C:\Windows\system32\cryptnet.dll'
805cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
806cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeefd0000 'C:\Windows\system32\cryptnet.dll'
807cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
808cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeefd0000 'C:\Windows\system32\cryptnet.dll'
809cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
810cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeefd0000 'C:\Windows\system32\cryptnet.dll'
811cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
812cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeefd0000 'C:\Windows\system32\cryptnet.dll'
813cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
814cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeefd0000 'C:\Windows\system32\cryptnet.dll'
815cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeefd0000 'C:\Windows\system32\cryptnet.dll'
816cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
817cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
818cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msvcrt.dll'.
819cd8.c20: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\shlwapi.dll)
820cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\shlwapi.dll
821cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
822cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
823cd8.c20: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
824cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
825cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
826cd8.c20: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
827cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
828cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
829cd8.c20: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
830cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\SHLWAPI.dll (Input=SHLWAPI.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
831cd8.c20: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll [lacks WinVerifyTrust]
832cd8.c20: supR3HardenedDllNotificationCallback: load 000007feff3a0000 LB 0x00071000 C:\Windows\system32\SHLWAPI.dll [fFlags=0x0]
833cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll [lacks WinVerifyTrust]
834cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff3a0000 'C:\Windows\system32\SHLWAPI.dll'
835cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
836cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff8a0000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
837cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\profapi.dll [lacks WinVerifyTrust]
838cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\profapi.dll (Input=profapi.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
839cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd8f0000 'C:\Windows\system32\profapi.dll'
840cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'cfgmgr32.dll'.
841cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcrt.dll'.
842cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'gdi32.dll'.
843cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
844cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'user32.dll'.
845cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'oleaut32.dll'.
846cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'devobj.dll'.
847cd8.c20: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\setupapi.dll)
848cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\setupapi.dll
849cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'devobj.dll'...
850cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'devobj.dll' -> '\Device\HarddiskVolume2\Windows\System32\devobj.dll' [rcNtRedir=0xc0150008]
851cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
852cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'cfgmgr32.dll'.
853cd8.c20: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\devobj.dll)
854cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\devobj.dll
855cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
856cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
857cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ole32.dll'.
858cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
859cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
860cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'user32.dll'.
861cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'gdi32.dll'.
862cd8.c20: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\oleaut32.dll)
863cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
864cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
865cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
866cd8.c20: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
867cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
868cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
869cd8.c20: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
870cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
871cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
872cd8.c20: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
873cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
874cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
875cd8.c20: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
876cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
877cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
878cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
879cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'rpcrt4.dll'.
880cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
881cd8.c20: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll)
882cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll
883cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
884cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
885cd8.c20: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
886cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
887cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
888cd8.c20: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
889cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
890cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
891cd8.c20: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
892cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
893cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
894cd8.c20: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
895cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
896cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
897cd8.c20: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
898cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
899cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
900cd8.c20: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
901cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
902cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
903cd8.c20: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
904cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
905cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
906cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
907cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
908cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'user32.dll'.
909cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'rpcrt4.dll'.
910cd8.c20: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\ole32.dll)
911cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ole32.dll
912cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
913cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
914cd8.c20: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll [lacks WinVerifyTrust]
915cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
916cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
917cd8.c20: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
918cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
919cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
920cd8.c20: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
921cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
922cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
923cd8.c20: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
924cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
925cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
926cd8.c20: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
927cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
928cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
929cd8.c20: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
930cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\setupapi.dll (Input=setupapi.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
931cd8.c20: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\setupapi.dll [lacks WinVerifyTrust]
932cd8.c20: supR3HardenedDllNotificationCallback: load 000007fefdcc0000 LB 0x001d7000 C:\Windows\system32\setupapi.dll [fFlags=0x0]
933cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\setupapi.dll [lacks WinVerifyTrust]
934cd8.c20: supR3HardenedDllNotificationCallback: load 000007fefdbc0000 LB 0x00036000 C:\Windows\system32\CFGMGR32.dll [fFlags=0x0]
935cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll [lacks WinVerifyTrust]
936cd8.c20: supR3HardenedDllNotificationCallback: load 000007feff8c0000 LB 0x000d7000 C:\Windows\system32\OLEAUT32.dll [fFlags=0x0]
937cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll [lacks WinVerifyTrust]
938cd8.c20: supR3HardenedDllNotificationCallback: load 000007feff680000 LB 0x00203000 C:\Windows\system32\ole32.dll [fFlags=0x0]
939cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\ole32.dll [lacks WinVerifyTrust]
940cd8.c20: supR3HardenedDllNotificationCallback: load 000007fefdca0000 LB 0x0001a000 C:\Windows\system32\DEVOBJ.dll [fFlags=0x0]
941cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\devobj.dll [lacks WinVerifyTrust]
942cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Core-LocalRegistry-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
943cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077880000 'API-MS-Win-Core-LocalRegistry-L1-1-0.dll'
944cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdcc0000 'C:\Windows\system32\setupapi.dll'
945cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
946cd8.c20: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\cabinet.dll)
947cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cabinet.dll
948cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
949cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
950cd8.c20: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
951cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\Cabinet.dll (Input=Cabinet.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
952cd8.c20: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cabinet.dll [lacks WinVerifyTrust]
953cd8.c20: supR3HardenedDllNotificationCallback: load 000007fefbf50000 LB 0x0001b000 C:\Windows\system32\Cabinet.dll [fFlags=0x0]
954cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cabinet.dll [lacks WinVerifyTrust]
955cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbf50000 'C:\Windows\system32\Cabinet.dll'
956cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
957cd8.c20: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\devrtl.dll)
958cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\devrtl.dll
959cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
960cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
961cd8.c20: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
962cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\DEVRTL.dll (Input=DEVRTL.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
963cd8.c20: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\devrtl.dll [lacks WinVerifyTrust]
964cd8.c20: supR3HardenedDllNotificationCallback: load 000007fefcc40000 LB 0x00012000 C:\Windows\system32\DEVRTL.dll [fFlags=0x0]
965cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\devrtl.dll [lacks WinVerifyTrust]
966cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcc40000 'C:\Windows\system32\DEVRTL.dll'
967cd8.c20: supR3HardenedDllNotificationCallback: Unload 000007fefdcc0000 LB 0x001d7000 C:\Windows\system32\setupapi.dll [flags=0x0]
968cd8.c20: supR3HardenedDllNotificationCallback: Unload 000007fefdca0000 LB 0x0001a000 C:\Windows\system32\DEVOBJ.dll [flags=0x0]
969cd8.c20: supR3HardenedDllNotificationCallback: Unload 000007feff8c0000 LB 0x000d7000 C:\Windows\system32\OLEAUT32.dll [flags=0x0]
970cd8.c20: supR3HardenedDllNotificationCallback: Unload 000007feff680000 LB 0x00203000 C:\Windows\system32\ole32.dll [flags=0x0]
971cd8.c20: supR3HardenedDllNotificationCallback: Unload 000007fefdbc0000 LB 0x00036000 C:\Windows\system32\CFGMGR32.dll [flags=0x0]
972cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
973cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeefd0000 'C:\Windows\system32\cryptnet.dll'
974cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000000 pwszName=\SystemRoot\System32\ntdll.dll
975cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: New context 0000000000825280
976cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
977cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=6463B603CF12442718467D754A1EDC45CE1D6E7E
978cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
979cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff8a0000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
980cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-Management-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
981cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff8a0000 'API-MS-WIN-Service-Management-L1-1-0.dll'
982cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-winsvc-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
983cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff8a0000 'API-MS-WIN-Service-winsvc-L1-1-0.dll'
984cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
985cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ADVAPI32.dll (Input=ADVAPI32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
986cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff9d0000 'C:\Windows\system32\ADVAPI32.dll'
987cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-LSALookup-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
988cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff8a0000 'API-MS-Win-Security-LSALookup-L1-1-0.dll'
989cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-LSALookup-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
990cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff8a0000 'API-MS-Win-Security-LSALookup-L1-1-0.dll'
991cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\SystemRoot\System32\ntdll.dll'
992cd8.c20: g_pfnWinVerifyTrust=000007fefd9a1010
993cd8.c20: supR3HardenedScreenImage/preload: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [redoing WinVerifyTrust]
994cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000e0 pwszName=\Device\HarddiskVolume2\Windows\System32\crypt32.dll
995cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
996cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
997cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=766DAE0DAEDFFD0DB96611658C619DD5922D2FEC
998cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\crypt32.dll'
999cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1000cd8.c20: supR3HardenedScreenImage/preload: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\crypt32.dll'
1001cd8.c20: supR3HardenedScreenImage/preload: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [redoing WinVerifyTrust]
1002cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000d4 pwszName=\Device\HarddiskVolume2\Windows\System32\wintrust.dll
1003cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
1004cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
1005cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=E8D9B442D9CC38B2D0501106E104A42A4EE0B238
1006cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\wintrust.dll'
1007cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1008cd8.c20: supR3HardenedScreenImage/preload: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\wintrust.dll'
1009cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000003f8 pwszName=\Device\HarddiskVolume2\Windows\System32\devrtl.dll
1010cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
1011cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
1012cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=445E5B0E9F43B5D56A5B9C4BC3369E3D076ACA1A
1013cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\devrtl.dll'
1014cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1015cd8.c20: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\devrtl.dll'
1016cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000003ec pwszName=\Device\HarddiskVolume2\Windows\System32\cabinet.dll
1017cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
1018cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
1019cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=5D1555851298EA005A2E9FEA027F5898BC240083
1020cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\cabinet.dll'
1021cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1022cd8.c20: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\cabinet.dll'
1023cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000003b4 pwszName=\Device\HarddiskVolume2\Windows\System32\ole32.dll
1024cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
1025cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
1026cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2E64AE329BD5124592BC8CB0B327AA3B95DC65B7
1027cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\ole32.dll'
1028cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1029cd8.c20: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\ole32.dll'
1030cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000003b0 pwszName=\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll
1031cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
1032cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
1033cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=8F731777EFC4BC982C1E1467FBF29A74CC14D93A
1034cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll'
1035cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1036cd8.c20: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll'
1037cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000003ac pwszName=\Device\HarddiskVolume2\Windows\System32\oleaut32.dll
1038cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
1039cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
1040cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=26A5C3FE898CBD66951D3BC65E742E0BE561E69B
1041cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\oleaut32.dll'
1042cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1043cd8.c20: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll'
1044cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000003a8 pwszName=\Device\HarddiskVolume2\Windows\System32\devobj.dll
1045cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
1046cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
1047cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B410A095222E69F0ECE7D66E4AC27A7125D2EB5A
1048cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\devobj.dll'
1049cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1050cd8.c20: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\devobj.dll'
1051cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000003a4 pwszName=\Device\HarddiskVolume2\Windows\System32\setupapi.dll
1052cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
1053cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
1054cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=1499C4FEA6E143F9BEC35B4FFA098917D3A6EBF2
1055cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\setupapi.dll'
1056cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1057cd8.c20: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\setupapi.dll'
1058cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000398 pwszName=\Device\HarddiskVolume2\Windows\System32\shlwapi.dll
1059cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
1060cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
1061cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=0AB8D9C9D3E1FC95D01F9A984B16ED031BB40CD8
1062cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\shlwapi.dll'
1063cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1064cd8.c20: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll'
1065cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000038c pwszName=\Device\HarddiskVolume2\Windows\System32\Wldap32.dll
1066cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
1067cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
1068cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=87E73086F2528CF31D3AD5F0D71E04F8B942D5D8
1069cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\Wldap32.dll'
1070cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1071cd8.c20: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\Wldap32.dll'
1072cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000388 pwszName=\Device\HarddiskVolume2\Windows\System32\cryptnet.dll
1073cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
1074cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
1075cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=CA2FE16E05087DA5C24DC5EB2EE8053CDA5DE9A9
1076cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\cryptnet.dll'
1077cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1078cd8.c20: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\cryptnet.dll'
1079cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000264 pwszName=\Device\HarddiskVolume2\Windows\System32\gpapi.dll
1080cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
1081cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
1082cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=470795C189226F7BDB8E50F42104CC34488B9340
1083cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\gpapi.dll'
1084cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1085cd8.c20: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\gpapi.dll'
1086cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000001d0 pwszName=\Device\HarddiskVolume2\Windows\System32\profapi.dll
1087cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
1088cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
1089cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2449672745D9BA339420451D13FA0380AA768231
1090cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\profapi.dll'
1091cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1092cd8.c20: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\profapi.dll'
1093cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000001cc pwszName=\Device\HarddiskVolume2\Windows\System32\userenv.dll
1094cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
1095cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
1096cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=D3E1A2CC7367F751C19EBF4E6EDF5E9A10E47313
1097cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\userenv.dll'
1098cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1099cd8.c20: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\userenv.dll'
1100cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000001ac pwszName=\Device\HarddiskVolume2\Windows\System32\ncrypt.dll
1101cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
1102cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
1103cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=3D482C50075646C922DC6A66C97956C5060C361B
1104cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\ncrypt.dll'
1105cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1106cd8.c20: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\ncrypt.dll'
1107cd8.c20: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\ntdll.dll'
1108cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000001b4 pwszName=\Device\HarddiskVolume2\Windows\System32\psapi.dll
1109cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
1110cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
1111cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=561BAAB249C395B66D294444DF251EDB701DB607
1112cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\psapi.dll'
1113cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1114cd8.c20: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\psapi.dll'
1115cd8.c20: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Program Files (x86)\Sophos\Sophos Anti-Virus\SOPHOS~2.DLL'
1116cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000194 pwszName=\Device\HarddiskVolume2\Windows\System32\msctf.dll
1117cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
1118cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
1119cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=803AF52F95A9EFDFDA06C595023831EE36ACD3A8
1120cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\msctf.dll'
1121cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1122cd8.c20: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\msctf.dll'
1123cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000190 pwszName=\Device\HarddiskVolume2\Windows\System32\imm32.dll
1124cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
1125cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
1126cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=6EEE1AB3B6D79AFF857940FF5F51ED27698153EC
1127cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\imm32.dll'
1128cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1129cd8.c20: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\imm32.dll'
1130cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000018c pwszName=\Device\HarddiskVolume2\Windows\System32\usp10.dll
1131cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
1132cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
1133cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=97AE9B5B40144F2794F30A891013393C80D631A1
1134cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\usp10.dll'
1135cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1136cd8.c20: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\usp10.dll'
1137cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000188 pwszName=\Device\HarddiskVolume2\Windows\System32\lpk.dll
1138cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
1139cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
1140cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=A42DFBB8A3A26D2178D79D34DA1CE275E2A0BE37
1141cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\lpk.dll'
1142cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1143cd8.c20: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\lpk.dll'
1144cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000184 pwszName=\Device\HarddiskVolume2\Windows\System32\gdi32.dll
1145cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
1146cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
1147cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=C8F7179D2AEB0FEB168A01D182223AC2D7B8F331
1148cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\gdi32.dll'
1149cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1150cd8.c20: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\gdi32.dll'
1151cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000180 pwszName=\Device\HarddiskVolume2\Windows\System32\user32.dll
1152cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
1153cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
1154cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B723D1B8AD72750B0CF5F6BEC66171B1254ED879
1155cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\user32.dll'
1156cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1157cd8.c20: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\user32.dll'
1158cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000017c pwszName=\Device\HarddiskVolume2\Windows\System32\imagehlp.dll
1159cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
1160cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
1161cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=AFE89CF1060867A10BD3963894BCDB4D3058F804
1162cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\imagehlp.dll'
1163cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1164cd8.c20: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\imagehlp.dll'
1165cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000130 pwszName=\Device\HarddiskVolume2\Windows\System32\cryptbase.dll
1166cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
1167cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
1168cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=A965CC5DB13A5FB23BBB1B6B5FA6D400DC49462F
1169cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\cryptbase.dll'
1170cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1171cd8.c20: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\cryptbase.dll'
1172cd8.c20: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\rsaenh.dll'
1173cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000012c pwszName=\Device\HarddiskVolume2\Windows\System32\cryptsp.dll
1174cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
1175cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
1176cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=40667EDBA9045D4A4BE1D4844665D3B88F8CD0E0
1177cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\cryptsp.dll'
1178cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1179cd8.c20: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\cryptsp.dll'
1180cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000120 pwszName=\Device\HarddiskVolume2\Windows\System32\sechost.dll
1181cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
1182cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
1183cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=3FA2A014BF360CDC0E203A174FFC9DC5343C5323
1184cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\sechost.dll'
1185cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1186cd8.c20: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\sechost.dll'
1187cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000011c pwszName=\Device\HarddiskVolume2\Windows\System32\advapi32.dll
1188cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
1189cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
1190cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=DBCDF817D89920EE3139FB7E090744EB36A4A21B
1191cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\advapi32.dll'
1192cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1193cd8.c20: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\advapi32.dll'
1194cd8.c20: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll'
1195cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000104 pwszName=\Device\HarddiskVolume2\Windows\System32\bcrypt.dll
1196cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
1197cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
1198cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=62E377A1F0AD0C2EDC0A73CB3EFF841FF18D00D2
1199cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\bcrypt.dll'
1200cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1201cd8.c20: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\bcrypt.dll'
1202cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000e4 pwszName=\Device\HarddiskVolume2\Windows\System32\msvcrt.dll
1203cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
1204cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
1205cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=DBEAC8C0FA88C88B540ACFE0683B1810C077AA53
1206cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\msvcrt.dll'
1207cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1208cd8.c20: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll'
1209cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000dc pwszName=\Device\HarddiskVolume2\Windows\System32\msasn1.dll
1210cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
1211cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
1212cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F2FF57DC30D774F93061607060DAA0DD15E39CCE
1213cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\msasn1.dll'
1214cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1215cd8.c20: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\msasn1.dll'
1216cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000d8 pwszName=\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
1217cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
1218cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
1219cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=BC4D9E909DFDD2EE8BA1A5C857D73D49EBE7952C
1220cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll'
1221cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1222cd8.c20: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll'
1223cd8.c20: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll'
1224cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000028 pwszName=\Device\HarddiskVolume2\Windows\System32\KernelBase.dll
1225cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
1226cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
1227cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=06FEC3C858DB28D2F4BFBDA99AF14D4747A8C5D4
1228cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\KernelBase.dll'
1229cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1230cd8.c20: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\KernelBase.dll'
1231cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000020 pwszName=\Device\HarddiskVolume2\Windows\System32\kernel32.dll
1232cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
1233cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
1234cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=D7AE634A00F24BBD4AE27DEA9BCCCE222DE9897B
1235cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\kernel32.dll'
1236cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1237cd8.c20: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\kernel32.dll'
1238cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll
1239cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\crypt32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
1240cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefda50000 'C:\Windows\system32\crypt32.dll'
1241cd8.c20: supR3HardenedWinIsDesiredRootCA: Adding 0x5ad46780fa5df300 DC=com, DC=microsoft, CN=Microsoft Root Certificate Authority
1242cd8.c20: supR3HardenedWinIsDesiredRootCA: Adding 0xea5386456178582b C=ZA, ST=Western Cape, L=Durbanville, O=Thawte, OU=Thawte Certification, CN=Thawte Timestamping CA
1243cd8.c20: supR3HardenedWinIsDesiredRootCA: Adding 0x3be670c1bd02a900 OU=Copyright (c) 1997 Microsoft Corp., OU=Microsoft Corporation, CN=Microsoft Root Authority
1244cd8.c20: supR3HardenedWinIsDesiredRootCA: Adding 0x4d3835aa4180b200 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2011
1245cd8.c20: supR3HardenedWinIsDesiredRootCA: Adding 0x646e3fe3ba08df00 C=US, O=MSFT, CN=Microsoft Authenticode(tm) Root Authority
1246cd8.c20: supR3HardenedWinIsDesiredRootCA: Adding 0xece4e4289e08b900 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010
1247cd8.c20: supR3HardenedWinIsDesiredRootCA: Adding 0x43a9cc371ff5385a O=Microsoft Trust Network, OU=Microsoft Corporation, OU=Microsoft Time Stamping Service Root, OU=Copyright (c) 1997 Microsoft Corp.
1248cd8.c20: supR3HardenedWinIsDesiredRootCA: Adding 0x2e2d2c7c68f0202e O=VeriSign Trust Network, OU=VeriSign, Inc., OU=VeriSign Time Stamping Service Root, OU=NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.
1249cd8.c20: supR3HardenedWinIsDesiredRootCA: Adding 0xf4fd306318ccda00 C=US, O=GeoTrust Inc., CN=GeoTrust Global CA
1250cd8.c20: supR3HardenedWinIsDesiredRootCA: Adding 0x83085097e9afdf00 O=Digital Signature Trust Co., CN=DST Root CA X3
1251cd8.c20: supR3HardenedWinIsDesiredRootCA: Adding 0x3d98ab22bb04a300 C=IE, O=Baltimore, OU=CyberTrust, CN=Baltimore CyberTrust Root
1252cd8.c20: supR3HardenedWinIsDesiredRootCA: Adding 0xa0ee62086758b15d C=US, O=Equifax, OU=Equifax Secure Certificate Authority
1253cd8.c20: supR3HardenedWinIsDesiredRootCA: Adding 0xd944bca189a00 C=BM, O=QuoVadis Limited, CN=QuoVadis Root CA 2
1254cd8.c20: supR3HardenedWinIsDesiredRootCA: Adding 0xa3ce8d99e60eda00 C=BE, O=GlobalSign nv-sa, OU=Root CA, CN=GlobalSign Root CA
1255cd8.c20: supR3HardenedWinIsDesiredRootCA: Adding 0xa8de7211e13be200 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root CA
1256cd8.c20: supR3HardenedWinIsDesiredRootCA: Adding 0x7ae89c50f0b6a00f C=US, O=GTE Corporation, OU=GTE CyberTrust Solutions, Inc., CN=GTE CyberTrust Global Root
1257cd8.c20: supR3HardenedWinIsDesiredRootCA: Adding 0xd45980fbf0a0ac00 C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2006 thawte, Inc. - For authorized use only, CN=thawte Primary Root CA
1258cd8.c20: supR3HardenedWinIsDesiredRootCA: Adding 0xf5cd95e581a4ab00 C=US, O=SecureTrust Corporation, CN=SecureTrust CA
1259cd8.c20: supR3HardenedWinIsDesiredRootCA: Adding 0x298be035a30bab00 C=DE, O=Deutsche Telekom AG, OU=T-TeleSec Trust Center, CN=Deutsche Telekom Root CA 2
1260cd8.c20: supR3HardenedWinIsDesiredRootCA: Adding 0x14018a1bf29e595c C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority
1261cd8.c20: supR3HardenedWinIsDesiredRootCA: Adding 0x9e5bc2d78b6a3636 C=ZA, ST=Western Cape, L=Cape Town, O=Thawte Consulting cc, OU=Certification Services Division, CN=Thawte Premium Server CA, Email=premium-server@thawte.com
1262cd8.c20: supR3HardenedWinIsDesiredRootCA: Adding 0xd4fbe673e5ccc600 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA
1263cd8.c20: supR3HardenedWinIsDesiredRootCA: Adding 0x357a29080824af00 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2006 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G5
1264cd8.c20: supR3HardenedWinIsDesiredRootCA: Adding 0x466cbc09db88c100 C=IL, O=StartCom Ltd., OU=Secure Digital Certificate Signing, CN=StartCom Certification Authority
1265cd8.c20: supR3HardenedWinIsDesiredRootCA: Adding 0x491857ead79dde00 C=US, O=The Go Daddy Group, Inc., OU=Go Daddy Class 2 Certification Authority
1266cd8.c20: supR3HardenedWinIsDesiredRootCA: Adding 0x8043e4ce150ead00 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID Root CA
1267cd8.c20: supR3HardenedWinIsDesiredRootCA: Adding 0xf2e6331af7b700 C=SE, O=AddTrust AB, OU=AddTrust External TTP Network, CN=AddTrust External CA Root
1268cd8.c20: supR3HardenedWinIsDesiredRootCA: Adding 0x4e0837025983be00 CN=IOW intern CA
1269cd8.c20: supR3HardenedWinIsDesiredRootCA: Adding 0x59f05dce42dfdb00 DC=de, DC=io-warnemuende, CN=IOWinternCA
1270cd8.c20: supR3HardenedWinIsDesiredRootCA: Adding 0xb9cace4366d5ba00 DC=de, DC=io-warnemuende, CN=IOW intern CA
1271cd8.c20: supR3HardenedWinIsDesiredRootCA: Adding 0xa5a4965db4f8d300 DC=de, DC=io-warnemuende, CN=IOW intern CA
1272cd8.c20: supR3HardenedWinIsDesiredRootCA: Adding 0xcab00050368ed700 DC=de, DC=io-warnemuende, CN=Institut fuer Ostseeforschung
1273cd8.c20: supR3HardenedWinIsDesiredRootCA: Adding 0xf08c181e2d75cb00 DC=de, DC=io-warnemuende, CN=IOW intern CA
1274cd8.c20: supR3HardenedWinIsDesiredRootCA: Adding 0xb326aa576d94e800 DC=de, DC=io-warnemuende, CN=IOW INTERN CA
1275cd8.c20: supR3HardenedWinRetrieveTrustedRootCAs: cAdded=34
1276cd8.c20: SUPR3HardenedMain: Load Runtime...
1277cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
1278cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
1279cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ws2_32.dll'.
1280cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'rpcrt4.dll'.
1281cd8.c20: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll) WinVerifyTrust
1282cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
1283cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
1284cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
1285cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
1286cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
1287cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000003dc pwszName=\Device\HarddiskVolume2\Windows\System32\ws2_32.dll
1288cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
1289cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
1290cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=3EF3BDC1E84DFA17EA056313214EE88EC3E66F79
1291cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\ws2_32.dll'
1292cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1293cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1294cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'rpcrt4.dll'.
1295cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'nsi.dll'.
1296cd8.c20: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ws2_32.dll) WinVerifyTrust
1297cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
1298cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
1299cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
1300cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
1301cd8.c20: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll) WinVerifyTrust
1302cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
1303cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
1304cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
1305cd8.c20: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll) WinVerifyTrust
1306cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
1307cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
1308cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
1309cd8.c20: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
1310cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
1311cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume2\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
1312cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000003d8 pwszName=\Device\HarddiskVolume2\Windows\System32\nsi.dll
1313cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
1314cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
1315cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=7AFD8538945F2D05BC1AF949B9B19B7D2D9FBBF8
1316cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\nsi.dll'
1317cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1318cd8.c20: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\nsi.dll) WinVerifyTrust
1319cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\nsi.dll
1320cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
1321cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
1322cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1323cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1324cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
1325cd8.c20: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
1326cd8.c20: supR3HardenedDllNotificationCallback: load 000007feede20000 LB 0x00527000 C:\Program Files\Oracle\VirtualBox\VBoxRT.dll [fFlags=0x0]
1327cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
1328cd8.c20: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
1329cd8.c20: supR3HardenedDllNotificationCallback: load 0000000070910000 LB 0x000d2000 C:\Program Files\Oracle\VirtualBox\MSVCR100.dll [fFlags=0x0]
1330cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
1331cd8.c20: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
1332cd8.c20: supR3HardenedDllNotificationCallback: load 0000000070870000 LB 0x00098000 C:\Program Files\Oracle\VirtualBox\MSVCP100.dll [fFlags=0x0]
1333cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
1334cd8.c20: supR3HardenedDllNotificationCallback: load 000007fefdfa0000 LB 0x0004d000 C:\Windows\system32\WS2_32.dll [fFlags=0x0]
1335cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
1336cd8.c20: supR3HardenedDllNotificationCallback: load 000007feff890000 LB 0x00008000 C:\Windows\system32\NSI.dll [fFlags=0x0]
1337cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\nsi.dll
1338cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
1339cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
1340cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feede20000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1341cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
1342cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
1343cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feede20000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1344cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
1345cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
1346cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feede20000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1347cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
1348cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
1349cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feede20000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1350cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
1351cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
1352cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feede20000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1353cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
1354cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
1355cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feede20000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1356cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feede20000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1357cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feede20000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1358cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feede20000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1359cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feede20000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1360cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feede20000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1361cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feede20000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1362cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feede20000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1363cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
1364cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
1365cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feede20000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1366cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feede20000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1367cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feede20000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1368cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feede20000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1369cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feede20000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1370cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feede20000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1371cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feede20000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1372cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feede20000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1373cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feede20000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1374cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feede20000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1375cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feede20000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1376cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feede20000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1377cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feede20000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1378cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feede20000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1379cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feede20000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1380cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feede20000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1381cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
1382cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
1383cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feede20000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1384cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feede20000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1385cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feede20000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1386cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feede20000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1387cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll
1388cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
1389cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd9a0000 'C:\Windows\system32\Wintrust.dll'
1390cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll
1391cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\crypt32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
1392cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefda50000 'C:\Windows\system32\crypt32.dll'
1393cd8.c20: SUPR3HardenedMain: Load TrustedMain...
1394cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'opengl32.dll'.
1395cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
1396cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcp100.dll'.
1397cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcr100.dll'.
1398cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qt5corevbox.dll'.
1399cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'qt5guivbox.dll'.
1400cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'qt5widgetsvbox.dll'.
1401cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'qt5printsupportvbox.dll'.
1402cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'qt5openglvbox.dll'.
1403cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'user32.dll'.
1404cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'advapi32.dll'.
1405cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'shell32.dll'.
1406cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'ole32.dll'.
1407cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'oleaut32.dll'.
1408cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #15 'winmm.dll'.
1409cd8.c20: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.dll) WinVerifyTrust
1410cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.dll
1411cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
1412cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
1413cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000448 pwszName=\Device\HarddiskVolume2\Windows\System32\winmm.dll
1414cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
1415cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
1416cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=82E2B2A7826F88BEB98FFF0540C9BDB0A12F001A
1417cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\winmm.dll'
1418cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1419cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
1420cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
1421cd8.c20: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\winmm.dll) WinVerifyTrust
1422cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\winmm.dll
1423cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
1424cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
1425cd8.c20: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
1426cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
1427cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
1428cd8.c20: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
1429cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
1430cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
1431cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000430 pwszName=\Device\HarddiskVolume2\Windows\System32\shell32.dll
1432cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
1433cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
1434cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=FCF00DB9BBECF4126AB4076577BBA73C0F94BDF9
1435cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\shell32.dll'
1436cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1437cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1438cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #21 'shlwapi.dll'.
1439cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'user32.dll'.
1440cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #24 'gdi32.dll'.
1441cd8.c20: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\shell32.dll) WinVerifyTrust
1442cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\shell32.dll
1443cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
1444cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
1445cd8.c20: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
1446cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1447cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1448cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5openglvbox.dll'...
1449cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5openglvbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5openglvbox.dll' [rcNtRedir=0xc0150008]
1450cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'qt5widgetsvbox.dll'.
1451cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'qt5guivbox.dll'.
1452cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5corevbox.dll'.
1453cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcr100.dll'.
1454cd8.c20: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll) WinVerifyTrust
1455cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll
1456cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5printsupportvbox.dll'...
1457cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5printsupportvbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5printsupportvbox.dll' [rcNtRedir=0xc0150008]
1458cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
1459cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
1460cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5widgetsvbox.dll'.
1461cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qt5guivbox.dll'.
1462cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qt5corevbox.dll'.
1463cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'winspool.drv'.
1464cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'comdlg32.dll'.
1465cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'msvcr100.dll'.
1466cd8.c20: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5PrintSupportVBox.dll) WinVerifyTrust
1467cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5PrintSupportVBox.dll
1468cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
1469cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
1470cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
1471cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
1472cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5guivbox.dll'.
1473cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qt5corevbox.dll'.
1474cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'shell32.dll'.
1475cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcp100.dll'.
1476cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcr100.dll'.
1477cd8.c20: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll) WinVerifyTrust
1478cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll
1479cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
1480cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
1481cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ole32.dll'.
1482cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'opengl32.dll'.
1483cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
1484cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
1485cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qt5corevbox.dll'.
1486cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcp100.dll'.
1487cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcr100.dll'.
1488cd8.c20: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll) WinVerifyTrust
1489cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
1490cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
1491cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
1492cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
1493cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'shell32.dll'.
1494cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ole32.dll'.
1495cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
1496cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ws2_32.dll'.
1497cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'mpr.dll'.
1498cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'msvcp100.dll'.
1499cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'msvcr100.dll'.
1500cd8.c20: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll) WinVerifyTrust
1501cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
1502cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
1503cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
1504cd8.c20: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
1505cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
1506cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
1507cd8.c20: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
1508cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
1509cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
1510cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
1511cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
1512cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000458 pwszName=\Device\HarddiskVolume2\Windows\System32\opengl32.dll
1513cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
1514cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
1515cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=608AC397FCC42B9FBAE25CB8C25EAF4C19AA384D
1516cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\opengl32.dll'
1517cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1518cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1519cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
1520cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'gdi32.dll'.
1521cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'glu32.dll'.
1522cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ddraw.dll'.
1523cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'user32.dll'.
1524cd8.c20: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\opengl32.dll) WinVerifyTrust
1525cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\opengl32.dll
1526cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1527cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1528cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ddraw.dll'...
1529cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'ddraw.dll' -> '\Device\HarddiskVolume2\Windows\System32\ddraw.dll' [rcNtRedir=0xc0150008]
1530cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000464 pwszName=\Device\HarddiskVolume2\Windows\System32\ddraw.dll
1531cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
1532cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
1533cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=24C763EA54CD792A0F1618411061DC356EE31FF6
1534cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\ddraw.dll'
1535cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1536cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1537cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
1538cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'dciman32.dll'.
1539cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
1540cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'setupapi.dll'.
1541cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'dwmapi.dll'.
1542cd8.c20: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ddraw.dll) WinVerifyTrust
1543cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ddraw.dll
1544cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'glu32.dll'...
1545cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'glu32.dll' -> '\Device\HarddiskVolume2\Windows\System32\glu32.dll' [rcNtRedir=0xc0150008]
1546cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000420 pwszName=\Device\HarddiskVolume2\Windows\System32\glu32.dll
1547cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
1548cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
1549cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=60E45AB914E06A11F44EA76C6EF750AF892F9EA2
1550cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\glu32.dll'
1551cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1552cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1553cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'opengl32.dll'.
1554cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
1555cd8.c20: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\glu32.dll) WinVerifyTrust
1556cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\glu32.dll
1557cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1558cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1559cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
1560cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
1561cd8.c20: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
1562cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1563cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1564cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
1565cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
1566cd8.c20: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
1567cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
1568cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
1569cd8.c20: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
1570cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mpr.dll'...
1571cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'mpr.dll' -> '\Device\HarddiskVolume2\Windows\System32\mpr.dll' [rcNtRedir=0xc0150008]
1572cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000470 pwszName=\Device\HarddiskVolume2\Windows\System32\mpr.dll
1573cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
1574cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
1575cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F84FE9BA047B24E7694C9E0C349B48B9FD5F925B
1576cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\mpr.dll'
1577cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1578cd8.c20: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\mpr.dll) WinVerifyTrust
1579cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\mpr.dll
1580cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
1581cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
1582cd8.c20: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
1583cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
1584cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
1585cd8.c20: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
1586cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
1587cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
1588cd8.c20: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
1589cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
1590cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
1591cd8.c20: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
1592cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1593cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1594cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
1595cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
1596cd8.c20: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
1597cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
1598cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
1599cd8.c20: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
1600cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
1601cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
1602cd8.c20: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
1603cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1604cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1605cd8.c20: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll
1606cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1607cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1608cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
1609cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
1610cd8.c20: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
1611cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
1612cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
1613cd8.c20: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
1614cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
1615cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
1616cd8.c20: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
1617cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
1618cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
1619cd8.c20: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
1620cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
1621cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
1622cd8.c20: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
1623cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
1624cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
1625cd8.c20: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
1626cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
1627cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
1628cd8.c20: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
1629cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1630cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1631cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1632cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1633cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
1634cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
1635cd8.c20: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
1636cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comdlg32.dll'...
1637cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'comdlg32.dll' -> '\Device\HarddiskVolume2\Windows\System32\comdlg32.dll' [rcNtRedir=0xc0150008]
1638cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000045c pwszName=\Device\HarddiskVolume2\Windows\System32\comdlg32.dll
1639cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
1640cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
1641cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=66EE5BDFFA413AEA9E1FE7838A08646E94136DA5
1642cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\comdlg32.dll'
1643cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1644cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1645cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'shlwapi.dll'.
1646cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
1647cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'gdi32.dll'.
1648cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'comctl32.dll'.
1649cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'shell32.dll'.
1650cd8.c20: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\comdlg32.dll) WinVerifyTrust
1651cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\comdlg32.dll
1652cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winspool.drv'...
1653cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'winspool.drv' -> '\Device\HarddiskVolume2\Windows\System32\winspool.drv' [rcNtRedir=0xc0150008]
1654cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000468 pwszName=\Device\HarddiskVolume2\Windows\System32\winspool.drv
1655cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
1656cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
1657cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=C89A2ED7B99A056D78CA6BAC9CCAB8B1FF119A14
1658cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\winspool.drv'
1659cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1660cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1661cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
1662cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
1663cd8.c20: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\winspool.drv) WinVerifyTrust
1664cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\winspool.drv
1665cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
1666cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
1667cd8.c20: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
1668cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
1669cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
1670cd8.c20: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
1671cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
1672cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
1673cd8.c20: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll
1674cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1675cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1676cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1677cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1678cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
1679cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
1680cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
1681cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
1682cd8.c20: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
1683cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
1684cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
1685cd8.c20: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
1686cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
1687cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
1688cd8.c20: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll
1689cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1690cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1691cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1692cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1693cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
1694cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
1695cd8.c20: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll
1696cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1697cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1698cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1699cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1700cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1701cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1702cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1703cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1704cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1705cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1706cd8.c20: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll
1707cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1708cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1709cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
1710cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
1711cd8.c20: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
1712cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comctl32.dll'...
1713cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'comctl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\comctl32.dll' [rcNtRedir=0x0]
1714cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000488 pwszName=\Device\HarddiskVolume2\Windows\System32\comctl32.dll
1715cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
1716cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
1717cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=4D3B2DA266DE92D9E1311E30C810160CDC5BD5AA
1718cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\comctl32.dll'
1719cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1720cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'advapi32.dll'.
1721cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
1722cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
1723cd8.c20: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\comctl32.dll) WinVerifyTrust
1724cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\comctl32.dll
1725cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1726cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1727cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1728cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1729cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
1730cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
1731cd8.c20: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll
1732cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1733cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1734cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1735cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1736cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
1737cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
1738cd8.c20: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
1739cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1740cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1741cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dwmapi.dll'...
1742cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'dwmapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\dwmapi.dll' [rcNtRedir=0xc0150008]
1743cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000460 pwszName=\Device\HarddiskVolume2\Windows\System32\dwmapi.dll
1744cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
1745cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
1746cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B79EE7B5AD74EF51A849809202E043183A2C727E
1747cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\dwmapi.dll'
1748cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1749cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1750cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
1751cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
1752cd8.c20: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\dwmapi.dll) WinVerifyTrust
1753cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\dwmapi.dll
1754cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
1755cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
1756cd8.c20: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\setupapi.dll
1757cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1758cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1759cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dciman32.dll'...
1760cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'dciman32.dll' -> '\Device\HarddiskVolume2\Windows\System32\dciman32.dll' [rcNtRedir=0xc0150008]
1761cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000044c pwszName=\Device\HarddiskVolume2\Windows\System32\dciman32.dll
1762cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
1763cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
1764cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=D3FEC714D729F7CAEB9B7A25E2012B6A6E9007F5
1765cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\dciman32.dll'
1766cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1767cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1768cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'gdi32.dll'.
1769cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
1770cd8.c20: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\dciman32.dll) WinVerifyTrust
1771cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\dciman32.dll
1772cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1773cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1774cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1775cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1776cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1777cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1778cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1779cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1780cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1781cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1782cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1783cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1784cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1785cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1786cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1787cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1788cd8.c20: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
1789cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1790cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1791cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1792cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1793cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
1794cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
1795cd8.c20: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
1796cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VirtualBox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
1797cd8.c20: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.dll
1798cd8.c20: supR3HardenedDllNotificationCallback: load 000007feed530000 LB 0x008e6000 C:\Program Files\Oracle\VirtualBox\VirtualBox.dll [fFlags=0x0]
1799cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.dll
1800cd8.c20: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
1801cd8.c20: supR3HardenedDllNotificationCallback: load 000007feee750000 LB 0x0011d000 C:\Windows\system32\OPENGL32.dll [fFlags=0x0]
1802cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
1803cd8.c20: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\glu32.dll
1804cd8.c20: supR3HardenedDllNotificationCallback: load 000007fefc780000 LB 0x0002d000 C:\Windows\system32\GLU32.dll [fFlags=0x0]
1805cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\glu32.dll
1806cd8.c20: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ddraw.dll
1807cd8.c20: supR3HardenedDllNotificationCallback: load 000007feee650000 LB 0x000f1000 C:\Windows\system32\DDRAW.dll [fFlags=0x0]
1808cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ddraw.dll
1809cd8.c20: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dciman32.dll
1810cd8.c20: supR3HardenedDllNotificationCallback: load 000007fefc820000 LB 0x00008000 C:\Windows\system32\DCIMAN32.dll [fFlags=0x0]
1811cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dciman32.dll
1812cd8.c20: supR3HardenedDllNotificationCallback: load 000007fefdcc0000 LB 0x001d7000 C:\Windows\system32\SETUPAPI.dll [fFlags=0x0]
1813cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\setupapi.dll
1814cd8.c20: supR3HardenedDllNotificationCallback: load 000007fefdbc0000 LB 0x00036000 C:\Windows\system32\CFGMGR32.dll [fFlags=0x0]
1815cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll
1816cd8.c20: supR3HardenedDllNotificationCallback: load 000007feff8c0000 LB 0x000d7000 C:\Windows\system32\OLEAUT32.dll [fFlags=0x0]
1817cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
1818cd8.c20: supR3HardenedDllNotificationCallback: load 000007feff680000 LB 0x00203000 C:\Windows\system32\ole32.dll [fFlags=0x0]
1819cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
1820cd8.c20: supR3HardenedDllNotificationCallback: load 000007fefdca0000 LB 0x0001a000 C:\Windows\system32\DEVOBJ.dll [fFlags=0x0]
1821cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\devobj.dll
1822cd8.c20: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dwmapi.dll
1823cd8.c20: supR3HardenedDllNotificationCallback: load 000007fefbc40000 LB 0x00018000 C:\Windows\system32\dwmapi.dll [fFlags=0x0]
1824cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dwmapi.dll
1825cd8.c20: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
1826cd8.c20: supR3HardenedDllNotificationCallback: load 000000006d2d0000 LB 0x00566000 C:\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [fFlags=0x0]
1827cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
1828cd8.c20: supR3HardenedDllNotificationCallback: load 000007fefe1d0000 LB 0x00d88000 C:\Windows\system32\SHELL32.dll [fFlags=0x0]
1829cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
1830cd8.c20: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\mpr.dll
1831cd8.c20: supR3HardenedDllNotificationCallback: load 000007fef9d60000 LB 0x00018000 C:\Windows\system32\MPR.dll [fFlags=0x0]
1832cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\mpr.dll
1833cd8.c20: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
1834cd8.c20: supR3HardenedDllNotificationCallback: load 000007feecf30000 LB 0x005f7000 C:\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll [fFlags=0x0]
1835cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
1836cd8.c20: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll
1837cd8.c20: supR3HardenedDllNotificationCallback: load 000000006c760000 LB 0x00561000 C:\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll [fFlags=0x0]
1838cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll
1839cd8.c20: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5PrintSupportVBox.dll
1840cd8.c20: supR3HardenedDllNotificationCallback: load 000007feeebf0000 LB 0x00051000 C:\Program Files\Oracle\VirtualBox\Qt5PrintSupportVBox.dll [fFlags=0x0]
1841cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5PrintSupportVBox.dll
1842cd8.c20: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winspool.drv
1843cd8.c20: supR3HardenedDllNotificationCallback: load 000007fef9ce0000 LB 0x00071000 C:\Windows\system32\WINSPOOL.DRV [fFlags=0x0]
1844cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winspool.drv
1845cd8.c20: supR3HardenedDllNotificationCallback: load 000007fefef60000 LB 0x00097000 C:\Windows\system32\COMDLG32.dll [fFlags=0x0]
1846cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\comdlg32.dll
1847cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'advapi32.dll'.
1848cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
1849cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
1850cd8.c20: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_a4d6a923711520a9\comctl32.dll)
1851cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_a4d6a923711520a9\comctl32.dll
1852cd8.c20: supR3HardenedDllNotificationCallback: load 000007fef9820000 LB 0x000a0000 C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_a4d6a923711520a9\COMCTL32.dll [fFlags=0x0]
1853cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_a4d6a923711520a9\comctl32.dll [avoiding WinVerifyTrust]
1854cd8.c20: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll
1855cd8.c20: supR3HardenedDllNotificationCallback: load 0000000070810000 LB 0x00054000 C:\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll [fFlags=0x0]
1856cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll
1857cd8.c20: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
1858cd8.c20: supR3HardenedDllNotificationCallback: load 000007fefb580000 LB 0x0003b000 C:\Windows\system32\WINMM.dll [fFlags=0x0]
1859cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
1860cd8.c20: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume2\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_a4d6a923711520a9\comctl32.dll'.
1861cd8.c20: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_a4d6a923711520a9\comctl32.dll' [rescheduled]
1862cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Core-LocalRegistry-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
1863cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077880000 'API-MS-Win-Core-LocalRegistry-L1-1-0.dll'
1864cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\imm32.dll
1865cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1866cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1867cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1868cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1869cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
1870cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
1871cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\imm32.dll (Input=imm32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
1872cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feffc80000 'C:\Windows\system32\imm32.dll'
1873cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff9d0000 'C:\Windows\system32\ADVAPI32.DLL'
1874cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cryptbase.dll
1875cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptbase.dll (Input=cryptbase.dll, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
1876cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd820000 'C:\Windows\system32\cryptbase.dll'
1877cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed530000 'C:\Program Files\Oracle\VirtualBox\VirtualBox.dll'
1878cd8.c20: SUPR3HardenedMain: Calling TrustedMain (000007feed531610)...
1879cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
1880cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ole32.dll (Input=ole32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
1881cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff680000 'C:\Windows\system32\ole32.dll'
1882cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff9d0000 'C:\Windows\system32\ADVAPI32.dll'
1883cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\profapi.dll
1884cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\profapi.dll (Input=profapi.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
1885cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd8f0000 'C:\Windows\system32\profapi.dll'
1886cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
1887cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'ole32.dll'.
1888cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
1889cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'imm32.dll'.
1890cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'winmm.dll'.
1891cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
1892cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'shell32.dll'.
1893cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'advapi32.dll'.
1894cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'qt5guivbox.dll'.
1895cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'qt5corevbox.dll'.
1896cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'msvcr100.dll'.
1897cd8.c20: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\platforms\qwindows.dll) WinVerifyTrust
1898cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\platforms\qwindows.dll
1899cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
1900cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
1901cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
1902cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
1903cd8.c20: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
1904cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
1905cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
1906cd8.c20: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
1907cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
1908cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
1909cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
1910cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
1911cd8.c20: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
1912cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
1913cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
1914cd8.c20: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
1915cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
1916cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
1917cd8.c20: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
1918cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
1919cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume2\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
1920cd8.c20: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\imm32.dll
1921cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1922cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1923cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
1924cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
1925cd8.c20: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
1926cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1927cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1928cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\platforms\qwindows.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
1929cd8.c20: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\platforms\qwindows.dll
1930cd8.c20: supR3HardenedDllNotificationCallback: load 000007feece00000 LB 0x0012e000 C:\Program Files\Oracle\VirtualBox\platforms\qwindows.dll [fFlags=0x0]
1931cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\platforms\qwindows.dll
1932cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feece00000 'C:\Program Files\Oracle\VirtualBox\platforms\qwindows.dll'
1933cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cryptbase.dll
1934cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTBASE.dll (Input=CRYPTBASE.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
1935cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd820000 'C:\Windows\system32\CRYPTBASE.dll'
1936cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000520 pwszName=\Device\HarddiskVolume2\Windows\System32\uxtheme.dll
1937cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
1938cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
1939cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=936D45CC7026757A151F62882B557DD75D5FCB21
1940cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\uxtheme.dll'
1941cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
1942cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1943cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
1944cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'gdi32.dll'.
1945cd8.c20: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\uxtheme.dll) WinVerifyTrust
1946cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
1947cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1948cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1949cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1950cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1951cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1952cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1953cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000008a03b0:C:\Windows\system32;;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
1954cd8.c20: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
1955cd8.c20: supR3HardenedDllNotificationCallback: load 000007fefc290000 LB 0x00056000 C:\Windows\system32\uxtheme.dll [fFlags=0x0]
1956cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
1957cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc290000 'C:\Windows\system32\uxtheme.dll'
1958cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
1959cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000008a03b0:C:\Windows\system32;;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
1960cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc290000 'C:\Windows\system32\uxtheme.dll'
1961cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
1962cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000008a03b0:C:\Windows\system32;;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
1963cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc290000 'C:\Windows\system32\uxtheme.dll'
1964cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
1965cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000008a03b0:C:\Windows\system32;;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
1966cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc290000 'C:\Windows\system32\uxtheme.dll'
1967cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077780000 'C:\Windows\system32\user32.dll'
1968cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
1969cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
1970cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe1d0000 'C:\Windows\system32\shell32.dll'
1971cd8.c20: supR3HardenedMonitor_LdrLoadDll: error opening 'C:\Windows\system32\wintab32.dll': 0 (NtPath=\??\C:\Windows\system32\wintab32.dll; Input=C:\Windows\system32\wintab32.dll; rcNtGetDll=0x0
1972cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wintab32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
1973cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000135 'C:\Windows\system32\wintab32.dll'
1974cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dwmapi.dll
1975cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\dwmapi.dll (Input=dwmapi.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
1976cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbc40000 'C:\Windows\system32\dwmapi.dll'
1977cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
1978cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\winmm.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
1979cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefb580000 'C:\Windows\system32\winmm.dll'
1980cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
1981cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\winmm.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
1982cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefb580000 'C:\Windows\system32\winmm.dll'
1983cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
1984cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
1985cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe1d0000 'C:\Windows\system32\shell32.dll'
1986cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
1987cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
1988cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc290000 'C:\Windows\system32\uxtheme.dll'
1989cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff9d0000 'C:\Windows\system32\advapi32.dll'
1990cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\userenv.dll
1991cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\userenv.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
1992cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcc20000 'C:\Windows\system32\userenv.dll'
1993cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll
1994cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (Input=kernel32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
1995cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077880000 'C:\Windows\system32\kernel32.dll'
1996cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000538 pwszName=\Device\HarddiskVolume2\Windows\System32\clbcatq.dll
1997cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
1998cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
1999cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B01469787CE9D8C6FEE98FB207652B88B8494526
2000cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\clbcatq.dll'
2001cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2002cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
2003cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'ole32.dll'.
2004cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
2005cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
2006cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
2007cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'rpcrt4.dll'.
2008cd8.c20: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\clbcatq.dll) WinVerifyTrust
2009cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\clbcatq.dll
2010cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
2011cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
2012cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
2013cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
2014cd8.c20: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
2015cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
2016cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
2017cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
2018cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
2019cd8.c20: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll
2020cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
2021cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
2022cd8.c20: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
2023cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
2024cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
2025cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CLBCatQ.DLL (Input=CLBCatQ.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
2026cd8.c20: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\clbcatq.dll
2027cd8.c20: supR3HardenedDllNotificationCallback: load 000007feffbe0000 LB 0x00099000 C:\Windows\system32\CLBCatQ.DLL [fFlags=0x0]
2028cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\clbcatq.dll
2029cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feffbe0000 'C:\Windows\system32\CLBCatQ.DLL'
2030cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff9d0000 'C:\Windows\system32\ADVAPI32.dll'
2031cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cryptsp.dll
2032cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTSP.dll (Input=CRYPTSP.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
2033cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd1c0000 'C:\Windows\system32\CRYPTSP.dll'
2034cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000568 pwszName=\Device\HarddiskVolume2\Windows\System32\RpcRtRemote.dll
2035cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
2036cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
2037cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=DFC4A7C7E103D324218E6EF5D219B953746D6EC1
2038cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\RpcRtRemote.dll'
2039cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2040cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'rpcrt4.dll'.
2041cd8.c20: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\RpcRtRemote.dll) WinVerifyTrust
2042cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\RpcRtRemote.dll
2043cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
2044cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
2045cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\RpcRtRemote.dll (Input=RpcRtRemote.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
2046cd8.c20: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\RpcRtRemote.dll
2047cd8.c20: supR3HardenedDllNotificationCallback: load 000007fefd830000 LB 0x00014000 C:\Windows\system32\RpcRtRemote.dll [fFlags=0x0]
2048cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\RpcRtRemote.dll
2049cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd830000 'C:\Windows\system32\RpcRtRemote.dll'
2050cd8.1098: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
2051cd8.1098: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
2052cd8.1098: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
2053cd8.1098: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
2054cd8.1098: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ole32.dll'.
2055cd8.1098: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'oleaut32.dll'.
2056cd8.1098: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxC.dll) WinVerifyTrust
2057cd8.1098: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxC.dll
2058cd8.1098: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
2059cd8.1098: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
2060cd8.1098: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
2061cd8.1098: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
2062cd8.1098: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
2063cd8.1098: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
2064cd8.1098: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
2065cd8.1098: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
2066cd8.1098: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
2067cd8.1098: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
2068cd8.1098: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
2069cd8.1098: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
2070cd8.1098: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
2071cd8.1098: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
2072cd8.1098: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
2073cd8.1098: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxC.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
2074cd8.1098: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxC.dll
2075cd8.1098: supR3HardenedDllNotificationCallback: load 000007feec900000 LB 0x004f5000 C:\Program Files\Oracle\VirtualBox\VBoxC.dll [fFlags=0x0]
2076cd8.1098: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxC.dll
2077cd8.1098: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec900000 'C:\Program Files\Oracle\VirtualBox\VBoxC.dll'
2078cd8.1098: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
2079cd8.1098: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
2080cd8.1098: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
2081cd8.1098: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'shlwapi.dll'.
2082cd8.1098: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ole32.dll'.
2083cd8.1098: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'oleaut32.dll'.
2084cd8.1098: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
2085cd8.1098: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll) WinVerifyTrust
2086cd8.1098: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll
2087cd8.1098: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
2088cd8.1098: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
2089cd8.1098: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
2090cd8.1098: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
2091cd8.1098: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
2092cd8.1098: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
2093cd8.1098: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
2094cd8.1098: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
2095cd8.1098: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
2096cd8.1098: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll
2097cd8.1098: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
2098cd8.1098: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
2099cd8.1098: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
2100cd8.1098: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
2101cd8.1098: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
2102cd8.1098: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
2103cd8.1098: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
2104cd8.1098: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll
2105cd8.1098: supR3HardenedDllNotificationCallback: load 000007feee8d0000 LB 0x000b5000 C:\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll [fFlags=0x0]
2106cd8.1098: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll
2107cd8.1098: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feee8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll'
2108cd8.1098: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
2109cd8.1098: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\oleaut32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000008a03b0:C:\Windows\system32;;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
2110cd8.1098: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff8c0000 'C:\Windows\system32\oleaut32.dll'
2111cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff9d0000 'C:\Windows\system32\ADVAPI32.dll'
2112cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff130000 'C:\Windows\system32\gdi32.dll'
2113cd8.ed8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
2114cd8.ed8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
2115cd8.ed8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMain.dll) WinVerifyTrust
2116cd8.ed8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMain.dll
2117cd8.ed8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
2118cd8.ed8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
2119cd8.ed8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
2120cd8.ed8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
2121cd8.ed8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMain.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
2122cd8.ed8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMain.dll
2123cd8.ed8: supR3HardenedDllNotificationCallback: load 000007fefc7c0000 LB 0x0000d000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMain.DLL [fFlags=0x0]
2124cd8.ed8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMain.dll
2125cd8.ed8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc7c0000 'C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMain.DLL'
2126cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
2127cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
2128cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe1d0000 'C:\Windows\system32\shell32.dll'
2129cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe1d0000 'C:\Windows\system32\shell32.dll'
2130cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe1d0000 'C:\Windows\system32\shell32.dll'
2131cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe1d0000 'C:\Windows\system32\shell32.dll'
2132cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe1d0000 'C:\Windows\system32\shell32.dll'
2133cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe1d0000 'C:\Windows\system32\shell32.dll'
2134cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff9d0000 'C:\Windows\system32\ADVAPI32.dll'
2135cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff680000 'C:\Windows\system32\ole32.dll'
2136cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msctf.dll
2137cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\MSCTF.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000008a0dd0:C:\Windows\system32;;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
2138cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdff0000 'C:\Windows\system32\MSCTF.dll'
2139cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
2140cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\WINMM.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
2141cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefb580000 'C:\Windows\system32\WINMM.dll'
2142cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff8c0000 'C:\Windows\system32\OLEAUT32.DLL'
2143cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe1d0000 'C:\Windows\system32\shell32.dll'
2144cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe1d0000 'C:\Windows\system32\shell32.dll'
2145cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff680000 'C:\Windows\system32\ole32.dll'
2146cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff8c0000 'C:\Windows\system32\OLEAUT32.dll'
2147cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000914 pwszName=\Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll
2148cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
2149cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
2150cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=41D7AA7A9ECA84ABF6801478BA3134174B21C472
2151cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll'
2152cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2153cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
2154cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'wbemcomn.dll'.
2155cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
2156cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
2157cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ole32.dll'.
2158cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'ws2_32.dll'.
2159cd8.c20: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll) WinVerifyTrust
2160cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll
2161cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
2162cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
2163cd8.c20: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
2164cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
2165cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
2166cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
2167cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
2168cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
2169cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
2170cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wbemcomn.dll'...
2171cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'wbemcomn.dll' -> '\Device\HarddiskVolume2\Windows\System32\wbemcomn.dll' [rcNtRedir=0xc0150008]
2172cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000918 pwszName=\Device\HarddiskVolume2\Windows\System32\wbemcomn.dll
2173cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
2174cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
2175cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=03D0A77E5195AA70198FDE6C2FAC2C76FF200674
2176cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\wbemcomn.dll'
2177cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2178cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
2179cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'oleaut32.dll'.
2180cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'ole32.dll'.
2181cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
2182cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ws2_32.dll'.
2183cd8.c20: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\wbemcomn.dll) WinVerifyTrust
2184cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wbemcomn.dll
2185cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
2186cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
2187cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
2188cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
2189cd8.c20: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
2190cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
2191cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
2192cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
2193cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
2194cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
2195cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
2196cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
2197cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
2198cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wbem\wbemprox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000002df4c30:C:\Windows\system32\wbem;;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
2199cd8.c20: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll
2200cd8.c20: supR3HardenedDllNotificationCallback: load 000007fef95a0000 LB 0x0000f000 C:\Windows\system32\wbem\wbemprox.dll [fFlags=0x0]
2201cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll
2202cd8.c20: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbemcomn.dll
2203cd8.c20: supR3HardenedDllNotificationCallback: load 000007fef9510000 LB 0x00086000 C:\Windows\system32\wbemcomn.dll [fFlags=0x0]
2204cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbemcomn.dll
2205cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Core-LocalRegistry-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
2206cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077880000 'API-MS-Win-Core-LocalRegistry-L1-1-0.dll'
2207cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef95a0000 'C:\Windows\system32\wbem\wbemprox.dll'
2208cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000940 pwszName=\Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll
2209cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
2210cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
2211cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=83AB88529BF28CFF670EA617E0B9C376CFE28B0F
2212cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll'
2213cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2214cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
2215cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'rpcrt4.dll'.
2216cd8.c20: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll) WinVerifyTrust
2217cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll
2218cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
2219cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
2220cd8.c20: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
2221cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
2222cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
2223cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wbem\wbemsvc.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000002e3da20:C:\Windows\system32\wbem;;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
2224cd8.c20: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll
2225cd8.c20: supR3HardenedDllNotificationCallback: load 000007fef8c80000 LB 0x00014000 C:\Windows\system32\wbem\wbemsvc.dll [fFlags=0x0]
2226cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll
2227cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef8c80000 'C:\Windows\system32\wbem\wbemsvc.dll'
2228cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000094c pwszName=\Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll
2229cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
2230cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
2231cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=391AD7580DBA8EA6A4190F5A010E834B8C320D79
2232cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll'
2233cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2234cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
2235cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'wbemcomn.dll'.
2236cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
2237cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'oleaut32.dll'.
2238cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ole32.dll'.
2239cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ntdsapi.dll'.
2240cd8.c20: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll) WinVerifyTrust
2241cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll
2242cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntdsapi.dll'...
2243cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntdsapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\ntdsapi.dll' [rcNtRedir=0xc0150008]
2244cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000934 pwszName=\Device\HarddiskVolume2\Windows\System32\ntdsapi.dll
2245cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
2246cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
2247cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=67C74E045820FCAB3FC8AD5C180928A20C1F11CE
2248cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\ntdsapi.dll'
2249cd8.c20: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2250cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
2251cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'rpcrt4.dll'.
2252cd8.c20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'ws2_32.dll'.
2253cd8.c20: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ntdsapi.dll) WinVerifyTrust
2254cd8.c20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ntdsapi.dll
2255cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
2256cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
2257cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
2258cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
2259cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
2260cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
2261cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wbemcomn.dll'...
2262cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'wbemcomn.dll' -> '\Device\HarddiskVolume2\Windows\System32\wbemcomn.dll' [rcNtRedir=0xc0150008]
2263cd8.c20: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbemcomn.dll
2264cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
2265cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
2266cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
2267cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
2268cd8.c20: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
2269cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
2270cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
2271cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
2272cd8.c20: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
2273cd8.c20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wbem\fastprox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000002e3da20:C:\Windows\system32\wbem;;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
2274cd8.c20: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll
2275cd8.c20: supR3HardenedDllNotificationCallback: load 000007fef9180000 LB 0x000e2000 C:\Windows\system32\wbem\fastprox.dll [fFlags=0x0]
2276cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll
2277cd8.c20: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ntdsapi.dll
2278cd8.c20: supR3HardenedDllNotificationCallback: load 000007fefa5a0000 LB 0x00027000 C:\Windows\system32\NTDSAPI.dll [fFlags=0x0]
2279cd8.c20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ntdsapi.dll
2280cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef9180000 'C:\Windows\system32\wbem\fastprox.dll'
2281cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff8c0000 'C:\Windows\system32\OLEAUT32.dll'
2282cd8.11a8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
2283cd8.11a8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrem.dll'.
2284cd8.11a8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
2285cd8.11a8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll) WinVerifyTrust
2286cd8.11a8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
2287cd8.11a8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
2288cd8.11a8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
2289cd8.11a8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrem.dll'...
2290cd8.11a8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrem.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrem.dll' [rcNtRedir=0xc0150008]
2291cd8.11a8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'vboxrt.dll'.
2292cd8.11a8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
2293cd8.11a8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcrt.dll'.
2294cd8.11a8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxREM.dll) WinVerifyTrust
2295cd8.11a8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxREM.dll
2296cd8.11a8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
2297cd8.11a8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
2298cd8.11a8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
2299cd8.11a8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
2300cd8.11a8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
2301cd8.11a8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
2302cd8.11a8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
2303cd8.11a8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
2304cd8.11a8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
2305cd8.11a8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
2306cd8.11a8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
2307cd8.11a8: supR3HardenedDllNotificationCallback: load 000007feec4f0000 LB 0x0029d000 C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL [fFlags=0x0]
2308cd8.11a8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
2309cd8.11a8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxREM.dll
2310cd8.11a8: supR3HardenedDllNotificationCallback: load 000000006d130000 LB 0x0010b000 C:\Program Files\Oracle\VirtualBox\VBoxREM.dll [fFlags=0x0]
2311cd8.11a8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxREM.dll
2312cd8.11a8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec4f0000 'C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL'
2313cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000a08 pwszName=\Device\HarddiskVolume2\Windows\System32\netcfgx.dll
2314cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
2315cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
2316cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B2E2834BA132AEF0C1091DED23D983BBB0CDB980
2317cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\netcfgx.dll'
2318cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2319cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'shlwapi.dll'.
2320cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
2321cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'gdi32.dll'.
2322cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ole32.dll'.
2323cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'oleaut32.dll'.
2324cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'user32.dll'.
2325cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'nsi.dll'.
2326cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'iphlpapi.dll'.
2327cd8.11b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\netcfgx.dll) WinVerifyTrust
2328cd8.11b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\netcfgx.dll
2329cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'iphlpapi.dll'...
2330cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'iphlpapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\iphlpapi.dll' [rcNtRedir=0xc0150008]
2331cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000a24 pwszName=\Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL
2332cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
2333cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
2334cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=3BDC72529DA09BA841BE702C4C902C8AA1242642
2335cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL'
2336cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2337cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
2338cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'nsi.dll'.
2339cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'winnsi.dll'.
2340cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'rpcrt4.dll'.
2341cd8.11b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL) WinVerifyTrust
2342cd8.11b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL
2343cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
2344cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume2\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
2345cd8.11b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\nsi.dll
2346cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
2347cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
2348cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
2349cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
2350cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
2351cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
2352cd8.11b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
2353cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
2354cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
2355cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
2356cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
2357cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
2358cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
2359cd8.11b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll
2360cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
2361cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
2362cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winnsi.dll'...
2363cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'winnsi.dll' -> '\Device\HarddiskVolume2\Windows\System32\winnsi.dll' [rcNtRedir=0xc0150008]
2364cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000009f4 pwszName=\Device\HarddiskVolume2\Windows\System32\winnsi.dll
2365cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
2366cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
2367cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B28F3E0DF5586B9FB3AEAC48E4ECCA0AFB6ABD91
2368cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\winnsi.dll'
2369cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2370cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
2371cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'rpcrt4.dll'.
2372cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'nsi.dll'.
2373cd8.11b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\winnsi.dll) WinVerifyTrust
2374cd8.11b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\winnsi.dll
2375cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
2376cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume2\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
2377cd8.11b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\nsi.dll
2378cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
2379cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
2380cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
2381cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume2\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
2382cd8.11b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\nsi.dll
2383cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
2384cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
2385cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
2386cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
2387cd8.11b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\netcfgx.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000002c75010:C:\Windows\system32;;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
2388cd8.11b4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\netcfgx.dll
2389cd8.11b4: supR3HardenedDllNotificationCallback: load 000007fef0580000 LB 0x00084000 C:\Windows\system32\netcfgx.dll [fFlags=0x0]
2390cd8.11b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\netcfgx.dll
2391cd8.11b4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL
2392cd8.11b4: supR3HardenedDllNotificationCallback: load 000007fefc520000 LB 0x00027000 C:\Windows\system32\IPHLPAPI.DLL [fFlags=0x0]
2393cd8.11b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL
2394cd8.11b4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winnsi.dll
2395cd8.11b4: supR3HardenedDllNotificationCallback: load 000007fefcab0000 LB 0x0000b000 C:\Windows\system32\WINNSI.DLL [fFlags=0x0]
2396cd8.11b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winnsi.dll
2397cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef0580000 'C:\Windows\system32\netcfgx.dll'
2398cd8.11b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\setupapi.dll
2399cd8.11b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\SETUPAPI.dll (Input=SETUPAPI.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
2400cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdcc0000 'C:\Windows\system32\SETUPAPI.dll'
2401cd8.11b4: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Core-LocalRegistry-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
2402cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077880000 'API-MS-Win-Core-LocalRegistry-L1-1-0.dll'
2403cd8.11b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll
2404cd8.11b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\WINTRUST.dll (Input=WINTRUST.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
2405cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd9a0000 'C:\Windows\system32\WINTRUST.dll'
2406cd8.11bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
2407cd8.11bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
2408cd8.11bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
2409cd8.11bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
2410cd8.11bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll) WinVerifyTrust
2411cd8.11bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll
2412cd8.11bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
2413cd8.11bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
2414cd8.11bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
2415cd8.11bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
2416cd8.11bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
2417cd8.11bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
2418cd8.11bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
2419cd8.11bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
2420cd8.11bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
2421cd8.11bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
2422cd8.11bc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll
2423cd8.11bc: supR3HardenedDllNotificationCallback: load 000007fefbf00000 LB 0x0000b000 C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL [fFlags=0x0]
2424cd8.11bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll
2425cd8.11bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbf00000 'C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL'
2426cd8.11bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077780000 'C:\Windows\system32\User32.dll'
2427cd8.11c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
2428cd8.11c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
2429cd8.11c8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
2430cd8.11c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll) WinVerifyTrust
2431cd8.11c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll
2432cd8.11c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
2433cd8.11c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
2434cd8.11c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
2435cd8.11c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
2436cd8.11c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
2437cd8.11c8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
2438cd8.11c8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
2439cd8.11c8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
2440cd8.11c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
2441cd8.11c8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll
2442cd8.11c8: supR3HardenedDllNotificationCallback: load 000007fefa9f0000 LB 0x0000d000 C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL [fFlags=0x0]
2443cd8.11c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll
2444cd8.11c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa9f0000 'C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL'
2445cd8.10cc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
2446cd8.10cc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
2447cd8.10cc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
2448cd8.10cc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll) WinVerifyTrust
2449cd8.10cc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll
2450cd8.10cc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
2451cd8.10cc: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
2452cd8.10cc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
2453cd8.10cc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
2454cd8.10cc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
2455cd8.10cc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
2456cd8.10cc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
2457cd8.10cc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll
2458cd8.10cc: supR3HardenedDllNotificationCallback: load 000007fefa790000 LB 0x0000c000 C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL [fFlags=0x0]
2459cd8.10cc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll
2460cd8.10cc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa790000 'C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL'
2461cd8.10d8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
2462cd8.10d8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
2463cd8.10d8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
2464cd8.10d8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll) WinVerifyTrust
2465cd8.10d8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll
2466cd8.10d8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
2467cd8.10d8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
2468cd8.10d8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
2469cd8.10d8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
2470cd8.10d8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
2471cd8.10d8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
2472cd8.10d8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
2473cd8.10d8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll
2474cd8.10d8: supR3HardenedDllNotificationCallback: load 000007fefa780000 LB 0x0000b000 C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL [fFlags=0x0]
2475cd8.10d8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll
2476cd8.10d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa780000 'C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL'
2477cd8.11b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
2478cd8.11b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\Shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
2479cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe1d0000 'C:\Windows\system32\Shell32.dll'
2480cd8.11b4: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
2481cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff8a0000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
2482cd8.11b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
2483cd8.11b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
2484cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec4f0000 'C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL'
2485cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
2486cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
2487cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
2488cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ole32.dll'.
2489cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
2490cd8.11b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll) WinVerifyTrust
2491cd8.11b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
2492cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
2493cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
2494cd8.11b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
2495cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
2496cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
2497cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
2498cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
2499cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
2500cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
2501cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
2502cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
2503cd8.11b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
2504cd8.11b4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
2505cd8.11b4: supR3HardenedDllNotificationCallback: load 000007fef7470000 LB 0x0002d000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL [fFlags=0x0]
2506cd8.11b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
2507cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef7470000 'C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL'
2508cd8.11b4: supR3HardenedDllNotificationCallback: Unload 000007fef7470000 LB 0x0002d000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL [flags=0x0]
2509cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
2510cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
2511cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
2512cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vboxddu.dll'.
2513cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'vboxdd2.dll'.
2514cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
2515cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'setupapi.dll'.
2516cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'ws2_32.dll'.
2517cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'ole32.dll'.
2518cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'iphlpapi.dll'.
2519cd8.11b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD.dll) WinVerifyTrust
2520cd8.11b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD.dll
2521cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'iphlpapi.dll'...
2522cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'iphlpapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\iphlpapi.dll' [rcNtRedir=0xc0150008]
2523cd8.11b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL
2524cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
2525cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
2526cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
2527cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
2528cd8.11b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
2529cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
2530cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
2531cd8.11b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\setupapi.dll
2532cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
2533cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
2534cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxdd2.dll'...
2535cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxdd2.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxdd2.dll' [rcNtRedir=0xc0150008]
2536cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
2537cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
2538cd8.11b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD2.dll) WinVerifyTrust
2539cd8.11b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD2.dll
2540cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxddu.dll'...
2541cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxddu.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxddu.dll' [rcNtRedir=0xc0150008]
2542cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
2543cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
2544cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
2545cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'setupapi.dll'.
2546cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'advapi32.dll'.
2547cd8.11b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDDU.dll) WinVerifyTrust
2548cd8.11b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDDU.dll
2549cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
2550cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
2551cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
2552cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
2553cd8.11b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
2554cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
2555cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
2556cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
2557cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
2558cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
2559cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
2560cd8.11b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\setupapi.dll
2561cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
2562cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
2563cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
2564cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
2565cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
2566cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
2567cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
2568cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
2569cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
2570cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
2571cd8.11b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxDD.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
2572cd8.11b4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD.dll
2573cd8.11b4: supR3HardenedDllNotificationCallback: load 000007fee9d40000 LB 0x008c5000 C:\Program Files\Oracle\VirtualBox\VBoxDD.DLL [fFlags=0x0]
2574cd8.11b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD.dll
2575cd8.11b4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDDU.dll
2576cd8.11b4: supR3HardenedDllNotificationCallback: load 000007feef060000 LB 0x00057000 C:\Program Files\Oracle\VirtualBox\VBoxDDU.dll [fFlags=0x0]
2577cd8.11b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDDU.dll
2578cd8.11b4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD2.dll
2579cd8.11b4: supR3HardenedDllNotificationCallback: load 000007fef7440000 LB 0x0005d000 C:\Program Files\Oracle\VirtualBox\VBoxDD2.dll [fFlags=0x0]
2580cd8.11b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD2.dll
2581cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee9d40000 'C:\Program Files\Oracle\VirtualBox\VBoxDD.DLL'
2582cd8.11b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
2583cd8.11b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
2584cd8.11b4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
2585cd8.11b4: supR3HardenedDllNotificationCallback: load 000007fef5ca0000 LB 0x0002d000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL [fFlags=0x0]
2586cd8.11b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
2587cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef5ca0000 'C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL'
2588cd8.11b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxC.dll
2589cd8.11b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxC.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
2590cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec900000 'C:\Program Files\Oracle\VirtualBox\VBoxC.DLL'
2591cd8.11b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD2.dll
2592cd8.11b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxDD2.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
2593cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef7440000 'C:\Program Files\Oracle\VirtualBox\VBoxDD2.DLL'
2594cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
2595cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
2596cd8.11b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.dll) WinVerifyTrust
2597cd8.11b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.dll
2598cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
2599cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
2600cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
2601cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
2602cd8.11b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
2603cd8.11b4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.dll
2604cd8.11b4: supR3HardenedDllNotificationCallback: load 000007fefa760000 LB 0x0001e000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.DLL [fFlags=0x0]
2605cd8.11b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.dll
2606cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa760000 'C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.DLL'
2607cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
2608cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
2609cd8.11b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.dll) WinVerifyTrust
2610cd8.11b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.dll
2611cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
2612cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
2613cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
2614cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
2615cd8.11b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
2616cd8.11b4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.dll
2617cd8.11b4: supR3HardenedDllNotificationCallback: load 000007fef7420000 LB 0x00017000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.DLL [fFlags=0x0]
2618cd8.11b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.dll
2619cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef7420000 'C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.DLL'
2620cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
2621cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
2622cd8.11b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.dll) WinVerifyTrust
2623cd8.11b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.dll
2624cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
2625cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
2626cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
2627cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
2628cd8.11b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
2629cd8.11b4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.dll
2630cd8.11b4: supR3HardenedDllNotificationCallback: load 000007fef5c50000 LB 0x00017000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.DLL [fFlags=0x0]
2631cd8.11b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.dll
2632cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef5c50000 'C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.DLL'
2633cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
2634cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
2635cd8.11b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.dll) WinVerifyTrust
2636cd8.11b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.dll
2637cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
2638cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
2639cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
2640cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
2641cd8.11b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
2642cd8.11b4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.dll
2643cd8.11b4: supR3HardenedDllNotificationCallback: load 000007fef5c30000 LB 0x00019000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.DLL [fFlags=0x0]
2644cd8.11b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.dll
2645cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef5c30000 'C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.DLL'
2646cd8.1128: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
2647cd8.1128: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
2648cd8.1128: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
2649cd8.1128: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll) WinVerifyTrust
2650cd8.1128: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll
2651cd8.1128: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
2652cd8.1128: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
2653cd8.1128: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
2654cd8.1128: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
2655cd8.1128: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
2656cd8.1128: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
2657cd8.1128: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
2658cd8.1128: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
2659cd8.1128: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll
2660cd8.1128: supR3HardenedDllNotificationCallback: load 000007fef7f50000 LB 0x0000d000 C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL [fFlags=0x0]
2661cd8.1128: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll
2662cd8.1128: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef7f50000 'C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL'
2663cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
2664cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
2665cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
2666cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
2667cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ws2_32.dll'.
2668cd8.11b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.dll) WinVerifyTrust
2669cd8.11b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.dll
2670cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
2671cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
2672cd8.11b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
2673cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
2674cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
2675cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
2676cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
2677cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
2678cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
2679cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
2680cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
2681cd8.11b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
2682cd8.11b4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.dll
2683cd8.11b4: supR3HardenedDllNotificationCallback: load 000007feec810000 LB 0x000e5000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.DLL [fFlags=0x0]
2684cd8.11b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.dll
2685cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec810000 'C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.DLL'
2686cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000ca8 pwszName=\Device\HarddiskVolume2\Windows\System32\dsound.dll
2687cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
2688cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
2689cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F6C3E3D9F8B48D816E52C31576FFFD4AF86AB813
2690cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\dsound.dll'
2691cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2692cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
2693cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
2694cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
2695cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ole32.dll'.
2696cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'winmm.dll'.
2697cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'powrprof.dll'.
2698cd8.11b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\dsound.dll) WinVerifyTrust
2699cd8.11b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\dsound.dll
2700cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'powrprof.dll'...
2701cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'powrprof.dll' -> '\Device\HarddiskVolume2\Windows\System32\powrprof.dll' [rcNtRedir=0xc0150008]
2702cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000cac pwszName=\Device\HarddiskVolume2\Windows\System32\powrprof.dll
2703cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
2704cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
2705cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=E0B7DE18787DB24DAD3580634869A9A8FF4AB48F
2706cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\powrprof.dll'
2707cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2708cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
2709cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'rpcrt4.dll'.
2710cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'setupapi.dll'.
2711cd8.11b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\powrprof.dll) WinVerifyTrust
2712cd8.11b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\powrprof.dll
2713cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
2714cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
2715cd8.11b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
2716cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
2717cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
2718cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
2719cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
2720cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
2721cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
2722cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
2723cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
2724cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
2725cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
2726cd8.11b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\setupapi.dll
2727cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
2728cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
2729cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
2730cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
2731cd8.11b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000092301a0:C:\Windows\System32;;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
2732cd8.11b4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dsound.dll
2733cd8.11b4: supR3HardenedDllNotificationCallback: load 000007feeb510000 LB 0x00088000 C:\Windows\System32\dsound.dll [fFlags=0x0]
2734cd8.11b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dsound.dll
2735cd8.11b4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\powrprof.dll
2736cd8.11b4: supR3HardenedDllNotificationCallback: load 000007fefbc70000 LB 0x0002c000 C:\Windows\System32\POWRPROF.dll [fFlags=0x0]
2737cd8.11b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\powrprof.dll
2738cd8.11b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dsound.dll
2739cd8.11b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
2740cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeb510000 'C:\Windows\System32\dsound.dll'
2741cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeb510000 'C:\Windows\System32\dsound.dll'
2742cd8.11b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dsound.dll
2743cd8.11b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
2744cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeb510000 'C:\Windows\system32\dsound.dll'
2745cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000cb0 pwszName=\Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
2746cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
2747cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
2748cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=704F97298D44B8146C54067788F597E0BF365197
2749cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll'
2750cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2751cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
2752cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'user32.dll'.
2753cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'rpcrt4.dll'.
2754cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'propsys.dll'.
2755cd8.11b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll) WinVerifyTrust
2756cd8.11b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
2757cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'propsys.dll'...
2758cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'propsys.dll' -> '\Device\HarddiskVolume2\Windows\System32\propsys.dll' [rcNtRedir=0xc0150008]
2759cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000cd4 pwszName=\Device\HarddiskVolume2\Windows\System32\propsys.dll
2760cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
2761cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
2762cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=6A1594E841359779EF7EA7EBCF775D89F55388D3
2763cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\propsys.dll'
2764cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2765cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
2766cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ole32.dll'.
2767cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'oleaut32.dll'.
2768cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'user32.dll'.
2769cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'rpcrt4.dll'.
2770cd8.11b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\propsys.dll) WinVerifyTrust
2771cd8.11b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\propsys.dll
2772cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
2773cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
2774cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
2775cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
2776cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
2777cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
2778cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
2779cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
2780cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
2781cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
2782cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
2783cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
2784cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
2785cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
2786cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
2787cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
2788cd8.11b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\MMDevApi.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000092301a0:C:\Windows\System32;;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
2789cd8.11b4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
2790cd8.11b4: supR3HardenedDllNotificationCallback: load 000007fefbe80000 LB 0x0004b000 C:\Windows\System32\MMDevApi.dll [fFlags=0x0]
2791cd8.11b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
2792cd8.11b4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\propsys.dll
2793cd8.11b4: supR3HardenedDllNotificationCallback: load 000007fefbd50000 LB 0x0012c000 C:\Windows\System32\PROPSYS.dll [fFlags=0x0]
2794cd8.11b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\propsys.dll
2795cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff9d0000 'C:\Windows\system32\ADVAPI32.dll'
2796cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbe80000 'C:\Windows\System32\MMDevApi.dll'
2797cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff680000 'C:\Windows\system32\ole32.dll'
2798cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdcc0000 'C:\Windows\system32\SETUPAPI.dll'
2799cd8.11b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll
2800cd8.11b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\SHLWAPI.dll (Input=SHLWAPI.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
2801cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff3a0000 'C:\Windows\system32\SHLWAPI.dll'
2802cd8.11b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
2803cd8.11b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\MMDEVAPI.DLL (Input=MMDEVAPI.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
2804cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbe80000 'C:\Windows\system32\MMDEVAPI.DLL'
2805cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff680000 'C:\Windows\system32\ole32.dll'
2806cd8.115c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll
2807cd8.115c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CFGMGR32.dll (Input=CFGMGR32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
2808cd8.115c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdbc0000 'C:\Windows\system32\CFGMGR32.dll'
2809cd8.11b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
2810cd8.11b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\winmm.dll (Input=winmm.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
2811cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefb580000 'C:\Windows\system32\winmm.dll'
2812cd8.11b4: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-Management-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
2813cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff8a0000 'API-MS-WIN-Service-Management-L1-1-0.dll'
2814cd8.11b4: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-winsvc-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
2815cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff8a0000 'API-MS-WIN-Service-winsvc-L1-1-0.dll'
2816cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff000000 'C:\Windows\system32\RPCRT4.dll'
2817cd8.11b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
2818cd8.11b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\MMDevAPI.DLL (Input=MMDevAPI.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
2819cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbe80000 'C:\Windows\system32\MMDevAPI.DLL'
2820cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000cfc pwszName=\Device\HarddiskVolume2\Windows\System32\wdmaud.drv
2821cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
2822cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
2823cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=4B64306F5558D2DEC53CF11AAF17F02438929FDD
2824cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\wdmaud.drv'
2825cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2826cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
2827cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
2828cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ole32.dll'.
2829cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'user32.dll'.
2830cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'winmm.dll'.
2831cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'ksuser.dll'.
2832cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'mmdevapi.dll'.
2833cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'avrt.dll'.
2834cd8.11b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\wdmaud.drv) WinVerifyTrust
2835cd8.11b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
2836cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'avrt.dll'...
2837cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'avrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\avrt.dll' [rcNtRedir=0xc0150008]
2838cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000d00 pwszName=\Device\HarddiskVolume2\Windows\System32\avrt.dll
2839cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
2840cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
2841cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=1362C343929DD08AB918B38DE195D1A11B1D1365
2842cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\avrt.dll'
2843cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2844cd8.11b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\avrt.dll) WinVerifyTrust
2845cd8.11b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\avrt.dll
2846cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mmdevapi.dll'...
2847cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'mmdevapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\mmdevapi.dll' [rcNtRedir=0xc0150008]
2848cd8.11b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
2849cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ksuser.dll'...
2850cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ksuser.dll' -> '\Device\HarddiskVolume2\Windows\System32\ksuser.dll' [rcNtRedir=0xc0150008]
2851cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000d1c pwszName=\Device\HarddiskVolume2\Windows\System32\ksuser.dll
2852cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
2853cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
2854cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=EC3873F9ACBE279185D3540F02128F42D21D0856
2855cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\ksuser.dll'
2856cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2857cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
2858cd8.11b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ksuser.dll) WinVerifyTrust
2859cd8.11b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ksuser.dll
2860cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
2861cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
2862cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
2863cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
2864cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
2865cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
2866cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
2867cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
2868cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
2869cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
2870cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
2871cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
2872cd8.11b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
2873cd8.11b4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
2874cd8.11b4: supR3HardenedDllNotificationCallback: load 000007fefbfd0000 LB 0x0003b000 C:\Windows\system32\wdmaud.drv [fFlags=0x0]
2875cd8.11b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
2876cd8.11b4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ksuser.dll
2877cd8.11b4: supR3HardenedDllNotificationCallback: load 0000000075670000 LB 0x00006000 C:\Windows\system32\ksuser.dll [fFlags=0x0]
2878cd8.11b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ksuser.dll
2879cd8.11b4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\avrt.dll
2880cd8.11b4: supR3HardenedDllNotificationCallback: load 000007fefbc60000 LB 0x00009000 C:\Windows\system32\AVRT.dll [fFlags=0x0]
2881cd8.11b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\avrt.dll
2882cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbfd0000 'C:\Windows\system32\wdmaud.drv'
2883cd8.11b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
2884cd8.11b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
2885cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbfd0000 'C:\Windows\system32\wdmaud.drv'
2886cd8.11b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
2887cd8.11b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
2888cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbfd0000 'C:\Windows\system32\wdmaud.drv'
2889cd8.11b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
2890cd8.11b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
2891cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbfd0000 'C:\Windows\system32\wdmaud.drv'
2892cd8.11b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
2893cd8.11b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
2894cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbfd0000 'C:\Windows\system32\wdmaud.drv'
2895cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000d34 pwszName=\Device\HarddiskVolume2\Windows\System32\AudioSes.dll
2896cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
2897cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
2898cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=1B5BCEE9F60F75E176D19C778D9B6CD5DBEB84BB
2899cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\AudioSes.dll'
2900cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2901cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
2902cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
2903cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ole32.dll'.
2904cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
2905cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
2906cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
2907cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'mmdevapi.dll'.
2908cd8.11b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\AudioSes.dll) WinVerifyTrust
2909cd8.11b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\AudioSes.dll
2910cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mmdevapi.dll'...
2911cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'mmdevapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\mmdevapi.dll' [rcNtRedir=0xc0150008]
2912cd8.11b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
2913cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
2914cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
2915cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
2916cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
2917cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
2918cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
2919cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
2920cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
2921cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
2922cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
2923cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
2924cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
2925cd8.11b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\AUDIOSES.DLL (Input=AUDIOSES.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
2926cd8.11b4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\AudioSes.dll
2927cd8.11b4: supR3HardenedDllNotificationCallback: load 000007fefb460000 LB 0x0004f000 C:\Windows\system32\AUDIOSES.DLL [fFlags=0x0]
2928cd8.11b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\AudioSes.dll
2929cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefb460000 'C:\Windows\system32\AUDIOSES.DLL'
2930cd8.11b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
2931cd8.11b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
2932cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbfd0000 'C:\Windows\system32\wdmaud.drv'
2933cd8.11b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
2934cd8.11b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
2935cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbfd0000 'C:\Windows\system32\wdmaud.drv'
2936cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbfd0000 'C:\Windows\system32\wdmaud.drv'
2937cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbfd0000 'C:\Windows\system32\wdmaud.drv'
2938cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbfd0000 'C:\Windows\system32\wdmaud.drv'
2939cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbfd0000 'C:\Windows\system32\wdmaud.drv'
2940cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000d24 pwszName=\Device\HarddiskVolume2\Windows\System32\msacm32.drv
2941cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
2942cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
2943cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=522563F5384AD4C93CF5CF4EEA899D3267552328
2944cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\msacm32.drv'
2945cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2946cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
2947cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
2948cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'winmm.dll'.
2949cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msacm32.dll'.
2950cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'mmdevapi.dll'.
2951cd8.11b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\msacm32.drv) WinVerifyTrust
2952cd8.11b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msacm32.drv
2953cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mmdevapi.dll'...
2954cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'mmdevapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\mmdevapi.dll' [rcNtRedir=0xc0150008]
2955cd8.11b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
2956cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msacm32.dll'...
2957cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msacm32.dll' -> '\Device\HarddiskVolume2\Windows\System32\msacm32.dll' [rcNtRedir=0xc0150008]
2958cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000d40 pwszName=\Device\HarddiskVolume2\Windows\System32\msacm32.dll
2959cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
2960cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
2961cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=DCA0A8AEE81B82C402AA72A300B2C8D2DC17C1DA
2962cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\msacm32.dll'
2963cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
2964cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
2965cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
2966cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
2967cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
2968cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'winmm.dll'.
2969cd8.11b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\msacm32.dll) WinVerifyTrust
2970cd8.11b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msacm32.dll
2971cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
2972cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
2973cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
2974cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
2975cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
2976cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
2977cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
2978cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
2979cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
2980cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
2981cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
2982cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
2983cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
2984cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
2985cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
2986cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
2987cd8.11b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
2988cd8.11b4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
2989cd8.11b4: supR3HardenedDllNotificationCallback: load 000007fefbfc0000 LB 0x0000a000 C:\Windows\system32\msacm32.drv [fFlags=0x0]
2990cd8.11b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
2991cd8.11b4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.dll
2992cd8.11b4: supR3HardenedDllNotificationCallback: load 000007fefbfa0000 LB 0x00018000 C:\Windows\system32\MSACM32.dll [fFlags=0x0]
2993cd8.11b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.dll
2994cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbfc0000 'C:\Windows\system32\msacm32.drv'
2995cd8.11b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
2996cd8.11b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
2997cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbfc0000 'C:\Windows\system32\msacm32.drv'
2998cd8.11b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
2999cd8.11b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
3000cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbfc0000 'C:\Windows\system32\msacm32.drv'
3001cd8.11b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
3002cd8.11b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
3003cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbfc0000 'C:\Windows\system32\msacm32.drv'
3004cd8.11b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
3005cd8.11b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
3006cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbfc0000 'C:\Windows\system32\msacm32.drv'
3007cd8.11b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
3008cd8.11b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
3009cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbfc0000 'C:\Windows\system32\msacm32.drv'
3010cd8.11b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
3011cd8.11b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
3012cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbfc0000 'C:\Windows\system32\msacm32.drv'
3013cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbfc0000 'C:\Windows\system32\msacm32.drv'
3014cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbfc0000 'C:\Windows\system32\msacm32.drv'
3015cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbfc0000 'C:\Windows\system32\msacm32.drv'
3016cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000cf4 pwszName=\Device\HarddiskVolume2\Windows\System32\midimap.dll
3017cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000825280
3018cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000825280
3019cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=43116C5C719A4751DA70B12932084D73D7AACEA3
3020cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\midimap.dll'
3021cd8.11b4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
3022cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
3023cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
3024cd8.11b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'winmm.dll'.
3025cd8.11b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\midimap.dll) WinVerifyTrust
3026cd8.11b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\midimap.dll
3027cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
3028cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
3029cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
3030cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
3031cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
3032cd8.11b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
3033cd8.11b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
3034cd8.11b4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\midimap.dll
3035cd8.11b4: supR3HardenedDllNotificationCallback: load 000007fefbf90000 LB 0x00009000 C:\Windows\system32\midimap.dll [fFlags=0x0]
3036cd8.11b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\midimap.dll
3037cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbf90000 'C:\Windows\system32\midimap.dll'
3038cd8.11b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\midimap.dll
3039cd8.11b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
3040cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbf90000 'C:\Windows\system32\midimap.dll'
3041cd8.11b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\midimap.dll
3042cd8.11b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
3043cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbf90000 'C:\Windows\system32\midimap.dll'
3044cd8.11b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\midimap.dll
3045cd8.11b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
3046cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbf90000 'C:\Windows\system32\midimap.dll'
3047cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefb580000 'C:\Windows\system32\winmm.dll'
3048cd8.11b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dsound.dll
3049cd8.11b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
3050cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeb510000 'C:\Windows\system32\dsound.dll'
3051cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefb580000 'C:\Windows\system32\winmm.dll'
3052cd8.11b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dsound.dll
3053cd8.11b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
3054cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeb510000 'C:\Windows\system32\dsound.dll'
3055cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefb580000 'C:\Windows\system32\winmm.dll'
3056cd8.11b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
3057cd8.11b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007e3f70:C:\Program Files\Oracle\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\PuTTY\ [calling]
3058cd8.11b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec4f0000 'C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL'
3059cd8.11a8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff8c0000 'C:\Windows\system32\OLEAUT32.dll'
3060cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe1d0000 'C:\Windows\system32\shell32.dll'
3061cd8.c20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe1d0000 'C:\Windows\system32\shell32.dll'
3062cd8.1214: supR3HardenedDllNotificationCallback: Unload 000007fef0580000 LB 0x00084000 C:\Windows\system32\netcfgx.dll [flags=0x0]

© 2024 Oracle Support Privacy / Do Not Sell My Info Terms of Use Trademark Policy Automated Access Etiquette